# gobysec/Goby

Attack surface mapping

Repository: https://github.com/gobysec/Goby
Canonical: https://ross.abutalabs.com/products/gobysec-goby
Homepage: https://gobies.org/
License Family: other
Topics: vulnerability-research, scan-tool, security, security-tools, hacking, networking, portscanning, cve, exp, pentesting, exploit, red-team, proxyshell, cve-2023-22527, cve-2024-0204, cve-2024-20931, cve-2024-21887, cve-2024-21893, cve-2024-23897, cve-2024-25600
Last push: 2024-02-29T09:48:14+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 2648, "days_push": 916, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1517, forks 153 (observed 2026-08-28T04:04:57.378641+00:00)

## What it is
Goby is a network security assessment tool that maps an organization's attack surface and scans for known vulnerabilities and weak passwords. It combines asset fingerprinting, port scanning, protocol recognition, and exploit checking in an Electron-based desktop app.

## Use cases
- map the attack surface of a company's internet-exposed assets
- scan a network for known CVE vulnerabilities
- find weak passwords on network devices
- enumerate services and fingerprint hardware and software across a subnet
- pivot from external vulnerabilities into an intranet during a pentest
- identify IoT, ICS, and SCADA devices on a network

## When to choose
- you need combined asset discovery and vulnerability scanning in one GUI tool
- you do red-team or offensive security assessments against enterprise networks
- you want built-in recognition rules for a wide range of devices, protocols, and products

## When to avoid
- you need fully open-source or auditable tooling - the core is distributed as a binary without a license file in the repo
- you only need lightweight command-line port scanning (nmap or masscan fit better)
- you require deep manual exploitation rather than broad automated scanning

## Facets
- artifact type: application
- maturity: active
- function: security, vulnerability-scanning, penetration-testing, networking, osint
- domain: security, penetration-testing, networking
- platform: windows, cross-platform
- tags: attack-surface-mapping, port-scanner, exploit, red-team, cve, asset-discovery, closed-source-binary, macos, linux, electron

## Member repositories
- gobysec/Goby (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:57.378641+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:32:04.486771+00:00, confidence not recorded.
  - readme: https://github.com/gobysec/Goby (fetched 2026-08-28T04:04:57.378641+00:00, sha 8c54f82413f6)
  - homepage: https://gobies.org/ (fetched 2026-08-29T11:35:45.836150+00:00, sha 4bf504eef6e1)
- Data as of 2026-08-30T08:39:29.467469+00:00.
