shadow1ng/fscan
一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。(An intranet comprehensive scanning tool, enabling one-click automated, all-round vulnerability scanning) observed · 2026-08-28
Health v2 · maintenance only
95/100
- Activity 99
- Release rhythm 87
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 46
- age_days: 2119
- days_rel: 8
- days_push: 8
- n_releases_24m: 4
Adoption not part of the score
14450 stars · 1938 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Fscan is a comprehensive intranet scanning tool written in Go that automates host discovery, port scanning, service identification, weak-password brute forcing, and vulnerability detection in one command. It also includes exploitation modules (e.g., Redis RCE, MS17-010), local information-gathering and persistence helpers, and a Go SDK for embedding into agents or security platforms.
Use cases
- scan an internal network for live hosts and open ports
- detect weak passwords on SSH, RDP, SMB, MySQL, Redis and other services
- check for MS17-010 (EternalBlue) and SMBGhost vulnerabilities
- find unauthorized-access exposures on Redis, MongoDB, Memcached, Elasticsearch
- fingerprint web servers, CMS, middleware, WAF and CDN during a pentest
- run one-click automated vulnerability scanning across a C-class subnet
- embed scanning capabilities into a security platform via a Go SDK
When to choose
- you need a single all-in-one binary for internal network reconnaissance and vuln scanning
- you want automated brute forcing plus POC-based vulnerability checks in one run
- you are doing authorized red-team or pentest work on Windows/Linux mixed intranets
- you need a Go SDK to integrate scanning into your own tooling
When to avoid
- you need stealthy, low-and-slow scanning that evades IDS/IPS
- you require a GUI-driven enterprise vulnerability management product
- you only need external web application scanning rather than intranet assessment
- unauthorized use - it is designed for authorized security testing only
Facets
cli-tool · maturity active
security penetration-testing vulnerability-scanning cli networking security penetration-testing networking developer-tools windows go cross-platform cli intranet-scanner vulnerability-scanner brute-force poc-scanning service-discovery port-scanner red-team post-exploitation command-line linux macos
1 source
- readme: https://github.com/shadow1ng/fscan · fetched 2026-08-28 · d847e47fd33f
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| shadow1ng/fscan | main | 95 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem