# j3ssie/osmedeus

A Modern Orchestration Engine for Security

Repository: https://github.com/j3ssie/osmedeus
Canonical: https://ross.abutalabs.com/products/osmedeus
Homepage: https://www.osmedeus.org/
Language: Go
License: MIT
License Family: permissive
Topics: reconnaissance, security-tools, hacking-tool, hacking, osint, bugbounty, pentesting, security, go, attack-surface-management, workflow-engine, workflows, llm, penetration-testing, agentic-ai
Last push: 2026-08-08T14:26:33+00:00

## Health v2 (maintenance only)
Score: 93/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 96, release rhythm 84, longevity 100
- inputs: {"age_days": 2853, "days_push": 25, "days_rel": 25, "gap_med": 55, "n_releases_24m": 8}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 6538, forks 1028 (observed 2026-08-28T04:09:45.035283+00:00)

## What it is
Osmedeus is a security-focused declarative orchestration engine that lets users define reconnaissance and vulnerability-scanning pipelines as auditable YAML workflows. It supports distributed execution via Redis workers, Docker/SSH runners, cron and event triggers, cloud provisioning, and LLM-powered agentic steps, with a CLI, REST API, and web UI.

## Use cases
- automate reconnaissance pipelines for bug bounty targets
- orchestrate penetration testing workflows in YAML
- run distributed security scans across multiple workers
- schedule recurring attack surface monitoring scans
- integrate LLM agents into security automation workflows
- provision cloud VMs to run scans and clean them up automatically
- trigger security workflows from webhooks or cron

## When to choose
- you need declarative, auditable YAML pipelines for security tooling
- you want distributed master-worker execution with Redis queues
- you need built-in recon utilities like nmap integration, WAF/CDN detection, and SARIF parsing
- you want LLM agent steps and cloud provisioning inside one security automation engine

## When to avoid
- you only need a single scanner rather than a workflow orchestrator
- you want a GUI-first product with no YAML or CLI work
- your automation is unrelated to security or reconnaissance
- you cannot run Go binaries or Docker in your environment

## Facets
- artifact type: cli-tool
- maturity: active
- function: workflow-automation, penetration-testing, osint, agent-framework, scheduling, cli, api-framework, webhook
- domain: security, penetration-testing, developer-tools, osint
- platform: windows, go, cli, self-hosted
- tags: reconnaissance, bug-bounty, attack-surface-management, yaml-workflows, distributed-execution, llm-agents, vulnerability-scanning, automation, command-line, linux, macos, docker

## Member repositories
- j3ssie/osmedeus (main) score 93

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:45.035283+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:44:07.024175+00:00, confidence not recorded.
  - readme: https://github.com/j3ssie/osmedeus (fetched 2026-08-28T04:09:45.035283+00:00, sha 5eb9bef69fac)
  - homepage: https://www.osmedeus.org/ (fetched 2026-08-29T08:40:27.220054+00:00, sha dae497a3d29b)
  - site_page: https://docs.osmedeus.org (fetched 2026-08-29T08:40:27.222652+00:00, sha 29ec70079b49)
- Data as of 2026-08-30T08:39:29.467469+00:00.
