awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
OWASP avatar

OWASP/Nettacker

0
View on GitHub↗
5,258 stars·1,113 forks·Python·Apache-2.0·48 viewsowasp.org/nettacker↗

Nettacker

Nettacker is an automated penetration testing framework designed to orchestrate reconnaissance, port scanning, and vulnerability detection. It functions as a network reconnaissance tool and vulnerability scanner that identifies open ports, fingerprints services, and checks systems against databases of known security flaws.

The framework distinguishes itself by combining a web application crawler for discovering hidden paths via fuzzing with a vulnerability management system that persists scan results in a database to track historical assessments. It also includes specialized capabilities for subdomain enumeration, credential brute forcing, and the ability to route traffic through proxies for anonymization.

The system covers a broad surface of security capabilities, including network asset discovery, multi-protocol service auditing, and configuration auditing. It supports multi-target scanning across IP ranges and CIDR blocks, and provides tools for generating security reports in multiple formats.

Programmatic control is available via a REST-based interface, allowing the framework to be integrated into security pipelines and automation flows.

Features

  • Network Vulnerability Scanning - Performs comprehensive scanning of network assets to identify security weaknesses and misconfigurations across infrastructure.
  • Reconnaissance Workflow Orchestrators - Orchestrates the full sequence of reconnaissance, port scanning, and vulnerability detection into an automated workflow.
  • Penetration Testing Frameworks - Provides a complete software environment to automate the discovery and exploitation of network security weaknesses.
  • Web Application Crawlers - Combines automated web crawling and input fuzzing to discover hidden paths and vulnerabilities in web applications.
  • Network Device Discovery - Maps the attack surface by discovering active devices, open ports, and subdomains across target networks.
  • Penetration Testing - Provides a comprehensive framework for conducting automated penetration testing through orchestrated reconnaissance and scanning.
  • Audit Result Persistence - Includes an internal database for persisting security audit findings and metadata for compliance tracking.
  • Relational Database Persistence - Uses relational databases to persist historical scan results and configurations for long-term tracking.
  • Recursive Crawl Discoverers - Automatically discovers application endpoints and hidden paths using recursive crawling and input fuzzing.
  • Attack Surface Mapping - Maps internet-facing assets and hidden subdomains to identify and document organizational exposure.
  • External Asset Discovery - Discovers external-facing domains, IPs, and subdomains to map the external footprint of a target.
  • Target-Agnostic Scanning - Supports a wide variety of target inputs including IP ranges, CIDR blocks, and domains for flexible network probing.
  • Network Security Auditing - Audits network services and server configurations for misconfigurations, outdated patches, and weak credentials.
  • Reconnaissance Workflow Automation - Automates the sequence of subdomain enumeration and vulnerability scanning to gather target intelligence.
  • Network Vulnerability Databases - Checks targets against comprehensive databases of known security flaws and common vulnerabilities.
  • Vulnerability Scanners - Implements automated tools to identify open ports, fingerprint services, and detect known security flaws in infrastructure.
  • Service Fingerprinting - Uses a detection engine to identify specific software versions and server banners via network probes.
  • Subdomain Enumeration Tools - Provides utilities for enumerating and discovering subdomains to expand the analysis surface area.
  • Network Reconnaissance Tools - Ships a suite for scanning networks to identify active services and map the target attack surface.
  • Vulnerability Scanning Workflows - Implements a workflow for scanning known security flaws and persisting results for remediation tracking.
  • Offline Vulnerability Analysis - Analyzes network services and device configurations against known bugs and security weaknesses.
  • Scanning Module Systems - Organizes vulnerability tests into discrete, interchangeable modules that can be grouped into targeted scan profiles.
  • Scan Management APIs - Ships a RESTful API for triggering on-demand security scans and managing scan records.
  • Security Scanning Integrations - Connects automated security scans into CI/CD pipelines via a programmatic interface.
  • Scan Configuration Profiles - Provides a system for grouping scanning modules into reusable profiles for standardized security audits.
  • Multi-Format Target Scanning - Accepts IP ranges, CIDR blocks, and domain names as input to perform scans across multiple targets.
  • Multi-Format Vulnerability Reports - Generates security scan reports in multiple formats including HTML, JSON, and SARIF for stakeholder review.
  • Multi-Protocol Vulnerability Scanning - Provides a probe capable of assessing diverse protocols for system vulnerabilities.
  • Web Application Fuzzers - Provides an active execution engine that generates HTTP inputs to discover vulnerabilities and hidden paths in web applications.
  • Credential Brute-Forcing - Provides a systematic tool for testing common login combinations to identify unauthorized access vulnerabilities.
  • Vulnerability Management Systems - Includes a centralized platform to persist scan results in a database and track historical security assessments.
  • CI Pipeline Integration - Provides a programmatic interface to integrate automated vulnerability scans directly into CI build processes.
  • Device Discovery Engines - Implements a network scanning tool that identifies active devices and services across a target network.
  • Automated Security Scan Triggers - Provides a mechanism to automatically trigger vulnerability assessments using defined modules and custom arguments.
  • Web Crawlers - Provides an automated tool to discover application endpoints and map the structure of web applications through crawling.
  • Security Configuration Auditing - Inspects server settings and HTTP headers to identify security misconfigurations and missing security headers.
  • Remote Control Interfaces - Exposes a programmatic interface for remote control and management of security scanning processes.
  • Application Security - Automated penetration testing and vulnerability scanning framework.
  • Vulnerability Scanning and Auditing - Automated information gathering and vulnerability scanning.

Star history

Star history chart for owasp/nettackerStar history chart for owasp/nettacker

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with Nettacker

These projects share indexed features with Nettacker. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • jaykali/maskphishjaykali avatar

    jaykali/maskphish

    3,020View on GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Shellhackhackinghacking-tool
    View on GitHub↗3,020
  • google/tsunami-security-scannergoogle avatar

    google/tsunami-security-scanner

    8,584View on GitHub↗

    Tsunami Security Scanner is a network vulnerability scanner and security auditor designed to identify high-severity flaws across network assets. It functions as an asynchronous security probe engine that utilizes automated probes and specialized detection logic to find critical weaknesses and prioritize remediation efforts. The project is distinguished by a plugin-based scanning engine, which uses a modular architecture of interchangeable detection plugins to identify vulnerabilities. This extensibility allows for the development and integration of custom security plugins to expand the variet

    Java
    View on GitHub↗8,584
  • guelfoweb/knockguelfoweb avatar

    guelfoweb/knock

    4,163View on GitHub↗

    Knock is an attack surface management tool and DNS reconnaissance framework used for discovering and mapping an organization's external infrastructure. It functions as a subdomain enumeration tool and HTTP security scanner to identify reachable hosts and organizational assets. The project distinguishes itself by using a passive-active hybrid enumeration strategy, combining external API lookups with active wordlist brute-force attacks and DNS zone transfers. It includes a multi-stage validation pipeline that detects DNS wildcard records and verifies host connectivity to filter out false positi

    Python
    View on GitHub↗4,163
  • projectdiscovery/naabuprojectdiscovery avatar

    projectdiscovery/naabu

    5,766View on GitHub↗

    Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to identify active services. It functions as a Go library for embedding port scanning into programs, and as a standalone tool that accepts targets as hostnames, IP addresses, CIDR ranges, or ASN numbers. The tool discovers live hosts before scanning, filters ports by range or top lists, and can integrate with Nmap for service version detection. The project distinguishes itself through its SYN-based port probing approach that sends TCP SYN packets and analyzes responses without complet

    Gocdn-exclusionhacktoberfestnmap
    View on GitHub↗5,766
Compare all 30 related projects→

Frequently asked questions

What does owasp/nettacker do?

Nettacker is an automated penetration testing framework designed to orchestrate reconnaissance, port scanning, and vulnerability detection. It functions as a network reconnaissance tool and vulnerability scanner that identifies open ports, fingerprints services, and checks systems against databases of known security flaws.

What are the main features of owasp/nettacker?

The main features of owasp/nettacker are: Network Vulnerability Scanning, Reconnaissance Workflow Orchestrators, Penetration Testing Frameworks, Web Application Crawlers, Network Device Discovery, Penetration Testing, Audit Result Persistence, Relational Database Persistence.

Which projects share features with owasp/nettacker?

Projects with overlapping indexed features include: jaykali/maskphish — Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network… google/tsunami-security-scanner — Tsunami Security Scanner is a network vulnerability scanner and security auditor designed to identify high-severity… guelfoweb/knock — Knock is an attack surface management tool and DNS reconnaissance framework used for discovering and mapping an… projectdiscovery/naabu — Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to… lcvvvv/kscan — kscan is a network security scanner and service fingerprinter used to discover active hosts and open ports. It… manisso/fsociety — fsociety is a penetration testing framework and security tool orchestrator designed to conduct full security audits.…

Curated searches featuring Nettacker

Hand-picked collections where Nettacker appears.
  • Automated SQL Injection Scanners
  • Automated Web Application Vulnerability Scanners