# zan8in/afrog

A Security Tool for Bug Bounty, Pentest and Red Teaming.

Repository: https://github.com/zan8in/afrog
Canonical: https://ross.abutalabs.com/products/afrog
Language: Go
License: MIT
License Family: permissive
Topics: vulnerability-scanner, poc, penetration-testing, afrog, vulnerability-scanning-tools, bug-bounty, pentest, red-teaming
Last push: 2026-08-04T03:32:34+00:00

## Health v2 (maintenance only)
Score: 96/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 96, release rhythm 94, longevity 100
- inputs: {"age_days": 1651, "days_push": 29, "days_rel": 42, "gap_med": 13, "n_releases_24m": 30}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 4372, forks 477 (observed 2026-08-28T04:08:46.815412+00:00)

## What it is
afrog is an open-source security tool written in Go for vulnerability scanning using PoC (Proof of Concept) rules. It is designed for bug bounty hunters, penetration testers, and red teamers to detect known vulnerabilities in targets.

## Use cases
- scan a target for known vulnerabilities with PoC rules
- find exploitable CVEs during a pentest
- run batch vulnerability scans for bug bounty recon
- write custom PoC rules for vulnerability detection
- verify whether a service is affected by a specific exploit

## When to choose
- you need a fast CLI-based PoC vulnerability scanner
- you do bug bounty, pentest, or red team engagements and want community PoCs
- you want to write and run custom PoC rules in a simple format

## When to avoid
- you need a full authenticated web application scanner
- you want a GUI-driven enterprise vulnerability management platform
- you need continuous compliance or asset inventory scanning rather than PoC-based checks

## Facets
- artifact type: cli-tool
- maturity: active
- function: vulnerability-scanning, security, penetration-testing, cli
- domain: security, penetration-testing
- platform: windows, cli, cross-platform
- tags: poc-scanner, bug-bounty, red-teaming, vulnerability-scanner, go, linux, macos

## Member repositories
- zan8in/afrog (main) score 96

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:46.815412+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:21:21.853485+00:00, confidence not recorded.
  - readme: https://github.com/zan8in/afrog (fetched 2026-08-28T04:08:46.815412+00:00, sha 5c445e3b37c2)
- Data as of 2026-08-30T08:39:29.467469+00:00.
