awesome-repositories.com
Blog
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoAcerca deCómo clasificamosPrensaServidor MCP
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
1N3 avatar

1N3/Sn1per

0
View on GitHub↗
10,049 estrellas·2,077 forks·Shell·other·13 vistassn1persecurity.com↗

Sn1per

Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets.

The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan outputs and triage vulnerabilities, alongside an active exploit validation engine to eliminate false positives.

Its broader capabilities cover mobile application auditing for Android and iOS binaries, dark web leak monitoring, and asset risk assessment. The system provides a security analysis dashboard for managing multi-user workspaces, generating structured reports, and configuring security tools via a web interface.

The environment is deployed using containers and persistent volumes to ensure a reproducible runtime.

Features

  • Attack Surface Management - Discovers and monitors internet-facing assets using OSINT and DNS enumeration to identify organizational exposures.
  • Penetration Testing Platforms - Provides a comprehensive platform for orchestrating vulnerability detection and automated exploit verification.
  • Security Orchestration - Orchestrates a unified automated pipeline combining multiple reconnaissance, scanning, and exploitation tools.
  • Continuous Security Monitoring - Performs continuous discovery and active exploitation of external assets to identify and track security gaps.

Búsqueda con IA

Explora más repositorios increíbles

Describe lo que necesitas en lenguaje sencillo: la IA clasifica miles de proyectos open-source curados por relevancia.

Start searching with AI
  • OSINT and Reconnaissance - Gathers passive intelligence and threat data about a target from public sources without direct interaction.
  • Scanner Orchestrators - Orchestrates multiple external vulnerability scanners to identify security flaws across various hosts.
  • Web Vulnerability Scanning - Automates vulnerability scanning for web targets and generates structured HTML reports.
  • Workspace Organization - Organizes targets, scan configurations, and live results into isolated environments to track engagement progress.
  • Docker Container Deployments - Packages the security toolkit and its dependencies into Docker images for a reproducible runtime.
  • Containerized Deployments - Provides a containerized deployment to ensure a reproducible and consistent security toolkit runtime.
  • AI-Powered Scan Interpretation - Employs large language models to summarize scan output, triage vulnerabilities, and determine subsequent scanning steps.
  • Attack Surface Mapping - Discovers and monitors internet-facing assets to identify unknown exposures and track changes in the organizational perimeter.
  • Exploit Frameworks - Runs specialized functional modules for brute forcing and fuzzing through a library of curated exploit signatures.
  • Exploitation Workflow Managers - Orchestrates the end-to-end security pipeline from reconnaissance to exploit verification to streamline penetration testing.
  • Finding Classification - Centralizes results from multiple scanning tools into a single interface for scoring and triage.
  • Security Analysis Dashboards - Provides a web interface for managing security workspaces, analyzing APK binaries, and visualizing risk scores.
  • AI-Powered Security Operations - Uses large language models to summarize scan outputs and automate the triage of identified vulnerabilities.
  • Subdomain Enumeration Tools - Discovers hidden and public subdomains using a variety of passive and active DNS reconnaissance techniques.
  • Exploitability Validation - Implements active exploitation tests to verify the exploitability of identified vulnerabilities and eliminate false positives.
  • Vulnerability Management - Centralizes security findings from multiple tools into a single interface for risk scoring and triage.
  • Reachability Prioritizers - Calculates risk scores based on criticality and exploitability to prioritize the remediation of vulnerabilities.
  • Automated Security Scan Triggers - Provides an API to automatically trigger reconnaissance and vulnerability scans using configurable logic gates.
  • Vulnerability Retesters - Verifies the accuracy of identified security flaws through active exploitation and re-testing.
  • Web Security Analysis - Crawls web targets to identify security holes, CMS versions, and underlying directory structures.
  • Security Tool Orchestration Pipelines - Coordinates a pipeline of third-party scanners and tools by normalizing outputs into a unified data format.
  • Workflow Logic Engines - Executes complex security sequences from discovery to exploitation based on conditional triggers and verification steps.
  • Autonomous Penetration Testing - Automates the full security assessment lifecycle from reconnaissance to exploit verification.
  • Subdomain Discovery - Extracts subdomains from GitHub to expand the known attack surface of a target domain.
  • Web Application Fuzzing - Ships capabilities to discover hidden directories and parameters in web applications using automated fuzzing payloads.
  • Cloud Infrastructure Discovery - Identifies publicly accessible cloud storage buckets to find potentially exposed sensitive data.
  • Email and Identity Discovery - Queries external APIs to discover associated email addresses and professional identities during reconnaissance.
  • Request Smuggling - Detects HTTP request smuggling vulnerabilities using active probes to confirm exploitability.
  • Subdomain Takeover Tools - Scans for dangling DNS records to detect and prevent potential subdomain takeover vulnerabilities.
  • Automated Audit Schedulers - Automates the execution of security tools on fixed timetables using cron jobs for continuous monitoring.
  • Workspace Collaboration - Coordinates penetration testing efforts across teams through shared workspaces and joint access to data.
  • Workspace Isolation - Organizes engagement data and scan results into isolated, dedicated workspaces for team collaboration.
  • Security Data Endpoints - Provides secure JSON endpoints to programmatically retrieve workspaces, host details, and vulnerability data.
  • Scan Data Importers - Ingests scan results and shell access from third-party exploitation frameworks into a centralized workspace via API.
  • Retrieval Augmentation - Integrates large language models with security knowledge bases to summarize scan findings and triage vulnerabilities.
  • Cron Scheduling - Uses system-level cron timers to automate recurring reconnaissance and attack surface monitoring.
  • Security Automation Workflows - Connects security scanning processes to CI/CD pipelines and notification platforms via a standardized JSON API.
  • Port Scanners - Maps open ports and network services using integrated scanning engines to define the attack surface.
  • Mobile Binary Analysis - Enables decompilation and analysis of Android binaries through a browser-based interface.
  • Credential Auditing Tools - Includes utilities to scan across multiple hosts for default and weak passwords to identify unauthorized access.
  • Dark Web Monitoring - Scans dark web sources and breach databases for leaked credentials and organizational mentions.
  • Exploit Execution Engines - Launches network and web-based exploit modules and manages listener configurations for callbacks.
  • Attack Simulations - Executes automated exploitation chains with stealth modes to simulate adversary attacks and bypass security defenses.
  • Security Report Generation - Generates findings summaries in CSV, Excel, PDF, HTML, and JSON formats for external documentation.
  • Security Reporting Tools - Generates structured security findings and host inventory reports in JSON, CSV, and TXT formats.
  • Threat Intelligence Platforms - Incorporates data from external threat feeds and security databases directly into the scanning workflow.
  • Contextual Enrichment - Integrates a retrieval engine to correlate scan findings with industry security databases.
  • Exposure Monitoring - Tracks the attack surface on a configurable schedule and alerts on new exposures.
  • Mobile App Security Auditing - Analyzes Android and iOS binaries through decompilation and static analysis to identify internal logic flaws.
  • Credential Brute-Forcing - Provides automated testing of authentication credentials through systematic brute-force attacks.
  • Mobile Application Scanners - Analyzes iOS and Android binaries through static analysis, dynamic instrumentation, and certificate-pinning bypasses.
  • Vulnerability Scanner Integrations - Integrates with OpenVAS instances to perform comprehensive vulnerability assessments across specific port lists.
  • Asset Risk Scoring - Calculates individual asset risk scores and generates vulnerability matrices to prioritize remediation efforts.
  • Data Leak Monitors - Scans GitHub for leaked credentials or sensitive information and sends alerts to messaging platforms.
  • Security Exposure Alerts - Sends automated alerts via Slack, email, or SIEM when new exposures are detected.
  • Workflow Management Dashboards - Provides a centralized dashboard to track host counts, scan timestamps, and risk levels across multiple engagements.
  • Open Source Intelligence - Automated reconnaissance and penetration testing scanner.
  • Security Frameworks - Automated pentest framework for offensive security operations.
  • Exploitation Frameworks - Automated reconnaissance and exploitation framework.
  • Information Gathering - Automates reconnaissance and vulnerability scanning tasks.
  • Penetration Testing Frameworks - Automated framework for offensive security professionals.
  • Security Tools - Automated pentest framework for offensive security experts.
  • Vulnerability Scanners - Automated pentest framework for offensive security.
  • Vulnerability Scanning - Automated scanner for web application and network testing.
  • Historial de estrellas

    Gráfico del historial de estrellas de 1n3/sn1perGráfico del historial de estrellas de 1n3/sn1per

    Alternativas open-source a Sn1per

    Proyectos open-source similares, clasificados según cuántas características comparten con Sn1per.
    • six2dez/reconftwAvatar de six2dez

      six2dez/reconftw

      7,226Ver en GitHub↗

      reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio

      Shellbug-bountybugbountybugbounty-tool
      Ver en GitHub↗7,226
    • blacklanternsecurity/bbotAvatar de blacklanternsecurity

      blacklanternsecurity/bbot

      9,929Ver en GitHub↗

      This project is an open-source intelligence reconnaissance framework and recursive attack surface mapper. It functions as a containerized security scanner designed to map public-facing infrastructure, perform subdomain enumeration, and automate the gathering of open-source intelligence. The system employs a recursive discovery engine to iteratively explore target infrastructure, utilizing a plugin-based module architecture to extend scanning capabilities. It integrates third-party APIs for data enrichment and applies YARA rules across discovered assets to identify specific vulnerability patte

      Python
      Ver en GitHub↗9,929
    • projectdiscovery/subfinderAvatar de projectdiscovery

      projectdiscovery/subfinder

      13,105Ver en GitHub↗

      Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It functions as a discovery engine that identifies and maps internet-exposed infrastructure, cloud-hosted assets, and network ranges to maintain a comprehensive inventory of an organization's digital footprint. The project distinguishes itself through a modular, template-driven scanning engine that executes security checks against discovered assets. It leverages cloud-native asset discovery to query provider APIs and infrastructure metadata, while supporting distributed agent orc

      Gobugbountyhackinghacktoberfest
      Ver en GitHub↗13,105
    • yogeshojha/rengineAvatar de yogeshojha

      yogeshojha/rengine

      8,472Ver en GitHub↗

      Rengine is an automated reconnaissance framework and vulnerability management platform designed for attack surface monitoring. It functions as a centralized hub for discovering subdomains and open ports, gathering open-source intelligence, and tracking security flaws across target networks. The system integrates large language models to analyze reconnaissance data and generate vulnerability descriptions and insights. It distinguishes itself through a plugin-based tool integration that wraps external security scanning binaries and a target mapping system that tracks changes to assets over time

      HTMLbug-bountybugbountyhacking
      Ver en GitHub↗8,472
    Ver las 30 alternativas a Sn1per→

    Preguntas frecuentes

    ¿Qué hace 1n3/sn1per?

    Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets.

    ¿Cuáles son las características principales de 1n3/sn1per?

    Las características principales de 1n3/sn1per son: Attack Surface Management, Penetration Testing Platforms, Security Orchestration, Continuous Security Monitoring, OSINT and Reconnaissance, Scanner Orchestrators, Web Vulnerability Scanning, Workspace Organization.

    ¿Qué alternativas de código abierto existen para 1n3/sn1per?

    Las alternativas de código abierto para 1n3/sn1per incluyen: six2dez/reconftw — reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the… blacklanternsecurity/bbot — This project is an open-source intelligence reconnaissance framework and recursive attack surface mapper. It functions… projectdiscovery/subfinder — Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It… yogeshojha/rengine — Rengine is an automated reconnaissance framework and vulnerability management platform designed for attack surface… owasp/nettacker — Nettacker is an automated penetration testing framework designed to orchestrate reconnaissance, port scanning, and… jaykali/maskphish — Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network…