Ross ROSS = Recommend OSS · open-source software intelligence for agents

gobysec/Goby

Attack surface mapping observed · 2026-08-28

github.com/gobysec/Goby · homepage observed · 2026-08-28

Health v2 · maintenance only

23/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2648
  • days_rel: n/a
  • days_push: 916
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1517 stars · 153 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Goby is a network security assessment tool that maps an organization's attack surface and scans for known vulnerabilities and weak passwords. It combines asset fingerprinting, port scanning, protocol recognition, and exploit checking in an Electron-based desktop app.

Use cases

  • map the attack surface of a company's internet-exposed assets
  • scan a network for known CVE vulnerabilities
  • find weak passwords on network devices
  • enumerate services and fingerprint hardware and software across a subnet
  • pivot from external vulnerabilities into an intranet during a pentest
  • identify IoT, ICS, and SCADA devices on a network

When to choose

  • you need combined asset discovery and vulnerability scanning in one GUI tool
  • you do red-team or offensive security assessments against enterprise networks
  • you want built-in recognition rules for a wide range of devices, protocols, and products

When to avoid

  • you need fully open-source or auditable tooling - the core is distributed as a binary without a license file in the repo
  • you only need lightweight command-line port scanning (nmap or masscan fit better)
  • you require deep manual exploitation rather than broad automated scanning

Facets

application · maturity active

security vulnerability-scanning penetration-testing networking osint security penetration-testing networking windows cross-platform attack-surface-mapping port-scanner exploit red-team cve asset-discovery closed-source-binary macos linux electron

2 sources

Member repositories

RepositoryRoleHealth v2
gobysec/Gobymain23

For agents

markdown · JSON · MCP: product_card(name="gobysec/Goby")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem