15 Repos
Systems for automatically initiating vulnerability assessments based on discovery or infrastructure changes.
Distinct from Scanning Template Libraries: Distinct from Scanning Template Libraries: focuses on the automation and triggering logic rather than the template library itself.
Explore 15 awesome GitHub repositories matching security & cryptography · Automated Security Scan Triggers. Refine with filters or upvote what's useful.
RustScan is a high-speed TCP network scanner written in Rust, designed for security reconnaissance and network mapping. It functions as an automated port discovery engine that identifies open ports on remote hosts using IPv6 addresses, CIDR ranges, or bulk input files. The tool is built for rapid surface area discovery, utilizing parallel port processing and OS-aware performance optimizations to identify active services. It allows for scan precision tuning through adjustable connection timeout thresholds and concurrent request controls to balance speed and accuracy. The system integrates wit
Supports automatically triggering external scripts to handle results or alerts after a scanning process.
dirsearch is a command-line security tool and web path scanner used for discovering hidden directories and files on web servers. It functions as a recursive directory fuzzer and brute-force utility that identifies undocumented paths and sensitive files using wordlists and HTTP status codes. The tool distinguishes itself through template-driven path generation and an automated HTTP response filter that uses status codes, content length, and regex patterns to isolate valid targets. It supports recursive directory crawling to map complex web structures and provides state-persistence serializatio
Provides programmatic interfaces to trigger automated security scans within larger discovery workflows.
Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast
Implements systems for automatically initiating security assessments based on infrastructure changes or discovery events.
Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It functions as a discovery engine that identifies and maps internet-exposed infrastructure, cloud-hosted assets, and network ranges to maintain a comprehensive inventory of an organization's digital footprint. The project distinguishes itself through a modular, template-driven scanning engine that executes security checks against discovered assets. It leverages cloud-native asset discovery to query provider APIs and infrastructure metadata, while supporting distributed agent orc
Automatically triggers security scans based on asset discovery and infrastructure changes to maintain continuous coverage.
Kubescape is a Kubernetes security posture management platform designed to scan clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance risks. It functions as a comprehensive security suite incorporating a compliance scanner, a container image vulnerability scanner, an admission controller for policy enforcement, and a runtime security monitor. The platform distinguishes itself through runtime-aware vulnerability filtering, which maps libraries loaded in memory to determine if vulnerabilities are actually reachable. It also integrates with AI assistants via a Mo
Automatically initiates security scans triggered by external providers and infrastructure changes.
Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets. The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan
Provides an API to automatically trigger reconnaissance and vulnerability scans using configurable logic gates.
Tsunami Security Scanner is a network vulnerability scanner and security auditor designed to identify high-severity flaws across network assets. It functions as an asynchronous security probe engine that utilizes automated probes and specialized detection logic to find critical weaknesses and prioritize remediation efforts. The project is distinguished by a plugin-based scanning engine, which uses a modular architecture of interchangeable detection plugins to identify vulnerabilities. This extensibility allows for the development and integration of custom security plugins to expand the variet
Provides a mechanism to toggle whether automated action scanning remains active for a specific repository.
reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio
Triggers aggressive reconnaissance techniques automatically based on subdomain count thresholds.
AutoRecon is an automated network reconnaissance tool that performs concurrent port scanning and service enumeration across multiple targets. It operates as a multi-target port scanner, probing IP addresses, CIDR ranges, or hostnames in parallel, and automatically dispatches service-specific enumeration tools after port detection to gather detailed information about each open service. The tool distinguishes itself through a plugin-based scanning system that allows extending or replacing default port and service scans via a flexible plugin architecture. It provides real-time pattern-based outp
Adjusts the verbosity of live scan output during execution using keyboard controls.
Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to identify active services. It functions as a Go library for embedding port scanning into programs, and as a standalone tool that accepts targets as hostnames, IP addresses, CIDR ranges, or ASN numbers. The tool discovers live hosts before scanning, filters ports by range or top lists, and can integrate with Nmap for service version detection. The project distinguishes itself through its SYN-based port probing approach that sends TCP SYN packets and analyzes responses without complet
Automatically scans assets when new vulnerability templates are added to protect against emerging threats.
Scorecard ist ein Open-Source-Sicherheitsscanner und ein Tool zur Analyse der Software-Lieferkette, das den Sicherheitsstatus von Projekten durch die Berechnung von Risikometriken basierend auf Best Practices bewertet. Es fungiert als Dashboard für die Sicherheitsgesundheit und visualisiert Sicherheitslücken durch Scores und Badges, um Maintainer bei der Identifizierung von Schwachstellen zu unterstützen. Das Projekt bietet ein System zur Überwachung der Repository-Sicherheit durch einen GitHub-Action-Sicherheitsauditor, der Maintainer alarmiert, wenn Sicherheits-Scores sinken. Es bietet zudem einen Mechanismus für Anleitungen zur Behebung von Schwachstellen, der identifizierte Sicherheitslücken auf präskriptive Anweisungen zur Verbesserung der Entwicklungspraktiken abbildet. Das Tool deckt eine breite Oberfläche an Funktionen ab, einschließlich Open-Source-Sicherheitsaudits, CI/CD-Sicherheitsautomatisierung und der Analyse von Drittanbieter-Repositories zur Risikobewertung vor der Integration. Es unterstützt verschiedene Schnittstellen für die Interaktion, einschließlich eines Command-Line-Interfaces für Scans und eines REST-Interfaces zum Abrufen vorab berechneter Sicherheitsmetriken.
Automates security scans on every code commit through CI pipelines to alert maintainers of regressions.
Nettacker ist ein automatisiertes Penetration-Testing-Framework zur Orchestrierung von Reconnaissance, Port-Scanning und Schwachstellenerkennung. Es fungiert als Tool zur Netzwerkaufklärung und als Schwachstellenscanner, der offene Ports identifiziert, Services fingerprintet und Systeme gegen Datenbanken bekannter Sicherheitslücken prüft. Das Framework kombiniert einen Web-Application-Crawler zur Entdeckung versteckter Pfade via Fuzzing mit einem Vulnerability-Management-System, das Scan-Ergebnisse in einer Datenbank speichert, um historische Assessments nachzuverfolgen. Es bietet zudem spezialisierte Funktionen für Subdomain-Enumeration, Credential-Brute-Forcing und die Möglichkeit, Traffic zur Anonymisierung über Proxys zu leiten. Das System deckt ein breites Spektrum an Sicherheitsfunktionen ab, darunter Network-Asset-Discovery, Multi-Protokoll-Service-Auditing und Konfigurations-Audits. Es unterstützt Multi-Target-Scans über IP-Bereiche und CIDR-Blöcke hinweg und bietet Tools zur Generierung von Sicherheitsberichten in verschiedenen Formaten. Die programmatische Steuerung erfolgt über ein REST-basiertes Interface, wodurch das Framework in Security-Pipelines und Automatisierungs-Flows integriert werden kann.
Provides a mechanism to automatically trigger vulnerability assessments using defined modules and custom arguments.
w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing
Enables triggering vulnerability scans via API requests using target URLs and configuration profiles.
SSLyze is an SSL/TLS security scanner and network encryption analyzer designed to identify vulnerabilities and misconfigurations in encryption settings. It functions as both a standalone tool for analyzing server certificates and cipher suites and a programmable Python security library for embedding automated scanning logic into larger applications. The tool distinguishes itself by supporting encryption analysis for both HTTP and non-HTTP network services, including mail, directory, and database protocols. It includes a security compliance validator that compares server configurations against
Provides a programmable library to embed custom scanning logic into larger security applications.
ScopeSentry ist eine verteilte Plattform für das Angriffsflächenmanagement, die darauf ausgelegt ist, digitale Assets zu katalogisieren und Sicherheitsbewertungen über große Netzwerkumgebungen hinweg zu automatisieren. Sie fungiert als Tool zur Netzwerkerkennung und Schwachstellen-Scanner und bietet ein Framework zur Aufrechterhaltung der Sichtbarkeit über die organisatorische Infrastruktur. Die Plattform zeichnet sich durch eine verteilte Architektur aus, die Worker-Nodes orchestriert, um Sicherheitsaufgaben parallel auszuführen. Sie nutzt einen ereignisgesteuerten Erkennungsprozess, um neue Assets und Subdomänen zu identifizieren, und führt eine zustandsbehaftete Aufzeichnung von Konfigurationen und Schwächen, um die langfristige Erkennung von Änderungen zu erleichtern. Das System unterstützt eine modulare Ausführungspipeline, die die Integration benutzerdefinierter Plugins und Sicherheitsdienstprogramme von Drittanbietern ermöglicht. Diese Erweiterbarkeit ermöglicht eine umfassende Überwachung von Web-Assets, automatisierte Subdomänen-Enumeration und die Identifizierung von Fehlkonfigurationen oder Lecks sensibler Informationen über verteilte Umgebungen hinweg.
Automates the identification of security weaknesses and misconfigurations across identified assets.