Scanners Box

A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
Alternatives To Scanners Box
Project NameStarsDownloadsRepos Using ThisPackages Using ThisMost Recent CommitTotal ReleasesLatest ReleaseOpen IssuesLicenseLanguage
Vuls10,259
9 hours ago154June 29, 202383gpl-3.0Go
Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices
Scanners Box7,483
a month ago2
A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
Brakeman6,7415,9841202 days ago148July 20, 2023101otherRuby
A static analysis security vulnerability scanner for Ruby on Rails applications
Faraday4,1921114 days ago34January 10, 202240gpl-3.0Python
Open Source Vulnerability Management Platform
Vulscan2,983
2 months ago7otherLua
Advanced vulnerability scanning with Nmap NSE
Dockle2,461215 days ago75July 09, 202326apache-2.0Go
Container Image Linter for Security, Helping build the Best-Practice Docker Image, Easy to start
Pwndoc1,676
2 months ago104mitJavaScript
Pentest Report Generator
Bearer1,351354 hours ago109May 03, 201913otherGo
Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
Secure Ios App Dev1,338
10 months ago1
Collection of the most common vulnerabilities found in iOS applications
Npq801
14 days ago92July 15, 20219apache-2.0JavaScript
🎖safely* install packages with npm or yarn by auditing them as part of your install process
Alternatives To Scanners Box
Select To Compare


Alternative Project Comparisons
Readme

English | 简体中文

202301 license number Twitter URL


Donate with PayPal

Sponsors

Introduction

Scanners Box also known as scanbox, is a powerful hacker toolkit, which has collected more than 10 categories of open source scanners from Github, including subdomain, database, middleware and other modular design scanner etc. But for other Well-known scanning tools, such as nmap, w3af, brakeman, arachni, nikto, metasploit, aircrack-ng will not be included in the scope of collection.

Contents


Large Language Model Security

  • leondz/garak - LLM vulnerability scanner for hallucination, data leakage, promp injection, misinformation, toxicity generation, jailbreaks, and many other weaknesses

GitHub language count GitHub last commit GitHub stars GitHub

  • protectai/rebuff - Designed to protect AI applications from prompt injection (PI) attacks

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

Smart Contracts Security

  • ConsenSys/mythril - Security analysis tool for EVM bytecode. Supports smart contracts built for Ethereum, Hedera etc.

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • eth-sri/securify2 - Official security scanner for Ethereum smart contracts supported by the Ethereum Foundation

GitHub language count GitHub last commit GitHub stars GitHub

  • smartdec/smartcheck - Static analysis tool that detects vulnerabilities and bugs in Solidity programs

GitHub language count GitHub last commit GitHub stars GitHub

  • ivicanikolicsg/MAIAN - Automatic tool for finding trace vulnerabilities in Ethereum smart contracts

GitHub language count GitHub last commit GitHub stars GitHub

Red Team vs Blue Team

Supply Chain Analysis(SCA)

GitHub language count GitHub last commit GitHub stars GitHub

Container and Cluster

  • cdk-team/CDK - A tool to gather information inside container/cluster and exploit them

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • armosec/kubescape - The first tool for testing if Kubernetes is deployed securely as defined in Kubernetes Hardening Guidance by to NSA and CISA

GitHub language count GitHub last commit GitHub stars GitHub

  • chaitin/veinmind-tools - Container security scanner for backdoor, malicious, weak pass and sensitive and the like.

GitHub language count GitHub last commit GitHub stars GitHub

  • deepfence/ThreatMapper - Scan for in-production vulnerabilities and exposed secrets, and identify attack paths to reach them remotely

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • kvesta/vesta - A static analysis of vulnerabilities, Docker and Kubernetes cluster configuration detect toolkit

GitHub language count GitHub last commit GitHub stars GitHub

Services fingerprint detection

GitHub language count GitHub last commit GitHub stars GitHub

Man-In-The-Middle

GitHub language count GitHub last commit GitHub stars GitHub

The framework

GitHub language count GitHub last commit GitHub stars GitHub

  • FunnyWolf/Viper - Graphical, Modularization and weaponization intranet penetration tool

GitHub language count GitHub last commit GitHub stars GitHub

  • P1-Team/AlliN - Mostly used for asset collection before penetration and lateral movement of intranet

GitHub language count GitHub last commit GitHub stars GitHub

  • k8gege/LadonGo - Pentest framework for Windows/Linux/Mac intranet networks

GitHub language count GitHub last commit GitHub stars GitHub

  • shmilylty/netspy - Quickly scan the reachable network segmentation of the intranet

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • u21h2/nacs - Event-driven intranet pentest scanner

GitHub language count GitHub last commit GitHub stars GitHub

  • h4wkst3r/SCMKit - Source Code Management Attack Toolkit,such as GitHub Enterprise, GitLab Enterprise and Bitbucket Server

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

Wireless Pentest

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • besimaltnok/PiFinger - Searches for wifi-pineapple traces and calculate wireless network security score

GitHub language count GitHub last commit GitHub stars GitHub

  • derv82/wifite2 - A complete re-write of Wifite,Automated Wireless Attack Tool

GitHub language count GitHub last commit GitHub stars GitHub

  • D3Ext/WEF - Wi-Fi Exploitation Framework for 2.4 and 5 Ghz both attacks

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

Mobile Apps Packages Analysis

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • maaaaz/androwarn - Yet another static code analyzer for malicious Android applications

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • abhi-r3v0/Adhrit - Android Security Suite for in-depth reconnaissance and static bytecode analysis based on Ghera benchmarks

GitHub language count GitHub last commit GitHub stars GitHub BlacHatUSA-arsenal-2022

  • pascal-lab/Tai-e - An easy-to-learn/use static analysis framework for Java, especially for Android

GitHub language count GitHub last commit GitHub stars GitHub

  • Cyber-Buddy/APKHunt - A comprehensive static code analysis tool for Android apps that is based on the OWASP MASVS framework

GitHub language count GitHub last commit GitHub stars GitHub

Binary Executables Analysis

GitHub language count GitHub last commit GitHub stars GitHub

  • Tencent/HaboMalHunter - Used for automated malware analysis and security assessment on the Linux system

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • fkie-cad/cwe_checker - Static analyzer for detecting common bug classes such as buffer overflows in binaries

GitHub language count GitHub last commit GitHub stars GitHub

  • airbus-seclab/bincat - Binary code static analyser, with IDA integration. Performs value and taint analysis

GitHub language count GitHub last commit GitHub stars GitHub

Privacy Compliance

  • riskscanner/riskscanner - Multi-cloud privacy compliance scanning platform, through Cloud Custodian's YAML DSL to define scanning rules

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

Subdomain Enumeration or Takeover

GitHub language count GitHub last commit GitHub stars GitHub

  • ring04h/wydomain - A Speed and Precision subdomain enumeration Tool by ringzero

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • TheRook/subbrute - A DNS meta-query spider that enumerates DNS records, and subdomains,supported API

GitHub language count GitHub last commit GitHub stars GitHub

  • We5ter/GSDF - Subdomain enumeration via Google certificate transparency

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • nmalcolm/Inventus - A spider designed to find subdomains of a specific domain by crawling it

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • jonluca/Anubis - Subdomain enumeration and information gathering tool

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • FeeiCN/ESD - Enumeration sub domains tool,based on AsyncIO and non-repeating dict

GitHub language count GitHub last commit GitHub stars GitHub

  • UnaPibaGeek/ctfr - Abusing certificate transparency logs for getting HTTPS websites subdomains

GitHub language count GitHub last commit GitHub stars GitHub

  • giovanifss/Dumb - Dumain Bruteforcer, a fast and flexible domain bruteforcer

GitHub language count GitHub last commit GitHub stars GitHub

  • OWASP/Amass - In-depth Attack Surface Mapping and Asset Discovery

GitHub language count GitHub last commit GitHub stars GitHub

  • Ice3man543/subfinder - A subdomain discovery tool which has a simple modular architecture and has been aimed as a successor to sublist3r project

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • yunxu1/dnsub - A high concurrency and cross platform subdomain scanner based on Golang

GitHub language count GitHub last commit GitHub stars GitHub

  • shmilylty/OneForAll - An ultimate subdomains scanner integrated multiple subdomain scanning tools

GitHub language count GitHub last commit GitHub stars GitHub

  • knownsec/ksubdomain - A stateless and cross-platform subdomain enumeration tool, speed up to 30w/s on Mac and Windows, and 160w/s on Linux

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • bit4woo/domain_hunter_pro - Domain finder and Targets management, automated information collection, integrated with burpsuite

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • v4d1/Dome - Active and/or passive scan to obtain subdomains and search for open port

GitHub language count GitHub last commit GitHub stars GitHub

  • cramppet/regulator - Automated subdomain enumeration tool by learning of regexes for DNS discovery

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

Database SQL Injection Vulnerability or Brute Force

GitHub language count GitHub last commit GitHub stars GitHub

  • stamparm/DSSS - A SQLi vulnerability scanner with 99 lines of code

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • missDronio/blindy - Simple script to automate brutforcing blind sql injection vulnerabilities

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • ron190/jsql-injection - A lightweight application used to find database information from a distant server

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • s0md3v/sqlmate - A friend of SQLmap which will do what you always expected from SQLmap

GitHub language count GitHub last commit GitHub stars GitHub

  • m8r0wn/enumdb - MySQL and MSSQL brute force and post exploitation tool

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

Weak Usernames or Passwords Enumeration For Web

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • s0md3v/Blazy - a modern login bruteforcer which also tests for CSRF, Clickjacking, Cloudflare and WAF

GitHub language count GitHub last commit GitHub stars GitHub

  • MooseDojo/myBFF - Web application brute force framework,supports Citrix Gateway,CiscoVPN and so on

GitHub language count GitHub last commit GitHub stars GitHub

  • TideSec/web_pwd_common_crack - A common web weak_password cracking script,can detect batches of management backgrounds without verification codes

GitHub language count GitHub last commit GitHub stars GitHub

Authorization Brute Force or Vulnerability Scan For IoT

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • firmianay/firmeye - An IDA plug-in, based on sensitive function parameter backtracking to assist in vulnerability mining

GitHub language count GitHub last commit GitHub stars GitHub

Mutiple types of Cross-site scripting Detection

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • shogunlab/shuriken - XSS command line tool for testing lists of XSS payloads on web apps

GitHub language count GitHub last commit GitHub stars GitHub

  • s0md3v/XSStrike - Fuzz and bruteforce parameters for XSS, WAFs detect and bypass

GitHub language count GitHub last commit GitHub stars GitHub

  • stamparm/DSXS - A fully functional cross-site scripting vulnerability scanner,supporting GET and POST parameters,and written in under 100 lines of code

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • lwzSoviet/NoXss - Faster reflected-xss and dom-xss scanner based on Phantomjs

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • hahwul/dalfox - Parameter Analysis and XSS Scanning tool based on golang

GitHub language count GitHub last commit GitHub stars GitHub

Enterprise sensitive information Leak Scan

GitHub language count GitHub last commit GitHub stars GitHub

  • Ekultek/Zeus-Scanner - An advanced dork searching tool that is capable of finding IP address /URL blocked by search engine,and can run sqlmap and nmap scans on the URL's

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • 1N3/Goohak - Automatically launch Google hacking queries against a target domain

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • FeeiCN/GSIL - Github sensitive information leakage scan

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • eth0izzle/shhgit - A docker and web based monitor for finding secrets and sensitive files across GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • SAP/credential-digger - A GitHub scanning tool that identifies hardcoded credentials, filtering the false positive data through machine learning models

GitHub language count GitHub last commit GitHub stars GitHub

  • sdushantha/dora - Find exposed API keys based on RegEx and get exploitation methods for some of keys that are found

GitHub language count GitHub last commit GitHub stars GitHub

Malicious Scripts Detection

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

Vulnerability Assessment for Middleware

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • rbsec/sslscan - Tests SSL/TLS enabled services to discover supported cipher suites

GitHub language count GitHub last commit GitHub stars GitHub

  • TideSec/TideFinger - Web fingerprint identification tool, more fingerprint database, more detection methods

GitHub language count GitHub last commit GitHub stars GitHub

  • TideSec/FuzzScanner - Comprehensive web information collection platform, easy to deploy, versatile and practical

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • nanshihui/Scan-T - A new spider based on Python with more function including Network fingerprint search

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • Xyntax/BingC - Based on the Bing search engine C / side-stop query, multi-threaded, supported API

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • zer0h/httpscan - A HTTP service detector with a crawler from IP/CIDR

GitHub language count GitHub last commit GitHub stars GitHub

  • lietdai/doom - Distributed task distribution of the IP port vulnerability scanner based on thorn

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • 18F/domain-scan - Scans domains for data on their HTTPS configuration and assorted other things

GitHub language count GitHub last commit GitHub stars GitHub

  • ggusoft/inforfinder - A tool made to collect information of any domain pointing at a server and fingerprinter

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • mozilla/cipherscan - A very simple way to find out which SSL ciphersuites are supported by a target

GitHub language count GitHub last commit GitHub stars GitHub

  • xmendez/wfuzz - Web application framework and web content scanner

GitHub language count GitHub last commit GitHub stars GitHub

  • s0md3v/Breacher - An advanced multithreaded admin panel finder written in Python

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • medbenali/CyberScan - An open source penetration testing tool that can analyse packets,decoding,scanning ports, pinging and geolocation of an IP

GitHub language count GitHub last commit GitHub stars GitHub

  • m0nad/HellRaiser - HellRaiser scan with nmap then correlates cpe's found with cve-search to enumerate vulnerabilities

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • n4xh4ck5/CMSsc4n - Tool to identify if a domain is a CMS such as Wordpress, Moodle, Joomla

GitHub language count GitHub last commit GitHub stars GitHub

  • Ekultek/WhatWaf - Detect and bypass web application firewalls and protection systems

GitHub language count GitHub last commit GitHub stars GitHub

  • dzonerzy/goWAPT - Go web application penetration test and web application fuzz tool

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • H4ckForJob/dirmap - An advanced web directory scanning tool that will be more powerful than DirBuster, Dirsearch, cansina, and Yu Jian

GitHub language count GitHub last commit GitHub stars GitHub

  • s0md3v/Photon - Incredibly fast crawler which extracts urls, emails, files, website accounts and much more

GitHub language count GitHub last commit GitHub stars GitHub

  • 1N3/BlackWidow - Gather OSINT and fuzz for OWASP vulnerabilities on a target website

GitHub language count GitHub last commit GitHub stars GitHub

  • saeeddhqan/Maryam - OSINT and Web-based Footprinting modular framework based on the Recon-ng

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • Tib3rius/AutoRecon - A multi-threaded network reconnaissance tool which performs automated enumeration of services

GitHub language count GitHub last commit GitHub stars GitHub

  • sowish/LNScan - Local Network Scanner based on BBScan via.lijiejie

GitHub language count GitHub last commit GitHub stars GitHub

  • shadow1ng/fscan - Intranet integrated scanning tool,build for automatic, full coverage scanning

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • v-byte-cpu/sx - A network scanner that 30x times faster than nmap

GitHub language count GitHub last commit GitHub stars GitHub

  • nullt3r/jfscan - Super fast port scanning & service discovery using Masscan and Nmap

GitHub language count GitHub last commit GitHub stars GitHub

  • lcvvvv/kscan - Port scanning, protocol detection(1200+), fingerprint(1w+) and brute force cracking

GitHub language count GitHub last commit GitHub stars GitHub

  • OJ/gobuster - Directory/File, DNS and VHost busting tool written in Go

GitHub language count GitHub last commit GitHub stars GitHub

Special Targets Scan

  • 1N3/XSSTracer - A small python script to check for cross-Site tracing, Clickjacking etc

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • epinna/tplmap - Automatic Server-Side Template Injection detection and exploitation tool

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • ilmila/J2EEScan - A plugin for Burp Suite proxy to improve the test coverage during web application penetration tests on J2EE applications

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • 0x4D31/salt-scanner - Linux vulnerability scanner based on Salt Open and vulners audit API, with Slack notifications and JIRA integration

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • mak-/parameth - This tool can be used to brute discover GET and POST parameters

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • hahwul/a2sv - Auto scanning to SSL vulnerability, such as heartbleed etc

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • kotobukki/BDA - The vulnerability detector for Hadoop and Spark

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • 3xp10it/xupload - A tool for automatically testing whether the upload function can upload webshell

GitHub language count GitHub last commit GitHub stars GitHub

  • rezasp/vbscan - OWASP VBScan is a Black Box vBulletin vulnerability scanner

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • radenvodka/SVScanner - Scanner vulnerability and massive exploit for Wordpress,Magento,Joomla and so on

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • 6IX7ine/djangohunter - Tool designed to help identify incorrectly configured Django applications that are exposing sensitive information

GitHub language count GitHub last commit GitHub stars GitHub

  • vulmon/Vulmap - Local vulnerability scanning programs for Windows and Linux operating systems

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • anouarbensaad/vulnx - Intelligent Bot, Shell can achieve automatic injection, and help researchers detect security vulnerabilities CMS system

GitHub language count GitHub last commit GitHub stars GitHub

  • MrEmpy/Mantra - A tool used to hunt down API key leaks in JS files and pages

GitHub language count GitHub last commit GitHub stars GitHub

Dynamic or Static Code Analysis

  • wufeifei/cobra - A static code analysis system that automates the detecting vulnerabilities and security issue

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • python-security/pyt - A static analysis tool for detecting security vulnerabilities in Python web applications

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • PyCQA/bandit - A tool designed to find common security issues in Python code

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • CoolerVoid/codecat - The tool to help you find/track user input sinks and security bugs in Java, C++,GO, Python, javascript, Swift etc. with regex rules

GitHub language count GitHub last commit GitHub stars GitHub

  • qax-os/goreporter - A Golang tool that does static analysis, unit testing, code review and generate code quality report

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • securego/gosec - Inspects source code for security problems by scanning the Go AST

GitHub language count GitHub last commit GitHub stars GitHub

Modular Design Scanners or Vulnerability Detecting Framework

  • infobyte/faraday - Collaborative penetration test and vulnerability management platform

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • Xyntax/POC-T - Penetration test plug-in concurrency framework

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • Tuhinshubhra/RED_HAWK - An all In one tool For information gathering, SQL vulnerability scanning and crawling, coded In PHP

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • anilbaranyelken/tulpar - Web Vulnerability Scanner written in Python,supported multiple web vulnerabilities scan

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • 0xsauby/yasuo - ruby script that scans for vulnerable & exploitable 3rd-party web applications on a network

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • erevus-cn/pocscan - Open source and distributed web vulnerability scanning framework

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • zaproxy/zaproxy - One of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers

GitHub language count GitHub last commit GitHub stars GitHub

  • s0md3v/Striker - Striker is an offensive information and vulnerability scanner

GitHub language count GitHub last commit GitHub stars GitHub

  • dermotblair/webvulscan - Written in PHP and can be used to test remote, or local, web applications for security vulnerabilities

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • toyakula/luna - An open-source web security scanner which is based on reduced-code passive scanning framework

GitHub language count GitHub last commit GitHub stars GitHub

  • Manisso/fsociety - A Penetration Testing Framework including Information Gathering,Wireless Testing,Web Hacking and so on

GitHub language count GitHub last commit GitHub stars GitHub

  • boy-hack/w9scan - A web vulnerability scanner framework,running with 1200+ plugins

GitHub language count GitHub last commit GitHub stars GitHub

  • YalcinYolalan/WSSAT - Web service security assessment tool,provide simple .exe application to use based on Windows OS

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • j3ssie/Osmedeus - Fully automated offensive security tool for reconnaissance and vulnerability scanning

GitHub language count GitHub last commit GitHub stars GitHub

  • jeffzh3ng/Fuxi-Scanner - Open source network security vulnerability scanner with asset discovery & management

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • opensec-cn/kunpeng - An open source POC framework written by Golang that provides various language calls in the form of a dynamic link library

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • google/tsunami-security-scanner - A general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high confidenc by Google

GitHub language count GitHub last commit GitHub stars GitHub

  • er10yi/MagiCude - A scanner based on the Spring Boot micro-service,supports distributed port (vulnerability) scanning, asset security management, real-time threat monitoring and notification, vulnerability lifecycle, vulnerability wiki, email notification, etc

GitHub language count GitHub last commit GitHub stars GitHub

  • projectdiscovery/nuclei - A fast tool for configurable targeted vulnerability scanning based on templates offering massive extensibility

GitHub language count GitHub last commit GitHub stars GitHub

  • ysrc/xunfeng - Vulnerability rapid response,scanning system for intranet

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • smallcham/sec-admin - SEC can be used for enterprises to scan and check the security of server resources which has strong controllability, supports distributed multi-node deployment

GitHub language count GitHub last commit GitHub stars GitHub

  • olacabs/jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems

GitHub language count GitHub last commit GitHub stars GitHub

  • bigblackhat/oFx - Vulnerability verification framework, corporate assets analysis and rapid scanner for 1day vulnerability

GitHub language count GitHub last commit GitHub stars GitHub

Advanced Persistent Threat Detect

GitHub language count GitHub last commit GitHub stars GitHub

GitHub language count GitHub last commit GitHub stars GitHub


Why Create This Collection?

The purpose of this collection is to provide various types of open-source security scanners that can help companies to be more safer.

Commit Symbolic Description

[↑scanner]xxx means update scanner info
[+scanner]xxx means add scanner
[-scanner]xxx means remove scanner
[+category]xxx means add scanner category
[-category]xxx means remove scanner category
[+contributor]xxx means add someone to acknowledgments
[↑contributor]xxx means update someone's info for acknowledgments
[↑other]xxx means other actions

Authors

Wester(Twitter @Zhiyang Zeng) & Martin(Twitter @Martin Chow)

Legal Disclaimer

The scanners provided by this project are for research and study purposes only, and you must obey the laws and regulations of your country during use. If you are a Chinese citizen, please ensure you are obedient to The Cyber Security Law of the People's Republic of China, and please do not break the article 286 of the Criminal Law of the People's Republic of China for the regulation on the crime of destroying computer systems. At last, I would like to point out to you that you must be fully held responsible duty for any consequence that may arise.

How to contribute?

If you have any questions about this project ,or you have found some valuable scanners, please feel free to tell us :)

License

The content of this Repository is released under the <CC BY-NC-ND 4.0> license.

Copyright

It's happy to see that this repository has been widely spreaded in information security community, but I hope everyone could at all times respect knowledge and our efforts, so please specify reproduced from We5ter/Scanners-Box in your articles, and please do not republish this article for profit.

Acknowledgments

We would like to thanks the following security researchers for their valuable feedbacks amd suggestions.

  • @0c0c0f
  • @藏形匿影
  • @Mottoin team
  • @BlackHole
  • @CodeColorist
  • @3xp10it
  • @re4lity
  • @s0md3v
  • @boy-hack
  • @marsII
  • @tom0li
  • @hksanduo
  • @alexlauerman
  • @MedivhMT
  • @TideSec
  • @0xHJK
  • @j3ssie
  • @Luci-d
  • @cnlnn
  • @yunxu1
  • @saeeddhqan
  • @Sofiane Lounici
  • Owen Garrettz@deepfence

Stargazers

Stargazers over time

©Monster Zero Team 2023

Popular Security Audit Projects
Popular Vulnerabilities Projects
Popular Security Categories
Related Searches

Get A Weekly Email With Trending Projects For These Categories
No Spam. Unsubscribe easily at any time.
Vulnerability
Scanner
Smart Contracts
Penetration Testing
Subdomain
Xss
Static Analysis
Information Security
Malware Analysis
Sqli
Vulnerability Scanners
Devsecops
Security Audit
Security Automation
Binary Analysis
Wifi Security
Exploitation Framework