EnableSecurity/sipvicious
SIPVicious OSS is a VoIP security testing toolset. It helps security teams, QA and developers test SIP-based VoIP systems and applications. This toolset is useful in simulating VoIP hacking attacks against PBX systems especially through identification, scanning, extension enumeration and password cracking. observed · 2026-08-28
Health v2 · maintenance only
89/100
- Activity 91
- Release rhythm 80
- Longevity 100
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 35
- age_days: 4191
- days_rel: 54
- days_push: 54
- n_releases_24m: 4
Adoption not part of the score
1098 stars · 185 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
SIPVicious OSS is a Python-based toolset for auditing SIP-based VoIP systems, including tools to scan for SIP servers (svmap), enumerate extensions (svwar), crack passwords (svcrack), generate reports (svreport), and crash malicious scanners (svcrash). It has been actively maintained since 2007 and is widely known in the VoIP security community as the 'friendly-scanner'.
Use cases
- scan IP ranges for SIP servers and PBX devices
- enumerate valid SIP extensions on a PBX
- crack SIP digest authentication passwords
- audit VoIP infrastructure security before deployment
- generate PDF/CSV/XML reports from SIP scan sessions
- protect a PBX from svwar and svcrack attacks
- run automated security smoke tests on SIP routers in CI/CD
When to choose
- you need to pentest or audit SIP-based VoIP systems like PBXes and SIP proxies
- you want an established, well-known open-source VoIP security toolset
- you need extension enumeration or SIP password cracking during authorized assessments
- you want scriptable CLI tools that run anywhere Python 3 runs, including IPv6 targets
When to avoid
- you need to test WebRTC or non-SIP real-time communications
- you require advanced or commercial-grade VoIP pentesting features beyond scanning, enumeration, and cracking
- you want a GUI-driven vulnerability scanner rather than command-line tools
- you are not authorized to test the target network - using this against systems without permission is illegal
Facets
cli-tool · maturity active
penetration-testing security networking security penetration-testing networking python cli cross-platform voip sip pbx password-cracking scanner telephony hacking-tools command-line
4 sources
- readme: https://github.com/EnableSecurity/sipvicious · fetched 2026-08-28 · e5c0b1872585
- homepage: https://www.enablesecurity.com/sipvicious/ · fetched 2026-08-29 · b8bf1ca4f8ca
- site_page: https://www.enablesecurity.com/about · fetched 2026-08-29 · 7df63bd5a452
- registry_pypi: https://pypi.org/pypi/sipvicious/json · fetched 2026-08-29 · 949925262400
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| EnableSecurity/sipvicious | main | 89 |
For agents
markdown · JSON · MCP: product_card(name="EnableSecurity/sipvicious")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem