# projectdiscovery/interactsh

An OOB interaction gathering server and client library

Repository: https://github.com/projectdiscovery/interactsh
Canonical: https://ross.abutalabs.com/products/interactsh
Homepage: https://app.interactsh.com
Language: Go
License: MIT
License Family: permissive
Topics: appsec, oast, dns, security, http, smtp, ldap, oob, bugbounty, golang, hacktoberfest
Last push: 2026-08-10T10:19:38+00:00

## Health v2 (maintenance only)
Score: 85/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 97, release rhythm 62, longevity 100
- inputs: {"age_days": 2042, "days_push": 23, "days_rel": 176, "gap_med": 46, "n_releases_24m": 6}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 4512, forks 478 (observed 2026-08-28T04:08:52.584127+00:00)

## What it is
Interactsh is an open-source tool for detecting out-of-band (OOB) interactions via DNS, HTTP(S), SMTP(S), and LDAP, useful for identifying vulnerabilities that trigger external callbacks. It ships as a CLI client, web client, and self-hostable server, with a Go client library for integration.

## Use cases
- detect blind SSRF vulnerabilities
- detect out-of-band interactions during penetration testing
- self-host an OOB interaction server for bug bounty testing
- detect blind command injection and XXE via DNS callbacks
- integrate OOB detection into security scanning tools
- correlate external callbacks with vulnerability payloads

## When to choose
- you need to detect blind/out-of-band vulnerabilities like SSRF, XXE, or blind RCE
- you want a self-hosted alternative to Burp Collaborator with encrypted, zero-logging interactions
- you need a Go client library to embed OOB detection into your own scanners

## When to avoid
- your testing scope forbids external network callbacks
- you only need passive vulnerability scanning without interaction correlation

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, http-server, networking, cli, sdk
- domain: security, penetration-testing, developer-tools, networking
- platform: windows, go, cli, self-hosted, browser
- tags: oob, oast, dns, bugbounty, vulnerability-detection, burp-suite, zap, smtp, ldap, linux, macos, docker

## Member repositories
- projectdiscovery/interactsh (main) score 85

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:52.584127+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:20:20.397966+00:00, confidence not recorded.
  - readme: https://github.com/projectdiscovery/interactsh (fetched 2026-08-28T04:08:52.584127+00:00, sha 3713218d686a)
  - homepage: https://app.interactsh.com (fetched 2026-08-29T09:06:13.404172+00:00, sha 22fc9d381553)
- Data as of 2026-08-30T08:39:29.467469+00:00.
