FoxStudio
WorksLabStudioTeamJournalContact
FR·EN·IT

FoxStudio

Subsidiary of FoxCase.

Navigate

  • Works
  • Lab
  • Studio
  • Team
  • Journal

Contact

  • hello@foxstudio.fr
  • Cannes, FR
  • Ombrys

Legal

  • Mentions
  • Privacy
  • Footprint

Cannes, FR · GMT+1MEASURING…v0.1.0
Decorative patternHatching
009 ▸ 2025TypeScript · Electron · Rust · Node.js× archived

Klown

Cross-platform desktop framework for authorised ethical hacking. Strict legal scope, audit logging, sandboxed modules.

01▸Context2025 · archived
Year
2025
Status
archived
Stack
TypeScript · Electron · Rust · Node.js

Existing pentest tools force a trade-off: either power and opacity (the user doesn't know exactly what's being executed), or transparency and slowness. None offers a complete, legally-actionable audit log proving no out-of-scope action was attempted.

Klown is built for authorised auditing — bug bounties, contractual intrusion tests, vulnerability research within legal bounds. Every action is logged, signed, timestamped. Exceeding the declared scope is technically blocked.

02▸Approach
studio.foxcase.fr/works/klown
System architecture diagramIPCWebSocketchat · eventsCLIENTElectron · UISERVICERust core · captureSERVICENode bridgeEXTERNALOBS · scenesEXTERNALTwitch API

Two-layer architecture: a Rust core handling isolation, logging and declared scope; an Electron UI exposing modules. Each module runs in its own sandbox with a manifest declaring what it's allowed to do — allowed network, allowed ports, allowed data.

The log is append-only, encrypted, STIX 2.1 exportable. Three platforms supported (Windows, macOS, Linux) from a single codebase. The project was archived in late 2025 — it proved itself, but the pentest ecosystem moved to Burp Suite Enterprise and the ROI to maintain dropped.

03▸Results
01

3

02

audit

03

sandbox

Decorative patternGrid

Next ▸ 008

Moe's Coffee