Ross ROSS = Recommend OSS · open-source software intelligence for agents

inbug-team/InScan

边界打点后的自动化渗透工具 observed · 2026-08-28

github.com/inbug-team/InScan · Go observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1971
  • days_rel: n/a
  • days_push: 1871
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1888 stars · 351 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

InScan is a Go-based automated intranet penetration testing tool designed for use after breaching a network boundary. It provides port scanning, service fingerprinting, PoC-based vulnerability verification, credential brute-forcing with generated dictionaries, and visualized multi-level tunnel management through a web interface.

Use cases

  • scan internal networks after gaining initial foothold
  • identify live hosts and open ports on intranet subnets
  • fingerprint services and CMS platforms on internal systems
  • run PoC vulnerability checks against discovered assets
  • brute-force weak passwords on internal web login pages
  • pivot through multi-layer networks with visual tunnel management
  • generate social-engineering password dictionaries from known credentials
  • perform privilege escalation checks on Windows hosts

When to choose

  • you need a dependency-free single binary for intranet scanning in restricted environments
  • you want integrated port scanning, service identification, and PoC verification in one tool
  • you need to pivot across multiple network layers with visual tunnel control
  • you are doing authorized red-team or penetration-test engagements on internal networks

When to avoid

  • you need a fully supported tool with an open-source license and active maintenance
  • you want external perimeter vulnerability scanning rather than post-breach internal testing
  • your use is not authorized security testing - the tool is explicitly for legal security testing only
  • you require the unfinished features like web SSH/RDP management or directory scanning, which were still in development

Facets

application · maturity maintenance

security penetration-testing vulnerability-scanning networking search-engine security penetration-testing networking developer-tools cross-platform windows cli self-hosted internal-network-pentest port-scanner pivoting tunneling brute-force poc-framework red-team post-exploitation web-ui single-binary linux

1 source

Member repositories

RepositoryRoleHealth v2
inbug-team/InScanmain32

For agents

markdown · JSON · MCP: product_card(name="inbug-team/InScan")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem