Ross ROSS = Recommend OSS · open-source software intelligence for agents

chainreactors/gogo

面向红队的, 高性能高度自由可拓展的自动化扫描引擎 | A highly controllable and extensionable automated scanning engine for red teams observed · 2026-08-28

github.com/chainreactors/gogo · homepage · Go · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

91/100

  • Activity 94
  • Release rhythm 81
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 58
  • age_days: 1539
  • days_rel: 50
  • days_push: 36
  • n_releases_24m: 8

Full methodology

Adoption not part of the score

2118 stars · 200 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

gogo is a high-performance, highly configurable automated scanning engine written in pure Go for red team operations. It combines port scanning, active/passive service fingerprinting, key information extraction, and harmless nuclei-based PoC checks with minimal packet emission and extensive DSL-based customization.

Use cases

  • scan an internal subnet for open ports and services
  • fingerprint web applications and services during red team engagements
  • run harmless nuclei PoC checks against discovered services
  • extract titles, certificates, and custom regex-matched info from services
  • perform large-scale A-class network scanning through proxies or webshells
  • customize scanning behavior with DSL config files
  • run a scanner on legacy systems like Windows 2003

When to choose

  • you need a fast, single-binary scanner that runs on almost any OS including legacy Windows
  • you want fine-grained control over scan behavior and minimal network noise
  • you operate in restricted environments like webshells, C2 sessions, or multi-hop proxies
  • you need port scanning plus fingerprinting plus PoC checks in one tool

When to avoid

  • you need service credential brute-forcing or exploitation — use companion tools like zombie or Metasploit
  • you need a GUI-driven vulnerability scanner
  • you only need simple port scanning where nmap or masscan suffice

Facets

cli-tool · maturity active

security networking search-engine cli developer-tools security penetration-testing networking windows cross-platform cli red-team port-scanner fingerprinting recon vulnerability-scanning nuclei-poc intranet-scanning go command-line automation linux macos

10 sources

Member repositories

RepositoryRoleHealth v2
chainreactors/gogomain91

For agents

markdown · JSON · MCP: product_card(name="chainreactors/gogo")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem