awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectDespreCum realizăm clasamentulPresăServer MCP
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
zan8in avatar

zan8in/afrog

0
View on GitHub↗
4,182 stele·466 fork-uri·Go·mit·13 vizualizări

Afrog

afrog is an HTTP vulnerability scanner and web vulnerability management system that identifies security flaws and known CVEs using a YAML-based rule engine. It functions as a payload generator and scanner, comparing server responses against detection rules to find unauthorized access points.

The project provides a framework for out-of-band security testing, detecting blind vulnerabilities by triggering and verifying external DNS or HTTP callbacks. Beyond web traffic, it includes a protocol fuzzer capable of executing multi-step read and write sequences over raw TCP and SSL sockets to identify flaws in non-HTTP services.

The system covers a broad range of security capabilities, including network service discovery, dictionary-based brute forcing, and HTTP protocol fuzzing. It supports dynamic variable injection for payload construction, regex-based data extraction from responses, and the ability to store results in a database or export them as HTML and JSON reports.

Features

  • Vulnerability Scanners - Provides an automated system to identify known CVEs and security flaws using a rule-based scanning engine.
  • Vulnerability Scanning - Identifies known CVEs and unauthorized access points by checking targets against a library of detection rules.
  • YAML-Based Check Definitions - Uses a YAML-based rule engine to evaluate security vulnerability checks via structured request and logic sequences.
  • Response Value Extraction - Uses regular expressions to capture specific data from HTTP responses to populate variables for subsequent requests.
  • Network Protocol Fuzzers - Executes multi-step read and write sequences over raw TCP and SSL sockets to find flaws in non-HTTP services.
  • Web Vulnerability Scanning - Identifies and exploits web application vulnerabilities by checking targets against a library of detection rules.
  • Payload Variable Management - Defines reusable variables with random strings and encoding options to construct flexible payloads for requests.
  • Response Header Extractors - Captures specific values from response bodies or headers using regular expressions for use in subsequent rules.
  • Protocol Fuzzing - Executes multi-step read and write sequences over raw TCP and SSL sockets to identify protocol-specific flaws.
  • Dictionary-Based Route Probing - Performs reconnaissance by testing predefined lists of common paths and credentials to discover hidden endpoints.
  • Out-of-Band Security Testing - Identifies blind vulnerabilities by triggering external network callbacks and verifying them through a remote check function.
  • Proof of Concept Execution - Runs custom YAML-based rules and scripts to verify if a target system is susceptible to specific vulnerabilities.
  • Out-of-Band Testing - Identifies blind vulnerabilities by triggering external network callbacks and verifying them via a remote check function.
  • Vulnerability Management Systems - Provides a centralized platform for scanning targets, storing detected CVEs in a database, and exporting reports.
  • YAML Security Rule Definition - Provides a system to create YAML-based rules using HTTP requests and logic expressions to identify security flaws.
  • HTTP Fuzzing - Generates permutations of HTTP requests using variables to discover hidden endpoints and unexpected server behavior.
  • Evasive Payload Generators - Constructs flexible HTTP requests using random variables, custom encodings, and manual header control.
  • Raw HTTP Request Construction - Allows construction of manual HTTP messages to control exact header order and manage complex multi-part bodies.
  • Variable Injection - Constructs flexible HTTP payloads by replacing placeholders with randomly generated or encoded values during runtime.
  • PoC Execution Engines - Loads and executes user-defined rule sets from external directories to identify specific security vulnerabilities.
  • Scan Result Exporters - Generates structured reports of scan findings in multiple formats such as HTML and JSON.
  • Vulnerability Result Storage - Saves detected vulnerabilities to a database and provides a web interface for searching and filtering.
  • Network Service Discovery - Automatically discovers active components and reachable services on a network via port scanning.
  • Scan Result Exporters - Generates vulnerability reports in HTML or JSON formats including detailed request and response data.
  • Port Scanners - Provides functional capabilities to identify open network ports and services across target hosts.
  • Protocol Session Orchestration - Manages multi-step read and write sequences over raw TCP and SSL sockets to identify flaws in non-HTTP services.
  • File Upload Security - Generates random boundaries and filenames to create self-deleting verification files to validate file upload vulnerabilities.
  • Credential Brute-Forcing - Performs automated testing of paths and credentials using dictionary-based brute-forcing to find vulnerable endpoints.
  • Vulnerability Report Generation - Generates detailed vulnerability reports and dashboards from scan results in HTML and JSON formats.
  • Analysis Report Serialization - Transforms scan findings and audit trails into human and machine-readable reports for external analysis.
  • Vulnerability Exploitation Tools - Vulnerability scanner for web applications.
  • Vulnerability Scanners - High-performance vulnerability scanner with customizable PoCs.

Istoric stele

Graficul istoricului de stele pentru zan8in/afrogGraficul istoricului de stele pentru zan8in/afrog

Căutare AI

Explorează mai multe repository-uri excelente

Descrie ce ai nevoie în limbaj simplu — AI-ul sortează mii de proiecte open source selectate în funcție de relevanță.

Start searching with AI

Alternative open-source pentru Afrog

Proiecte open-source similare, clasificate după numărul de funcționalități comune cu Afrog.
  • projectdiscovery/nucleiAvatar projectdiscovery

    projectdiscovery/nuclei

    29,189Vezi pe GitHub↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Goattack-surfacecve-scannerdast
    Vezi pe GitHub↗29,189
  • jaykali/maskphishAvatar jaykali

    jaykali/maskphish

    3,020Vezi pe GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Shellhackhackinghacking-tool
    Vezi pe GitHub↗3,020
  • projectdiscovery/subfinderAvatar projectdiscovery

    projectdiscovery/subfinder

    13,105Vezi pe GitHub↗

    Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It functions as a discovery engine that identifies and maps internet-exposed infrastructure, cloud-hosted assets, and network ranges to maintain a comprehensive inventory of an organization's digital footprint. The project distinguishes itself through a modular, template-driven scanning engine that executes security checks against discovered assets. It leverages cloud-native asset discovery to query provider APIs and infrastructure metadata, while supporting distributed agent orc

    Gobugbountyhackinghacktoberfest
    Vezi pe GitHub↗13,105
  • projectdiscovery/naabuAvatar projectdiscovery

    projectdiscovery/naabu

    5,766Vezi pe GitHub↗

    Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to identify active services. It functions as a Go library for embedding port scanning into programs, and as a standalone tool that accepts targets as hostnames, IP addresses, CIDR ranges, or ASN numbers. The tool discovers live hosts before scanning, filters ports by range or top lists, and can integrate with Nmap for service version detection. The project distinguishes itself through its SYN-based port probing approach that sends TCP SYN packets and analyzes responses without complet

    Gocdn-exclusionhacktoberfestnmap
    Vezi pe GitHub↗5,766
Vezi toate cele 30 alternative pentru Afrog→

Întrebări frecvente

Ce face zan8in/afrog?

afrog is an HTTP vulnerability scanner and web vulnerability management system that identifies security flaws and known CVEs using a YAML-based rule engine. It functions as a payload generator and scanner, comparing server responses against detection rules to find unauthorized access points.

Care sunt principalele funcționalități ale zan8in/afrog?

Principalele funcționalități ale zan8in/afrog sunt: Vulnerability Scanners, Vulnerability Scanning, YAML-Based Check Definitions, Response Value Extraction, Network Protocol Fuzzers, Web Vulnerability Scanning, Payload Variable Management, Response Header Extractors.

Care sunt câteva alternative open-source pentru zan8in/afrog?

Alternativele open-source pentru zan8in/afrog includ: projectdiscovery/nuclei — Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure… jaykali/maskphish — Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network… projectdiscovery/subfinder — Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It… projectdiscovery/naabu — Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to… chaitin/xray — Xray is a security assessment tool focused on web vulnerability scanning, attack surface mapping, and technology… andresriancho/w3af — w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities…