Ross ROSS = Recommend OSS · open-source software intelligence for agents

grayddq/GScan

本程序旨在为安全应急响应人员对Linux主机排查时提供便利,实现主机侧Checklist的自动全面化检测,根据检测结果自动数据聚合,进行黑客攻击路径溯源。 observed · 2026-08-28

github.com/grayddq/GScan · Python observed · 2026-08-28

Health v2 · maintenance only

23/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2725
  • days_rel: n/a
  • days_push: 1488
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2826 stars · 624 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

GScan is a Python-based CLI security tool that automates comprehensive Linux host security checks for incident response. It scans for backdoors, rootkits, webshells, suspicious processes, network connections, and account issues, then aggregates results to trace attacker paths.

Use cases

  • automate linux host security checklist during incident response
  • detect backdoors and rootkits on a compromised server
  • scan for webshell files on a linux host
  • trace hacker attack paths from aggregated scan results
  • check for suspicious processes and reverse shells
  • audit user accounts, sudoers, and ssh keys for compromise
  • schedule periodic security scans of a linux server

When to choose

  • you need a fast automated triage of a possibly compromised CentOS linux host
  • you want a single tool covering files, processes, network, backdoors, accounts, and logs
  • you are a security responder doing host-side checklist verification

When to avoid

  • you need to audit non-CentOS distributions, which are untested and may give unreliable results
  • you need a maintained tool with active development or a license
  • you need network-wide or containerized environment scanning rather than single-host checks

Facets

cli-tool · maturity maintenance

security vulnerability-scanning developer-tools security python cli incident-response host-detection rootkit-detection backdoor-detection webshell-scanning linux-security-audit checklist-automation command-line devops linux

1 source

Member repositories

RepositoryRoleHealth v2
grayddq/GScanmain23

For agents

markdown · JSON · MCP: product_card(name="grayddq/GScan")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem