Ross ROSS = Recommend OSS · open-source software intelligence for agents

EnableSecurity/sipvicious

SIPVicious OSS is a VoIP security testing toolset. It helps security teams, QA and developers test SIP-based VoIP systems and applications. This toolset is useful in simulating VoIP hacking attacks against PBX systems especially through identification, scanning, extension enumeration and password cracking. observed · 2026-08-28

github.com/EnableSecurity/sipvicious · homepage · Python · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

89/100

  • Activity 91
  • Release rhythm 80
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 35
  • age_days: 4191
  • days_rel: 54
  • days_push: 54
  • n_releases_24m: 4

Full methodology

Adoption not part of the score

1098 stars · 185 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

SIPVicious OSS is a Python-based toolset for auditing SIP-based VoIP systems, including tools to scan for SIP servers (svmap), enumerate extensions (svwar), crack passwords (svcrack), generate reports (svreport), and crash malicious scanners (svcrash). It has been actively maintained since 2007 and is widely known in the VoIP security community as the 'friendly-scanner'.

Use cases

  • scan IP ranges for SIP servers and PBX devices
  • enumerate valid SIP extensions on a PBX
  • crack SIP digest authentication passwords
  • audit VoIP infrastructure security before deployment
  • generate PDF/CSV/XML reports from SIP scan sessions
  • protect a PBX from svwar and svcrack attacks
  • run automated security smoke tests on SIP routers in CI/CD

When to choose

  • you need to pentest or audit SIP-based VoIP systems like PBXes and SIP proxies
  • you want an established, well-known open-source VoIP security toolset
  • you need extension enumeration or SIP password cracking during authorized assessments
  • you want scriptable CLI tools that run anywhere Python 3 runs, including IPv6 targets

When to avoid

  • you need to test WebRTC or non-SIP real-time communications
  • you require advanced or commercial-grade VoIP pentesting features beyond scanning, enumeration, and cracking
  • you want a GUI-driven vulnerability scanner rather than command-line tools
  • you are not authorized to test the target network - using this against systems without permission is illegal

Facets

cli-tool · maturity active

penetration-testing security networking security penetration-testing networking python cli cross-platform voip sip pbx password-cracking scanner telephony hacking-tools command-line

4 sources

Member repositories

RepositoryRoleHealth v2
EnableSecurity/sipviciousmain89

For agents

markdown · JSON · MCP: product_card(name="EnableSecurity/sipvicious")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem