There is no absolute solution paradigm for security problems, but Yak creates enough possibilities, allowing us to stand on the shoulders of giants and let our imagination run wild. Its vision and ambition are worth learning from and reflecting on.
Widely Used Open-Source CybersecurityInfrastructure
Yak Project is an open-source cybersecurity infrastructure built around the Yaklang security programming language, providing the Yakit security workbench, IRify static analysis, and Memfit AI for penetration testing, code auditing, and security automation.
★ 7,735 stars825 forksLatest release v1.4.8-0911100% open source
Yak and Yakit Released at XCon
Yak Project entered public development; Yakit began providing security engineers with a unified desktop workbench.
CDSL-YAK Open Source Launch at Beijing National Convention Center
Core language, runtime, and security capability base were opened to the community, allowing external developers to inspect source code, file issues, and contribute.
YAKIT Cybersecurity Individual Test System V2.0 Listed in Beijing New Technology and Products Catalog
Yakit’s productization and practical application entered a new stage of development.
Yakit V2.0 Passed Third Research Institute of the Ministry of Public Security Testing
Yakit completed testing against national standards for cyber-security products and Web application security detection.
“YakLang: A Domain-Specific Secure Programming Language for Communication Networks” Named One of 2023 Top 10 ICT Tech Advances
Yaklang’s domain-specific programming language path entered the annual ICT technology advance list.
IRify Released
Yak SSA, SyntaxFlow, and AI capabilities formed a standalone code-auditing product, extending project capabilities from interactive testing to source-code security analysis.
“Domain-Specific Programming Language and Development Environment for Cybersecurity” Won First Prize of CIC Science and Technology Award
Yaklang and its supporting development environment received an industry technology award for technical achievements and practical application.
“Homegrown Cybersecurity Development Environment YAK” Won Third Prize in Maker China National Finals Enterprise Group
YAK advanced from the cybersecurity themed competition to the national finals, demonstrating the engineering capabilities and application value of a homegrown security development environment.
Memfit AI Released
Yaklang, Yakit, and their tool ecosystem entered the Agent workflow, providing security engineers with analysis, execution, and delivery support.
Everyone
Loves YakEveryone Loves Using Yak
See why developers choose Yak every day
To me, Yakit is a security testing framework that can be customized. It is a great fit for hands-on security practitioners who want to forge their own blade.
The idea behind Yak can greatly lighten the environment-configuration burden for security practitioners, and the rich plugins noticeably improve penetration testing work. I hope Yak keeps getting better as a domestic security product.
I first came across Yak in late 2021, when the community was still small. As the developers kept collecting, sorting, adding, and refining user feedback, the documentation got better and Yakit became smoother to use, and I gradually felt this is a warm, human team. I originally thought Yakit was partly about moving away from foreign cracked software, but what impressed me most was the tense international situation. So many companies and products took sides; if we do not plan ahead, we may face the same situation one day. In the end, I hope Yak keeps thriving, and more security practitioners join the domestic ecosystem effort.
First, I must mention that the Yakit authors are genuinely passionate and responsible: every question gets answered. I learned a lot talking with V, in particular. Second, Yakit's server-plus-console model is really nice for team work. Finally, I wish Yakit all the best and hope it becomes the strongest tool in the world!
Yakit is an excellent domestic web penetration tool, lovable from the very first design. As a power user, I can feel in every detail the craftsmanship of a team dedicated to the comfort of penetration testers. From reconnaissance to fuzzing to PoC verification, Yakit is like a comrade fighting beside you. The Yakit community is active, the developers listen to suggestions, and the product keeps iterating. I believe it will become a must-have offensive tool for web penetration.
In 2022, I strongly recommend a vulnerability-hunting tool I cannot put down — Yakit. The maintainers are friendly and skilled, tirelessly building new features. Yakit is truly a tool that can do anything you can think of. I hope Yakit replaces Burp soon; this time I back the domestic powerhouse ~Yakit.
The product's original intention is excellent: as a solo-operation tool for Chinese penetration testers, it brings practical plugins into a single platform, exposes interfaces for users to add their own plugins or rules at any time, and even thoughtfully supports Nuclei rules. It is a rare and good tool, the best alternative to BurpSuite. Highly recommended!
I got to know V1ll4n through the SIEM he built early on, which fused many security capabilities. As an enterprise security practitioner, I very much agree with his concepts of high- and low-level security. Then Yakit came along, extending those SIEM ideas and showing more possibilities. Yakit's complete ecosystem and compatibility help solve security-capability construction. As the community grows and more peers join, Yakit becomes more mature. In my view, Yakit is a security tool with no ceiling — it provides a base and gives security practitioners room to freely innovate. And V1ll4n fixes bugs fast; he is solid.
Three reasons to choose Yakit. 1. Yakit looks great — clean logo, clean interface. Perfection itself is proof of strength. 2. V, the Yakit core team, and community contributors ship high-frequency updates — 18 releases in one day; nobody has the latest version. In a short time Yakit grew from a spark into a rich, mature, lethal weapon. 3. The Yak team is friendly, energetic, and highly execution-oriented — you can always trust Yak.
Deep data fusion in penetration tools is the inevitable trend in security tooling. Customizability and extensibility are basic needs for every senior penetration engineer, and excellent UI interaction is the catalyst for wide adoption. To build a tool covering the full penetration-test workflow, you need to understand every stage of the process. It is, however, a huge and long-term project requiring: 1) coders familiar with penetration processes and interaction design, 2) a company that unconditionally supports it, and 3) an operation team that constantly responds to user needs and feedback. The Yaikit project grew from this purpose and has the conditions to achieve it. I hope everyone uses it and offers fixes and optimization suggestions to make the project more complete and excellent.
For me, Yak is an excellent fusion language with strong security-development attributes; you can use it to efficiently develop security scripts, platforms, and tools. The Yak project not only created Yak but also thoughtfully built Yakit, a solo-operation platform for security practitioners. The birth of Yakit actually represents a kind of "unification" that brings many capabilities together, avoiding constant switching between tools and compatibility headaches. Although it is not a BurpSuite competitor, it has many similar features and is more practical. For example, Web Fuzz innovates by bringing real fuzzing thinking into web security, also reducing unnecessary dictionary collection. The Yak team made a bold attempt that many would not dare to make, requiring huge human investment, which I deeply admire and find inspiring. I believe Yak and Yakit will forge their own path in the future. Keep going — the future is bright!
Yakit is a very useful network solo-operation tool. It covers Burp Suite's most frequently used features and adds its own innovations. The Web Fuzzer tag greatly raises the ceiling for penetration testers, making tests more capable and convenient. Thanks to Yakit's Yaklang foundation and Go-like syntax, users can hook MITM with simpler code to implement a wide variety of plugins.
Yakit is a young, integrated platform with front-line attack-defense experience. It engineers excellent offensive experience into practical tooling, making life easier for front-line red-teamers. UI and polish still have room to improve. I hope Yakit keeps getting better!
The scanning interface is very convenient, and the built-in dynamic Yak-script parsing is also advanced. The team is awesome.
For the Yakit/Yak project, I was initially curious about how the Yak scripting language was implemented. But in use, I found the plugin architecture, Yak built-in security functions, and Yakit GUI combined are the project's highlights. Since the project is young, design bugs are inevitable, but author V1ll4n's update frequency is amazing.
Yak is the best security-capability foundation in China I have seen, with a lot of effort put into heterogeneous multi-source data integration, letting security practitioners truly focus on solving security problems.
Overall, I really like this tool: it scans ports, detects vulnerabilities, and brute-forces credentials, integrating many capabilities in an easy-to-use way that greatly improves efficiency. Yakit does not target Burp, but has many of Burp's features and bundles common penetration-test functions in one place. Practitioners can also use Yakit's customization to build their own offensive tools. Yakit did what many dared not do, and I hope Yakit can do what others cannot.
In my eyes, Yak's significance is far greater than Yakit; Yakit is only a collection of scenario implementations for security needs built on Yak. From Yakit's open source to now, it keeps covering more security scenarios, which makes me feel Yak is, as the original docs said, constantly proving to security people that Yak is indeed the most suitable language for security, and makes people expect it to truly become the "base" of security. What amazes me most about Yakit is the reverse-connection platform expansion; I have been talking with V about extending the OAST detection model and have tried building a similar product. During my own implementation, I felt Yakit's direction on reverse connection kept validating my own work, and I deeply appreciate how hard it is to make a product that satisfies both yourself and others. In short, I very much look forward to Yak covering more security scenarios in the future.
I was moved by the Yak team's vision the first time I touched Yak. As a security-domain scripting language, Yak integrates common security capabilities. Not long ago I tested a workflow, and after a little learning I quickly designed a detection process the way I wanted. The official Yakit implementation provides many practical tools such as MITM and codec-specific vulnerability detection. Yakit is still under rapid development, the WeChat community is very active, many interesting technologies and ideas are landing, and the team fixes bugs and iterates features incredibly fast. I sincerely hope the Yak ecosystem and community grow stronger and become the MATLAB of security.
Try Now
Whether you're an industry user or a student,
Yak is always your good partnerWhether you're an industry user or a student, Yak is always your good partner

