Ross ROSS = Recommend OSS · open-source software intelligence for agents

shadow1ng/fscan

一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。(An intranet comprehensive scanning tool, enabling one-click automated, all-round vulnerability scanning) observed · 2026-08-28

github.com/shadow1ng/fscan · Go · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

95/100

  • Activity 99
  • Release rhythm 87
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 46
  • age_days: 2119
  • days_rel: 8
  • days_push: 8
  • n_releases_24m: 4

Full methodology

Adoption not part of the score

14450 stars · 1938 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Fscan is a comprehensive intranet scanning tool written in Go that automates host discovery, port scanning, service identification, weak-password brute forcing, and vulnerability detection in one command. It also includes exploitation modules (e.g., Redis RCE, MS17-010), local information-gathering and persistence helpers, and a Go SDK for embedding into agents or security platforms.

Use cases

  • scan an internal network for live hosts and open ports
  • detect weak passwords on SSH, RDP, SMB, MySQL, Redis and other services
  • check for MS17-010 (EternalBlue) and SMBGhost vulnerabilities
  • find unauthorized-access exposures on Redis, MongoDB, Memcached, Elasticsearch
  • fingerprint web servers, CMS, middleware, WAF and CDN during a pentest
  • run one-click automated vulnerability scanning across a C-class subnet
  • embed scanning capabilities into a security platform via a Go SDK

When to choose

  • you need a single all-in-one binary for internal network reconnaissance and vuln scanning
  • you want automated brute forcing plus POC-based vulnerability checks in one run
  • you are doing authorized red-team or pentest work on Windows/Linux mixed intranets
  • you need a Go SDK to integrate scanning into your own tooling

When to avoid

  • you need stealthy, low-and-slow scanning that evades IDS/IPS
  • you require a GUI-driven enterprise vulnerability management product
  • you only need external web application scanning rather than intranet assessment
  • unauthorized use - it is designed for authorized security testing only

Facets

cli-tool · maturity active

security penetration-testing vulnerability-scanning cli networking security penetration-testing networking developer-tools windows go cross-platform cli intranet-scanner vulnerability-scanner brute-force poc-scanning service-discovery port-scanner red-team post-exploitation command-line linux macos

1 source

Member repositories

RepositoryRoleHealth v2
shadow1ng/fscanmain95

For agents

markdown · JSON · MCP: product_card(name="shadow1ng/fscan")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem