Ross ROSS = Recommend OSS · open-source software intelligence for agents

function: vulnerability-scanning

447 products, primary matches first, then adoption-weighted; health v2 shown.

ProductHealth v2StarsMaturity
cloudflare/security-audit-skill
A coding-agent skill from Cloudflare that turns an LLM coding agent into a security auditor via a six-phase pipeline (recon, hunting, valid…
543077active
opengrep/opengrep
Opengrep is an open-source static application security testing (SAST) engine forked from Semgrep under LGPL-2.1, supporting pattern-based c…
842995active
microsoft/AttackSurfaceAnalyzer
Attack Surface Analyzer is a Microsoft open-source security tool that scans an operating system's security configuration before and after s…
822950active
netwrix/pingcastle
PingCastle is a C# tool that assesses the security posture of Active Directory and Entra ID environments, producing risk scores, health che…
982937active
protectai/vulnhuntr
Vulnhuntr is a Python CLI tool that uses large language models combined with static code analysis to autonomously discover exploitable vuln…
242747active
Bearer/bearer
Bearer CLI is an open-source static application security testing (SAST) tool written in Go that scans source code and analyzes data flows t…
952739active
Checkmarx/kics
KICS (Keeping Infrastructure as Code Secure) is an open-source static analysis tool by Checkmarx that scans IaC files for security vulnerab…
982695active
nuver-labs/vps-audit
A dependency-free Bash script that audits Linux VPS security and performance, running 18 graded checks covering SSH configuration, firewall…
862676active
rbsec/sslscan
sslscan is a command-line tool that tests SSL/TLS enabled services to discover supported cipher suites, protocols, key exchange groups, and…
752618active
visa/visa-vulnerability-agentic-harness
VVAH is Visa's open-source agentic harness for autonomous vulnerability discovery, remediation, and validation using frontier AI models. It…
672601active
ajinabraham/nodejsscan
nodejsscan is a static application security testing (SAST) scanner for Node.js applications, built on libsast and semgrep. It provides a we…
442570active
TH3xACE/SUDO_KILLER
SUDO_KILLER is a Shell-based security tool that audits Linux systems for sudo-related privilege escalation vectors, including misconfigurat…
642481active
archerysec/archerysec
ArcherySec is an open-source application security orchestration and correlation (ASOC) and vulnerability management platform that integrate…
342471active
cisco-ai-defense/skill-scanner
A security scanner for AI agent skills that detects prompt injection, data exfiltration, and malicious code patterns using pattern-based de…
802460active
assetnote/react2shell-scanner
A Python command-line scanner that detects RCE vulnerabilities CVE-2025-55182 and CVE-2025-66478 in Next.js applications using React Server…
412459active
XSS Hunter
XSS Hunter Express is a self-hosted service for tracking and detecting blind cross-site scripting (XSS) vulnerabilities via injected payloa…
322440active
find-sec-bugs/find-sec-bugs
Find Security Bugs is a SpotBugs plugin that performs static security analysis of Java bytecode, detecting 144 vulnerability patterns inclu…
562437active
LoRexxar/Kunlun-M
Kunlun-M is an open-source static code analysis (SAST) tool that detects security vulnerabilities in PHP, JavaScript/Node.js, Python, Golan…
962413active
hasherezade/hollows_hunter
Hollows Hunter is a Windows command-line tool built on the PE-sieve passive memory scanner that scans running processes for malicious impla…
712401active
slimm609/checksec
A Go rewrite of the classic checksec tool that inspects security hardening properties (RELRO, stack canaries, NX, PIE, FORTIFY_SOURCE, CFI)…
862371active
lijiejie/BBScan
BBScan is a fast, lightweight, high-concurrency web vulnerability scanner written in Python. It helps penetration testers quickly identify …
232371active
jorhelp/Ingram
Ingram is a Python-based vulnerability scanning framework targeting network cameras (IP/CCTV devices). It integrates known exploits for com…
672356active
AabyssZG/SpringBoot-Scan
SpringBoot-Scan is an open-source penetration testing framework targeting Spring Boot applications, written in Python. It scans for sensiti…
532340active
ssl/ezXSS
ezXSS is a self-hosted PHP application that helps penetration testers and bug bounty hunters detect and exploit (blind) cross-site scriptin…
642330active
API-Security/APIKit
APIKit is a BurpSuite extension (Java plugin) that discovers, scans, and audits leaked API documentation such as GraphQL, OpenAPI/Swagger, …
232286active
salesforce/cloudsplaining
Cloudsplaining is an AWS IAM security assessment tool that identifies violations of least privilege in IAM policies. It generates a risk-pr…
862244active
zakirkun/deep-eye
Deep Eye is an AI-driven penetration testing CLI that orchestrates multiple LLM providers (OpenAI, Claude, Gemini, OLLAMA, Groq, and others…
682219active
punk-security/dnsReaper
DNS Reaper is a Python CLI tool that scans DNS records for subdomain takeover vulnerabilities using over 50 signatures, at roughly 50 subdo…
582216active
lenucksi/aur-malware-check
A Python CLI tool that detects compromised AUR packages from the June 2026 atomic-lockfile supply-chain attack and other historical campaig…
542168active
zhzyker/dismap
Dismap is a Go-based asset discovery and identification tool that fingerprints web, TCP, UDP, and TLS services using a rule base of 4500+ w…
232163active
last-byte/PersistenceSniper
PersistenceSniper is a PowerShell module for hunting persistence mechanisms implanted in Windows machines. It is aimed at Blue Teams, Incid…
342139active
a13xp0p0v/kernel-hardening-checker
A Python CLI tool that checks the security hardening options of the Linux kernel across Kconfig options, boot command line arguments, and s…
762123active
hannob/snallygaster
Snallygaster is a Python command-line scanner that probes HTTP servers for files that should not be publicly accessible, such as exposed gi…
542110active
thoughtworks/talisman
Talisman is a Go-based CLI tool that installs a git pre-commit/pre-push hook to scan outgoing changesets for potential secrets such as toke…
662096active
al0ne/LinuxCheck
A shell-based Linux emergency response and information gathering tool that performs 70+ security checks across 13 categories, including roo…
232096active
Trail of Bits Claude Code Config
A Claude Code plugin marketplace from Trail of Bits offering skills for AI-assisted security analysis, code auditing, and vulnerability det…
602079active
lirantal/is-website-vulnerable
A Node.js CLI tool that scans a website's frontend JavaScript libraries for publicly known security vulnerabilities using the Snyk database…
972035active
wyzxxz/jndi_tool
A Java-based JNDI exploitation tool that runs malicious RMI/LDAP reference servers to test and exploit JNDI injection vulnerabilities, incl…
322021active
Kritt-ai/open-kritt
open·kritt is an open-source, self-hosted AI vulnerability research platform that decomposes a codebase into focused security tasks, runs A…
792011active
pyupio/safety
Safety CLI is a Python dependency vulnerability scanner that detects packages with known vulnerabilities and malicious packages in local de…
941995active
msoedov/agentic_security
Agentic Security is an open-source LLM vulnerability scanner and AI red-teaming toolkit that probes large language models and agent workflo…
871977active
intruder-io/autoswagger
Autoswagger is a Python command-line tool that discovers Swagger/OpenAPI specifications, parses their endpoints, and automatically tests th…
341960active
kkbo8005/mitan
Mitan (密探) is an all-in-one penetration testing and security assessment desktop application integrating asset mapping, subdomain brute-forc…
791955active
RustSec
RustSec is the Rust ecosystem's security advisory database plus a workspace of tooling crates, including the rustsec client library, cargo-…
971943stable
anthropics/defending-code-reference-harness
A reference implementation from Anthropic for autonomous vulnerability discovery and remediation using Claude, including Claude Code skills…
577368maintenance
SleepingBag945/dddd
dddd is a Go-based batch information gathering and supply-chain vulnerability detection CLI tool designed to streamline red team workflows.…
191924active
cisagov/cset
CSET is a free desktop application from CISA and Idaho National Laboratory that guides organizations through step-by-step cybersecurity ass…
691887active
aquasecurity/tfsec
tfsec is a static analysis security scanner for Terraform code that detects misconfigurations across major cloud providers using hundreds o…
597035maintenance
sourcery-ai/sourcery
Sourcery is an AI-powered automated code review service that reviews pull requests on GitHub and GitLab, posting summaries, inline comments…
971858active
selinuxG/Golin
Golin is a Go-based security assessment tool combining asset discovery, port/service scanning, weak password brute-forcing for 40+ services…
661847active
wapiti-scanner/wapiti
Wapiti is an open-source black-box web vulnerability scanner written in Python that crawls deployed web applications and fuzzes scripts and…
981846active
valqore/valqore
Valqore is a deterministic infrastructure governance engine that scans Kubernetes manifests, Terraform, Helm, and cloud resources against 1…
811831active
78778443/QingScan
QingScan is a self-hosted, open-source security operations platform that unifies vulnerability scanning, code auditing, asset inventory, an…
661831active
White-hua/Apt_t00ls
A Java-based exploitation tool that aggregates proof-of-concept and weaponized exploits for high-severity vulnerabilities in Chinese enterp…
261830active
scipag/HardeningKitty
HardeningKitty is a PowerShell module that audits and hardens Windows system configurations against a predefined finding list. It reads reg…
841822active
1N3/BlackWidow
BlackWidow is a Python-based web application spider that crawls a target site to collect URLs, dynamic parameters, subdomains, email addres…
571821active
wagiro/BurpBounty
Burp Bounty (Scan Check Builder) is a Burp Suite extension that lets users improve Burp's active and passive web vulnerability scanners wit…
231809active
OpenSCAP/openscap
OpenSCAP is a NIST-certified open-source toolkit providing both a C library and the 'oscap' command-line tool for parsing, validating, edit…
871806stable
betterleaks/betterleaks
Betterleaks is a fast, configurable secrets scanner for finding leaked credentials in git repositories, filesystems, and platforms like Git…
821792active
nccgroup/sobelow
Sobelow is a security-focused static analysis tool for Elixir and the Phoenix framework, detecting common vulnerability classes like SQL in…
231791active
lirantal/npq
npq is a command-line tool that audits npm packages for security risks before installing them, checking CVE databases and applying syntacti…
951789active
R4gd0ll/I-Wanna-Get-All
A comprehensive Java post-exploitation vulnerability exploitation tool integrating 470 exploit modules for detection and attack of known vu…
591787active
j3ers3/Hello-Java-Sec
A deliberately vulnerable Java Spring Boot application demonstrating common web vulnerabilities (SQLi, XSS, RCE, deserialization, SSTI, SSR…
271763active
ossf/cve-bin-tool
A Python CLI tool that scans binaries and systems for known CVEs in over 350 common open-source components like openssl, libpng, and expat.…
671753active
murphysecurity/murphysec
MurphySec CLI is an open-source software composition analysis (SCA) tool that detects vulnerable dependencies in projects from the command …
571753active
bytedance/appshark
AppShark is a static taint analysis platform written in Kotlin that scans Android APKs for security vulnerabilities and compliance issues. …
541752active
ev-flow/quark-engine
Quark Engine is an Android malware scoring and analysis system that inspects APKs using rule-based behavioral detection on Dalvik bytecode.…
981713active
cr0hn/dockerscan
DockerScan is a comprehensive Docker security scanner written in Go that scans containers, images, and registries using multiple techniques…
931710active
SiriusScan/Sirius
Sirius is an open-source vulnerability scanner that automates network discovery via Nmap and performs CVE-based detection with CVSS scoring…
881695active
duo-labs/cloudmapper
CloudMapper is a tool for analyzing Amazon Web Services (AWS) environments, originally built to generate interactive network diagrams in th…
236288maintenance
wireghoul/graudit
graudit is a shell-based source code auditing tool that uses GNU grep with signature databases of extended regular expressions to find pote…
591688active
trailofbits/buttercup
Buttercup is a Cyber Reasoning System (CRS) developed by Trail of Bits for the DARPA AI Cyber Challenge that automatically finds and patche…
561683active
KeenSecurityLab/BinAbsInspector
BinAbsInspector is a static analyzer for automated reverse engineering and vulnerability scanning in binaries, built on abstract interpreta…
231672active
tabby-sec/tabby
Tabby is a Java static code analysis tool built on the Soot framework that converts JAR/WAR/CLASS files into a code property graph stored i…
511659active
chaitin/veinmind-tools
veinmind-tools is a container security toolkit by Chaitin Tech built on the veinmind-sdk, providing scanners for malicious files, weak pass…
231652active
coffinxp/loxs
Loxs is a Python-based multi-vulnerability scanner for web applications that detects SQL injection, XSS, LFI, open redirect, and CRLF injec…
521612active
jakehildreth/Locksmith
Locksmith is a PowerShell module and script that audits Active Directory Certificate Services (AD CS) for common misconfigurations. It can …
751606active
Autumn-27/ScopeSentry
ScopeSentry is a self-hosted attack surface and asset mapping platform that combines subdomain enumeration, port scanning, fingerprinting, …
881587active
AlisamTechnology/ATSCAN
ATSCAN is a Perl-based command-line scanner for mass dork searching and vulnerability exploitation. It combines search engine dorking with …
231583active
attify/firmware-analysis-toolkit
Firmware Analysis Toolkit (FAT) is a Python-based automation wrapper around Firmadyne that emulates IoT and embedded device firmware images…
231582active
nccgroup/PMapper
Principal Mapper (PMapper) is a Python CLI tool and library that models AWS IAM users and roles as a directed graph to identify privilege e…
231576active
stealthcopter/deepce
DEEPCE is a single-file pure-shell script for enumerating Docker environments and attempting privilege escalation and container escapes. It…
581567active
Tsojan/TsojanScan
TsojanScan is an integrated BurpSuite plugin for vulnerability detection that bundles multiple common vulnerability POCs into a single exte…
851563active
dwisiswant0/crlfuzz
CRLFuzz is a fast command-line tool written in Go that scans websites for CRLF (carriage return/line feed) injection vulnerabilities. It su…
661560active
BlackSnufkin/LitterBox
LitterBox is a self-hosted payload-analysis sandbox for red teams that runs static, dynamic, and EDR-based analysis on samples and produces…
621526active
gobysec/Goby
Goby is a network security assessment tool that maps an organization's attack surface and scans for known vulnerabilities and weak password…
231517active
fossas/fossa-cli
FOSSA CLI is a zero-configuration, language-agnostic dependency analysis tool that detects dependencies in any codebase across 20+ build sy…
951516active
ztgrace/changeme
changeme is a Python CLI tool that scans networks for devices and services using default or backdoor credentials. Credential definitions ar…
361516active
Gowtham-Darkseid/AutoPentestX
AutoPentestX is a Python-based automated penetration testing toolkit that scans targets for vulnerabilities and generates security reports.…
451504active
Schira4396/VcenterKiller
A Go-based all-in-one exploitation and verification tool targeting VMware vCenter, covering major CVEs such as CVE-2021-21972, CVE-2021-219…
231485active
controlplaneio/kubesec
Kubesec is a static analysis tool that performs security risk analysis on Kubernetes resource manifests, assigning a security score and det…
641477active
jvoisin/php-malware-finder
PHP Malware Finder is a command-line tool that scans filesystems for potentially malicious PHP files using YARA rules. It detects obfuscate…
101475active
shuanx/BurpAPIFinder
BurpAPIFinder is a Burp Suite extension written in Java that passively analyzes HTTP traffic (HTML and JS files) to discover hidden API end…
151472active
c0ny1/passive-scan-client
A Burp Suite extension written in Java that forwards passive scanning traffic to external passive vulnerability scanners (like xray, w13sca…
231462stable
openclarity/openclarity
OpenClarity is an open-source platform for agentless detection and management of Virtual Machine SBOMs and security threats such as vulnera…
101460active
One-Fox-Security-Team/One-Fox-T00ls
One-Fox-T00ls is a curated collection of penetration testing and security toolboxes from the One-Fox security team, covering information ga…
561443active
cyberark/KubiScan
KubiScan is a Python CLI tool that scans Kubernetes clusters for risky permissions in the RBAC authorization model. It identifies risky rol…
331431active
Metarget/metarget
Metarget is a Python-based framework that automatically builds vulnerable cloud-native infrastructures, installing vulnerable versions of D…
651415active
BlendLog/MinerSearch
A free Windows utility that scans for and removes hidden cryptocurrency miners by checking processes, files, registry, WMI, services, and s…
911413active
owasp-noir/noir
OWASP Noir is a static analysis (SAST) CLI tool that scans source code to extract every endpoint an application exposes, including shadow A…
991383active

← prev page 2 / 5 next →