Ross ROSS = Recommend OSS · open-source software intelligence for agents

kkbo8005/mitan

密探渗透测试工具包含资产信息收集,子域名爆破,搜索语法,资产测绘(聚合测绘,FO FA,Hunter,Quake,Zoomeye,DayDayMap,censys,shodan, 零零信安),指纹识别,敏感信息采集,文件扫描、端口扫描、弱口令破解、jwt密钥爆破、Sessionkey,heapdump, 微信小程序,密码本,随机用户,社工字典,AI渗透(MCP、代码审计)等功能 observed · 2026-08-28

github.com/kkbo8005/mitan observed · 2026-08-28

Health v2 · maintenance only

79/100

  • Activity 97
  • Release rhythm 66
  • Longevity 63

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 462
  • age_days: 882
  • days_rel: 18
  • days_push: 18
  • n_releases_24m: 2

Full methodology

Adoption not part of the score

1955 stars · 133 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Mitan (密探) is an all-in-one penetration testing and security assessment desktop application integrating asset mapping, subdomain brute-forcing, fingerprint recognition, port scanning, weak password cracking, sensitive information collection, and cloud security checks. Version 2.0 is built in Rust and adds AI-assisted automated penetration testing, MCP tooling, and code auditing alongside 50+ reconnaissance and vulnerability detection capabilities.

Use cases

  • aggregate asset mapping across FOFA, Hunter, Quake, ZoomEye, Shodan, Censys and DayDayMap
  • brute-force subdomains and scan directories on a target domain
  • identify web fingerprints and run POC scans for known vulnerabilities
  • crack weak passwords and JWT secrets during authorized tests
  • collect sensitive information like heapdumps, session keys, and WeChat mini-program data
  • generate social engineering dictionaries and password wordlists
  • use AI-assisted automated penetration testing and code auditing via MCP

When to choose

  • you need a single GUI tool covering the full recon-to-exploitation chain for authorized engagements
  • you want to query multiple cyberspace mapping engines with automatic search syntax translation
  • you manage penetration test projects and need per-project data isolation and history

When to avoid

  • you need a fully open-source tool - it has no license file and prohibits reverse engineering or redistribution
  • you only need one narrow capability like port scanning, where dedicated tools are lighter
  • you require CLI automation or CI integration rather than a desktop GUI

Facets

application · maturity active

osint penetration-testing vulnerability-scanning web-scraping search-engine security mcp llm-inference security penetration-testing osint developer-tools artificial-intelligence cross-platform rust jvm asset-mapping subdomain-enumeration fingerprinting port-scanning weak-password-bruteforce cyberspace-mapping cloud-security social-engineering-dictionary wechat-miniprogram red-team desktop

1 source

Member repositories

RepositoryRoleHealth v2
kkbo8005/mitanmain79

For agents

markdown · JSON · MCP: product_card(name="kkbo8005/mitan")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem