awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com

Open-Source Alternatives to Qualys

Ranking updated Aug 19, 2026

For an open source vulnerability scanner for infrastructure, the strongest matches are autumn-27/scopesentry (ScopeSentry is a distributed attack surface management platform that), owasp-amass/amass (Amass is a robust asset discovery and attack surface) and google/tsunami-security-scanner (This is a network vulnerability scanner featuring a modular). owasp/nettacker and sullo/nikto round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

We curate open-source GitHub repositories matching “open source alternatives to qualys”. Results are ranked by relevance to your query — pick filters below to narrow, or refine with AI.

Open-Source Alternatives to Qualys

Find the best repos with AI.We'll search the best matching repositories with AI.
  • autumn-27/scopesentryAutumn-27 avatar

    Autumn-27/ScopeSentry

    1,519View on GitHub↗

    ScopeSentry is a distributed attack surface management platform designed to catalog digital assets and automate security assessments across large network environments. It functions as a network asset discovery tool and vulnerability scanner, providing a framework for maintaining visibility over organizational infrastructure. The platform distinguishes itself through a distributed architecture that orchestrates worker nodes to execute security tasks in parallel. It utilizes an event-driven discovery process to identify new assets and subdomains, maintaining a stateful record of configurations

    ScopeSentry is a distributed attack surface management platform that covers network asset discovery and vulnerability scanning, matching the core capabilities needed for infrastructure visibility.

    GoAsset Discovery ToolsVulnerability ScannersAttack Surface Management
    View on GitHub↗1,519
  • owasp-amass/amassowasp-amass avatar

    owasp-amass/amass

    14,155View on GitHub↗

    Amass is an attack surface management tool designed to identify, map, and inventory an organization's internet-facing digital assets. It functions as a security asset discovery engine that systematically expands an organization's known infrastructure footprint through recursive domain name resolution and the collection of intelligence from diverse public data sources. The platform distinguishes itself by utilizing a graph-based modeling approach to organize discovered resources. By maintaining a persistent graph database, it tracks the relationships between infrastructure components and norma

    Amass is a robust asset discovery and attack surface management tool that maps an organization's digital footprint using graph-based intelligence, though it focuses primarily on reconnaissance rather than performing full vulnerability scanning or compliance checking.

    GoAsset Discovery ToolsAttack Surface Management
    View on GitHub↗14,155
  • google/tsunami-security-scannergoogle avatar

    google/tsunami-security-scanner

    8,584View on GitHub↗

    Tsunami Security Scanner is a network vulnerability scanner and security auditor designed to identify high-severity flaws across network assets. It functions as an asynchronous security probe engine that utilizes automated probes and specialized detection logic to find critical weaknesses and prioritize remediation efforts. The project is distinguished by a plugin-based scanning engine, which uses a modular architecture of interchangeable detection plugins to identify vulnerabilities. This extensibility allows for the development and integration of custom security plugins to expand the variet

    This is a network vulnerability scanner featuring a modular, plugin-based architecture for identifying high-severity flaws, though it lacks some of the broader asset discovery and web application scanning features found in comprehensive enterprise platforms.

    JavaNetwork Vulnerability ScanningNetwork Vulnerability ScanningVulnerability Scanners
    View on GitHub↗8,584
  • owasp/nettackerOWASP avatar

    OWASP/Nettacker

    5,258View on GitHub↗

    Nettacker is an automated penetration testing framework designed to orchestrate reconnaissance, port scanning, and vulnerability detection. It functions as a network reconnaissance tool and vulnerability scanner that identifies open ports, fingerprints services, and checks systems against databases of known security flaws. The framework distinguishes itself by combining a web application crawler for discovering hidden paths via fuzzing with a vulnerability management system that persists scan results in a database to track historical assessments. It also includes specialized capabilities for

    Nettacker is an automated penetration testing framework that provides vulnerability scanning, asset discovery, and network reconnaissance capabilities, though it leans more toward offensive pentesting than an enterprise vulnerability management platform.

    PythonNetwork Vulnerability ScanningVulnerability ScannersNetwork Vulnerability Databases
    View on GitHub↗5,258
  • sullo/niktosullo avatar

    sullo/nikto

    10,104View on GitHub↗

    Nikto is an open-source HTTP security auditing tool and web server vulnerability scanner. It functions as a reconnaissance engine designed to identify insecure server options, outdated software, and common vulnerabilities by analyzing HTTP responses. The project differentiates itself through capabilities for intrusion detection evasion and web server fingerprinting. It uses request-level encoding and timing spacers to bypass security filters and employs signature-based identification to determine specific server software versions and misconfigurations. The scanner covers broad capability are

    Nikto is an open-source web server vulnerability scanner that handles web application auditing and reconnaissance, though it lacks broader enterprise asset discovery and compliance checking features.

    PerlVulnerability ScannersWeb Vulnerability Scanners
    View on GitHub↗10,104
  • projectdiscovery/nucleiprojectdiscovery avatar

    projectdiscovery/nuclei

    29,189View on GitHub↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Nuclei is a powerful template-driven vulnerability scanner and reconnaissance framework that covers asset discovery and vulnerability detection, though it operates as a modular CLI tool rather than an all-in-one enterprise platform with built-in compliance dashboards.

    GoAsset Discovery ToolsVulnerability ScannersAttack Surface Management
    View on GitHub↗29,189
  • aquasecurity/kube-hunteraquasecurity avatar

    aquasecurity/kube-hunter

    5,064View on GitHub↗

    Kube-hunter is a security scanner and vulnerability hunter for Kubernetes clusters. It operates as a cloud-native penetration tool designed to identify security weaknesses, infrastructure misconfigurations, and exploitable gaps by simulating attacker techniques. The tool distinguishes itself through a dual-mode scanning engine that executes both remote external probes and internal network scans. It features identity-based impersonation, allowing it to use service account tokens and pod identities to simulate security access from specific cluster roles and determine the potential blast radius

    Kube-hunter is an open-source security tool tailored specifically for discovering vulnerabilities and misconfigurations in Kubernetes clusters, making it a specialized asset and security scanner for that domain.

    PythonNetwork Vulnerability Scanning
    View on GitHub↗5,064
  • deepfence/threatmapperdeepfence avatar

    deepfence/ThreatMapper

    5,282View on GitHub↗

    ThreatMapper is a cloud native application protection platform and infrastructure security scanner. It functions as a vulnerability management system and cloud workload telemetry collector designed to monitor workloads and detect security risks across cloud and container environments. The platform distinguishes itself through a network traffic visualizer that uses machine learning to classify communication patterns and a graph-based attack mapping system to identify high-risk paths between vulnerabilities and network dependencies. Its broader capabilities cover cloud infrastructure complianc

    ThreatMapper is a cloud-native vulnerability management and security scanner designed for infrastructure and container workloads, covering most of the requested scanning and asset discovery features even though it specializes in modern cloud environments rather than traditional enterprise networks.

    TypeScriptCompliance Security Audits
    View on GitHub↗5,282
  • usestrix/strixusestrix avatar

    usestrix/strix

    20,138View on GitHub↗

    Strix is an automated security research and vulnerability scanning platform that leverages language models to orchestrate complex security analysis tasks. It functions as a comprehensive framework for penetration testing and continuous security integration, allowing users to embed automated vulnerability research directly into development pipelines or execute it within isolated, containerized environments. The platform distinguishes itself through a multi-agent orchestration engine that coordinates specialized autonomous agents to perform parallel security assessments. By integrating LLM-agno

    Strix is an automated security research and vulnerability scanning platform featuring agent-based orchestration and analysis engines, though it leans more toward AI-driven penetration testing than traditional enterprise asset management and compliance reporting.

    PythonVulnerability ScannersAttack Surface ManagementSecurity Reporting Tools
    View on GitHub↗20,138
  • 1n3/sn1per1N3 avatar

    1N3/Sn1per

    10,049View on GitHub↗

    Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets. The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan

    Sn1per is a vulnerability management platform that automates asset discovery and security scanning across networks and web applications, fulfilling the core requirements despite its script-heavy orchestration approach.

    ShellAttack Surface ManagementSecurity Reporting Tools
    View on GitHub↗10,049
  • aquasecurity/trivyaquasecurity avatar

    aquasecurity/trivy

    36,462View on GitHub↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Trivy is a vulnerability and misconfiguration scanner focused on containers, filesystems, and infrastructure-as-code files, which makes it a strong security tool despite lacking broader network discovery features.

    GoVulnerability Scanners
    View on GitHub↗36,462
  • future-architect/vulsfuture-architect avatar

    future-architect/vuls

    12,185View on GitHub↗

    Vuls is an agentless vulnerability scanner and CVE intelligence aggregator. It identifies security flaws in operating systems, containers, and network devices without requiring the installation of permanent software agents on target machines. The project distinguishes itself by cross-referencing software versions against multiple vulnerability databases, security advisories, and known exploit catalogs. It utilizes platform-based enumeration and lockfile analysis to detect vulnerabilities in network hardware, programming libraries, and website plugins. The tool covers a broad range of securit

    Vuls is a vulnerability scanner that identifies security flaws in operating systems, containers, and network devices, fitting the core intent while lacking an all-in-one web application scanning and dashboard suite.

    GoVulnerability Scanners
    View on GitHub↗12,185
  • zan8in/afrogzan8in avatar

    zan8in/afrog

    4,182View on GitHub↗

    afrog is an HTTP vulnerability scanner and web vulnerability management system that identifies security flaws and known CVEs using a YAML-based rule engine. It functions as a payload generator and scanner, comparing server responses against detection rules to find unauthorized access points. The project provides a framework for out-of-band security testing, detecting blind vulnerabilities by triggering and verifying external DNS or HTTP callbacks. Beyond web traffic, it includes a protocol fuzzer capable of executing multi-step read and write sequences over raw TCP and SSL sockets to identify

    Afrog provides HTTP and web vulnerability scanning via a YAML-based rule engine, making it a capable tool for web security assessment even though it lacks broader enterprise asset management and compliance workflows.

    GoVulnerability Scanners
    View on GitHub↗4,182
  • lissy93/web-checkLissy93 avatar

    Lissy93/web-check

    33,721View on GitHub↗

    Web-check is a self-hosted diagnostic platform designed to perform comprehensive technical reconnaissance and security audits on web domains. It functions as a network scanner that inspects infrastructure by querying IP addresses, DNS records, SSL certificate chains, and server headers to identify potential misconfigurations or vulnerabilities. The platform is built to run within private infrastructure, ensuring that site investigations remain independent of external tracking or third-party data logging. By utilizing server-side request proxying, the tool bypasses client-side security restric

    Web-check is a self-hosted reconnaissance and diagnostic platform that inspects infrastructure and web configurations, functioning as a targeted reconnaissance tool for web applications even though it lacks full enterprise vulnerability management suites like compliance checking.

    TypeScriptWebsite Diagnostic ToolsInfrastructure MonitoringSecurity Auditing
    View on GitHub↗33,721
  • chaitin/xraychaitin avatar

    chaitin/xray

    11,612View on GitHub↗

    Xray is a security assessment tool focused on web vulnerability scanning, attack surface mapping, and technology fingerprinting. It identifies common security flaws through automated scanning and semantic analysis, while verifying findings via a custom proof-of-concept execution engine. The system distinguishes itself with a containerized vulnerability testbed used to deploy pre-configured vulnerable applications. This environment allows for the simulation of specific vulnerabilities and edge-case scenarios to validate scanner accuracy and eliminate false positives. The platform covers a bro

    Xray is a web vulnerability scanner and attack surface mapping tool with plugin extensibility, though it focuses more on web application assessments than broad enterprise infrastructure asset management.

    VueSecurity Assessment FrameworksWeb Vulnerability ScanningAttack Surface Mapping
    View on GitHub↗11,612
  • defectdojo/django-defectdojoDefectDojo avatar

    DefectDojo/django-DefectDojo

    4,528View on GitHub↗

    DefectDojo is a vulnerability management system and application security orchestration tool. It serves as a centralized platform for importing, deduplicating, and tracking security findings from multiple scanners and tools to manage an organization's overall security posture. The system distinguishes itself by aggregating findings from various security tools into a single report and normalizing that data to prioritize remediation. It provides specific workflows for vulnerability triage and deduplication to reduce noise and redundant manual work across the software development lifecycle. The

    DefectDojo is a centralized vulnerability management and application security orchestration platform that aggregates findings and tracks security posture, though it acts as a management system rather than a direct active scanner.

    HTMLVulnerability ManagementVulnerability Management SystemsAsset Hierarchy Modeling
    View on GitHub↗4,528
Compare the top 10 at a glance
RepositoryStarsLanguageLicenseLast push
autumn-27/scopesentry1.5KGo—Jun 12, 2026
owasp-amass/amass14.2KGootherFeb 22, 2026
google/tsunami-security-scanner8.6KJavaApache-2.0Jun 11, 2026
owasp/nettacker5.3KPythonApache-2.0Jun 19, 2026
sullo/nikto10.1KPerlotherFeb 19, 2026
projectdiscovery/nuclei29.2KGoMITJun 15, 2026
aquasecurity/kube-hunter5.1KPythonApache-2.0Mar 19, 2024
deepfence/threatmapper5.3KTypeScriptApache-2.0Jun 1, 2026
usestrix/strix20.1KPythonapache-2.0Feb 19, 2026
1n3/sn1per10KShellotherApr 29, 2026

Related searches

  • an open source scanner for security vulnerabilities
  • an open source file and url scanner
  • an open source antivirus software for servers
  • an open source technology stack detector
  • an open source malware scanner and remover
  • an open source alternative to BuiltWith
  • an open source alternative to SolarWinds
  • an open source tool for network security