# kkbo8005/mitan

密探渗透测试工具包含资产信息收集，子域名爆破，搜索语法，资产测绘（聚合测绘，FO FA，Hunter，Quake,Zoomeye,DayDayMap,censys,shodan, 零零信安），指纹识别，敏感信息采集，文件扫描、端口扫描、弱口令破解、jwt密钥爆破、Sessionkey,heapdump, 微信小程序，密码本，随机用户，社工字典,AI渗透（MCP、代码审计）等功能

Repository: https://github.com/kkbo8005/mitan
Canonical: https://ross.abutalabs.com/products/mitan
License Family: other
Last push: 2026-08-15T18:04:43+00:00

## Health v2 (maintenance only)
Score: 79/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 97, release rhythm 66, longevity 63
- inputs: {"age_days": 882, "days_push": 18, "days_rel": 18, "gap_med": 462, "n_releases_24m": 2}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1955, forks 133 (observed 2026-08-28T04:05:58.978378+00:00)

## What it is
Mitan (密探) is an all-in-one penetration testing and security assessment desktop application integrating asset mapping, subdomain brute-forcing, fingerprint recognition, port scanning, weak password cracking, sensitive information collection, and cloud security checks. Version 2.0 is built in Rust and adds AI-assisted automated penetration testing, MCP tooling, and code auditing alongside 50+ reconnaissance and vulnerability detection capabilities.

## Use cases
- aggregate asset mapping across FOFA, Hunter, Quake, ZoomEye, Shodan, Censys and DayDayMap
- brute-force subdomains and scan directories on a target domain
- identify web fingerprints and run POC scans for known vulnerabilities
- crack weak passwords and JWT secrets during authorized tests
- collect sensitive information like heapdumps, session keys, and WeChat mini-program data
- generate social engineering dictionaries and password wordlists
- use AI-assisted automated penetration testing and code auditing via MCP

## When to choose
- you need a single GUI tool covering the full recon-to-exploitation chain for authorized engagements
- you want to query multiple cyberspace mapping engines with automatic search syntax translation
- you manage penetration test projects and need per-project data isolation and history

## When to avoid
- you need a fully open-source tool - it has no license file and prohibits reverse engineering or redistribution
- you only need one narrow capability like port scanning, where dedicated tools are lighter
- you require CLI automation or CI integration rather than a desktop GUI

## Facets
- artifact type: application
- maturity: active
- function: osint, penetration-testing, vulnerability-scanning, web-scraping, search-engine, security, mcp, llm-inference
- domain: security, penetration-testing, osint, developer-tools, artificial-intelligence
- platform: cross-platform, rust, jvm
- tags: asset-mapping, subdomain-enumeration, fingerprinting, port-scanning, weak-password-bruteforce, cyberspace-mapping, cloud-security, social-engineering-dictionary, wechat-miniprogram, red-team, desktop

## Member repositories
- kkbo8005/mitan (main) score 79

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:58.978378+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:06:26.858650+00:00, confidence not recorded.
  - readme: https://github.com/kkbo8005/mitan (fetched 2026-08-28T04:05:58.978378+00:00, sha 8c810cae3a69)
- Data as of 2026-08-30T08:39:29.467469+00:00.
