awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目关于排名机制媒体报道MCP 服务器
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
scipag avatar

scipag/vulscan

0
View on GitHub↗
3,761 星标·695 分支·Lua·6 次浏览www.computec.ch/projekte/vulscan↗

Vulscan

Vulscan is a network service auditor and vulnerability scanner that utilizes the Nmap Scripting Engine to identify security flaws. It functions as a version-based flaw detector, matching detected software banners against an offline vulnerability database to identify potential security risks without requiring a constant internet connection.

The tool provides mechanisms for refining identification accuracy, including an interactive mode for manual version overriding and configurable matching logic to filter results. It manages security data through a system for loading local datasets and synchronizing vulnerability databases via automated or manual updates.

The project covers network security auditing and flaw identification, producing security audits through a template-based reporting system. This allows for the customization of vulnerability reports using predefined strings and dynamic templates.

Features

  • Service Version Matching - Identifies security risks by matching detected service versions against local datasets without requiring an internet connection.
  • Nmap NSE Vulnerability Scanning - Leverages Nmap NSE scripts to identify known security flaws and vulnerabilities across network devices.
  • Network Vulnerability Scanning - Identifies potential attacker entry points by matching software versions against vulnerability databases.
  • Nmap Integration - Integrates with Nmap and the Nmap Scripting Engine for initial network discovery and service fingerprinting.
  • Network Security Auditing - Performs structured scans of network services to identify outdated software and critical vulnerabilities.
  • Network Service Auditors - Functions as a scanner that analyzes open ports and identifies outdated or vulnerable software versions across a network.
  • Version-Based Vulnerability Detection - Matches detected software banners against databases of known affected releases to identify security exploits.
  • Nmap-Based - Uses the Nmap Scripting Engine to detect software vulnerabilities by matching service versions against offline databases.
  • Offline Vulnerability Analysis - Maintains a local dataset of known security flaws for use in air-gapped or offline environments.
  • Vulnerability Report Templates - Uses standardized templates to generate consistent and technical security vulnerability reports.
  • Manual Fingerprint Overrides - Provides an interactive mode to manually correct detected software versions for specific ports.
  • Manual Version Overrides - Allows users to manually override misidentified software versions to ensure accurate vulnerability matching.
  • Customizable Report Templates - Produces detailed reports using custom templates to format discovered vulnerabilities for different stakeholders.
  • Vulnerability Database Management - Manages the loading and synchronization of local vulnerability datasets and custom database files.
  • Vulnerability Data Synchronization - Provides mechanisms for updating local security definitions from remote vulnerability sources.
  • Network and Web Reconnaissance - Advanced vulnerability scanning using Nmap NSE.
  • 安全与加固 - Advanced vulnerability scanning using network scripts.
  • Web Application Scanning - Network and service-level vulnerability scanner.

Star 历史

scipag/vulscan 的 Star 历史图表scipag/vulscan 的 Star 历史图表

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Start searching with AI

Vulscan 的开源替代方案

相似的开源项目,按与 Vulscan 的功能重合度排序。
  • wpscanteam/wpscanwpscanteam 的头像

    wpscanteam/wpscan

    9,636在 GitHub 上查看↗

    WPScan is a security analysis utility and vulnerability scanner designed specifically for auditing WordPress installations and other content management systems. It functions as a web application security tool that identifies misconfigurations, outdated software, and security holes in core installations, plugins, and themes. The tool employs black-box scanning techniques to perform site component enumeration, identifying users, themes, and plugins by matching known file paths and response signatures. It matches these detected components against a database of known security flaws to analyze the

    Ruby
    在 GitHub 上查看↗9,636
  • google/tsunami-security-scannergoogle 的头像

    google/tsunami-security-scanner

    8,584在 GitHub 上查看↗

    Tsunami Security Scanner is a network vulnerability scanner and security auditor designed to identify high-severity flaws across network assets. It functions as an asynchronous security probe engine that utilizes automated probes and specialized detection logic to find critical weaknesses and prioritize remediation efforts. The project is distinguished by a plugin-based scanning engine, which uses a modular architecture of interchangeable detection plugins to identify vulnerabilities. This extensibility allows for the development and integration of custom security plugins to expand the variet

    Java
    在 GitHub 上查看↗8,584
  • owasp/nettackerOWASP 的头像

    OWASP/Nettacker

    5,258在 GitHub 上查看↗

    Nettacker is an automated penetration testing framework designed to orchestrate reconnaissance, port scanning, and vulnerability detection. It functions as a network reconnaissance tool and vulnerability scanner that identifies open ports, fingerprints services, and checks systems against databases of known security flaws. The framework distinguishes itself by combining a web application crawler for discovering hidden paths via fuzzing with a vulnerability management system that persists scan results in a database to track historical assessments. It also includes specialized capabilities for

    Pythonautomationbruteforcecve
    在 GitHub 上查看↗5,258
  • sensepost/gowitnesssensepost 的头像

    sensepost/gowitness

    4,174在 GitHub 上查看↗

    Gowitness is a system for rendering web interfaces at scale to capture visual snapshots, HTTP metadata, and network scan results. It functions as a headless browser screenshot tool and a web surface mapper used to identify and visually document the attack surface of network ranges and URL lists. The tool includes a screenshot gallery server that provides a web-based interface for browsing, filtering, and managing a database of captures. It specifically serves as an Nmap target visualizer, parsing network scan results to automatically capture screenshots of discovered web services. Capabiliti

    Gochromechrome-headlessfingerprint
    在 GitHub 上查看↗4,174
查看 Vulscan 的所有 30 个替代方案→

常见问题解答

scipag/vulscan 是做什么的?

Vulscan is a network service auditor and vulnerability scanner that utilizes the Nmap Scripting Engine to identify security flaws. It functions as a version-based flaw detector, matching detected software banners against an offline vulnerability database to identify potential security risks without requiring a constant internet connection.

scipag/vulscan 的主要功能有哪些?

scipag/vulscan 的主要功能包括:Service Version Matching, Nmap NSE Vulnerability Scanning, Network Vulnerability Scanning, Nmap Integration, Network Security Auditing, Network Service Auditors, Version-Based Vulnerability Detection, Nmap-Based。

scipag/vulscan 有哪些开源替代品?

scipag/vulscan 的开源替代品包括: wpscanteam/wpscan — WPScan is a security analysis utility and vulnerability scanner designed specifically for auditing WordPress… google/tsunami-security-scanner — Tsunami Security Scanner is a network vulnerability scanner and security auditor designed to identify high-severity… owasp/nettacker — Nettacker is an automated penetration testing framework designed to orchestrate reconnaissance, port scanning, and… sensepost/gowitness — Gowitness is a system for rendering web interfaces at scale to capture visual snapshots, HTTP metadata, and network… xmirrorsecurity/opensca-cli — OpenSCA-cli is an open-source software composition analysis tool and vulnerability management command-line interface… google/osv.dev — OSV is a distributed database and aggregator of open-source security advisories that uses a standardized vulnerability…