For a vulnerability management platform, the first results are infobyte/faraday (Faraday is a full-featured vulnerability management platform that aggregates findings from diverse security scanners into a single dashboard, tracks remediation, and analyzes risk, fitting this search for a centralized, open-source solution), wazuh/wazuh (Wazuh is a full-featured open-source security platform that provides vulnerability scanning, asset inventory, continuous monitoring, and dashboards, making it a strong fit for a centralized vulnerability management tool with remediation tracking and integrations) and yogeshojha/rengine (Rengine is an open-source vulnerability management platform that continuously monitors attack surfaces, discovers assets, runs vulnerability scans via plugins, and provides centralized tracking and reporting for remediation — fitting this search squarely). defectdojo/django-defectdojo and 1n3/sn1per round out the shortlist. Compare the match explanations and check the project documentation against your requirements.
Automated platforms for continuously monitoring, identifying, and remediating security vulnerabilities across your digital infrastructure assets.
Faraday is a vulnerability management platform and security tool aggregator designed to centralize security findings from multiple scanners into a single dashboard. It utilizes a relational security database to catalog hosts, services, and security flaws, enabling users to track remediation and analyze organizational risk. The platform distinguishes itself through a plugin-based system that normalizes diverse security tool outputs into a unified data model. It supports deep integration with a wide array of scanners and CLI tools, intercepting shell command output or parsing report files to ag
Faraday is a full-featured vulnerability management platform that aggregates findings from diverse security scanners into a single dashboard, tracks remediation, and analyzes risk, fitting this search for a centralized, open-source solution.
Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity. The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monito
Wazuh is a full-featured open-source security platform that provides vulnerability scanning, asset inventory, continuous monitoring, and dashboards, making it a strong fit for a centralized vulnerability management tool with remediation tracking and integrations.
Rengine is an automated reconnaissance framework and vulnerability management platform designed for attack surface monitoring. It functions as a centralized hub for discovering subdomains and open ports, gathering open-source intelligence, and tracking security flaws across target networks. The system integrates large language models to analyze reconnaissance data and generate vulnerability descriptions and insights. It distinguishes itself through a plugin-based tool integration that wraps external security scanning binaries and a target mapping system that tracks changes to assets over time
Rengine is an open-source vulnerability management platform that continuously monitors attack surfaces, discovers assets, runs vulnerability scans via plugins, and provides centralized tracking and reporting for remediation — fitting this search squarely.
DefectDojo is a vulnerability management system and application security orchestration tool. It serves as a centralized platform for importing, deduplicating, and tracking security findings from multiple scanners and tools to manage an organization's overall security posture. The system distinguishes itself by aggregating findings from various security tools into a single report and normalizing that data to prioritize remediation. It provides specific workflows for vulnerability triage and deduplication to reduce noise and redundant manual work across the software development lifecycle. The
DefectDojo aggregates findings from multiple security scanners, normalizes them for prioritization, tracks remediation, and provides dashboards and reporting, making it a comprehensive open-source vulnerability management platform that fits your need for centralized, continuous monitoring and tracking.
Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets. The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan
Sn1per is a vulnerability management platform that automates reconnaissance, scanning, and AI-powered analysis, with attack surface discovery and continuous monitoring, closely matching the need for a centralized detection and remediation tool.
Fscan is an automated penetration testing tool designed for internal network reconnaissance and vulnerability assessment. It functions as a comprehensive security framework that maps network infrastructure, identifies active hosts and services, and detects security weaknesses across internal environments. The tool distinguishes itself through a modular plugin architecture that allows for extensible security checks and a stateful asset tracking system that maintains an in-memory registry of discovered infrastructure. It incorporates a dedicated credential brute-force engine for testing passwor
Fscan is an automated penetration testing and vulnerability assessment tool for internal network reconnaissance, which performs scanning and detection, but it is not a continuous vulnerability management platform with centralized remediation tracking, risk-based prioritization, or sustained monitoring and reporting features.
Vuls is an agentless vulnerability scanner and CVE intelligence aggregator. It identifies security flaws in operating systems, containers, and network devices without requiring the installation of permanent software agents on target machines. The project distinguishes itself by cross-referencing software versions against multiple vulnerability databases, security advisories, and known exploit catalogs. It utilizes platform-based enumeration and lockfile analysis to detect vulnerabilities in network hardware, programming libraries, and website plugins. The tool covers a broad range of securit
Vuls is an agentless vulnerability scanner and CVE aggregator, but it is a scanning component rather than a full vulnerability management platform with built-in asset inventory, risk-based prioritization, remediation tracking, and centralized dashboards.
afrog is an HTTP vulnerability scanner and web vulnerability management system that identifies security flaws and known CVEs using a YAML-based rule engine. It functions as a payload generator and scanner, comparing server responses against detection rules to find unauthorized access points. The project provides a framework for out-of-band security testing, detecting blind vulnerabilities by triggering and verifying external DNS or HTTP callbacks. Beyond web traffic, it includes a protocol fuzzer capable of executing multi-step read and write sequences over raw TCP and SSL sockets to identify
afrog is a powerful HTTP vulnerability scanner with PoC execution and fuzzing, but it is primarily a scanning tool rather than a full vulnerability management platform with asset inventory, remediation tracking, and integrated dashboards.
Kubescape is a security platform for Kubernetes that provides tools for scanning clusters, configurations, and container images against industry compliance and security benchmarks. It functions as a suite of security utilities, including a compliance auditor, a misconfiguration scanner, and a container vulnerability scanner. The project differentiates itself through automated remediation and active enforcement. It can automatically patch operating system vulnerabilities in images and fix security errors within manifest files. It also utilizes an admission controller to block the deployment of
Kubescape is a powerful Kubernetes security scanner that detects vulnerabilities in container images and configurations, but it is limited to Kubernetes environments and does not cover the full range of assets (servers, cloud, networks) that a general vulnerability management platform should monitor and track.
This project is an AI-powered static analysis tool and automated vulnerability scanner designed to detect security flaws such as injection and authentication bypasses. It uses large language models to perform semantic reasoning across multiple programming languages, identifying vulnerabilities within code changes. The tool operates as a GitHub Action that integrates into continuous integration pipelines to analyze pull request diffs. It focuses on modified lines of code to target new risks and reports findings by posting automated comments directly to the pull request. Analysis is directed b
This is an AI-powered static analysis scanner that finds vulnerabilities in pull request diffs via a GitHub Action, but it lacks the asset inventory, continuous monitoring across all assets, risk-based prioritization, remediation tracking, and centralized dashboard that define a full vulnerability management platform.
Brakeman is a static analysis security tool and scanner specifically designed for Ruby on Rails source code. It identifies common security vulnerabilities, such as injection and cross-site scripting, by analyzing the application codebase without executing the application. The tool functions as a security auditor that detects mass assignment risks and template vulnerabilities. It evaluates the final output of rendered views and identifies unrestricted assignment patterns that could allow unauthorized modification of model attributes. The system provides vulnerability management through the us
Brakeman is a static analysis security scanner for Ruby on Rails code, not a continuous vulnerability management platform—it scans code on demand rather than monitoring assets across an organization with inventory, prioritization, and remediation tracking.
Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ
Nuclei is a fast, template-driven vulnerability scanner that excels at automated detection, but it is not a centralized vulnerability management platform—it lacks built-in asset inventory, remediation tracking, and dashboards needed for continuous monitoring and prioritization across an organization.
| Repository | Stars | Language | License | Last push |
|---|---|---|---|---|
| infobyte/faraday | 6.5K | Python | GPL-3.0 | |
| wazuh/wazuh | 14.8K | C | other | |
| yogeshojha/rengine |
| 8.5K |
| HTML |
| gpl-3.0 |
| defectdojo/django-defectdojo | 4.5K | HTML | bsd-3-clause |
| 1n3/sn1per | 10K | Shell | other |
| shadow1ng/fscan | 13.4K | Go | mit |
| future-architect/vuls | 12.2K | Go | GPL-3.0 |
| zan8in/afrog | 4.2K | Go | mit |
| armosec/kubescape | 11.5K | Go | Apache-2.0 |
| anthropics/claude-code-security-review | 5.3K | Python | MIT |