# EnableSecurity/sipvicious

SIPVicious OSS is a VoIP security testing toolset. It helps security teams, QA and developers test SIP-based VoIP systems and applications. This toolset is useful in simulating VoIP hacking attacks against PBX systems especially through identification, scanning, extension enumeration and password cracking.

Repository: https://github.com/EnableSecurity/sipvicious
Canonical: https://ross.abutalabs.com/products/sipvicious
Homepage: https://www.enablesecurity.com/sipvicious/
Language: Python
License: NOASSERTION
License Family: other
Topics: sip, voip, password-cracker, svwar, svcrack, svmap, war-dial, svcrash, security, security-tools, audit-sip, hacking-tools
Last push: 2026-07-10T05:46:43+00:00

## Health v2 (maintenance only)
Score: 89/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 91, release rhythm 80, longevity 100
- inputs: {"age_days": 4191, "days_push": 54, "days_rel": 54, "gap_med": 35, "n_releases_24m": 4}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1098, forks 185 (observed 2026-08-28T04:03:34.919525+00:00)

## What it is
SIPVicious OSS is a Python-based toolset for auditing SIP-based VoIP systems, including tools to scan for SIP servers (svmap), enumerate extensions (svwar), crack passwords (svcrack), generate reports (svreport), and crash malicious scanners (svcrash). It has been actively maintained since 2007 and is widely known in the VoIP security community as the 'friendly-scanner'.

## Use cases
- scan IP ranges for SIP servers and PBX devices
- enumerate valid SIP extensions on a PBX
- crack SIP digest authentication passwords
- audit VoIP infrastructure security before deployment
- generate PDF/CSV/XML reports from SIP scan sessions
- protect a PBX from svwar and svcrack attacks
- run automated security smoke tests on SIP routers in CI/CD

## When to choose
- you need to pentest or audit SIP-based VoIP systems like PBXes and SIP proxies
- you want an established, well-known open-source VoIP security toolset
- you need extension enumeration or SIP password cracking during authorized assessments
- you want scriptable CLI tools that run anywhere Python 3 runs, including IPv6 targets

## When to avoid
- you need to test WebRTC or non-SIP real-time communications
- you require advanced or commercial-grade VoIP pentesting features beyond scanning, enumeration, and cracking
- you want a GUI-driven vulnerability scanner rather than command-line tools
- you are not authorized to test the target network - using this against systems without permission is illegal

## Facets
- artifact type: cli-tool
- maturity: active
- function: penetration-testing, security, networking
- domain: security, penetration-testing, networking
- platform: python, cli, cross-platform
- tags: voip, sip, pbx, password-cracking, scanner, telephony, hacking-tools, command-line

## Member repositories
- EnableSecurity/sipvicious (main) score 89

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:34.919525+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:46:12.665190+00:00, confidence not recorded.
  - readme: https://github.com/EnableSecurity/sipvicious (fetched 2026-08-28T04:03:34.919525+00:00, sha e5c0b1872585)
  - homepage: https://www.enablesecurity.com/sipvicious/ (fetched 2026-08-29T12:49:38.935985+00:00, sha b8bf1ca4f8ca)
  - site_page: https://www.enablesecurity.com/about (fetched 2026-08-29T12:49:38.946082+00:00, sha 7df63bd5a452)
  - registry_pypi: https://pypi.org/pypi/sipvicious/json (fetched 2026-08-29T12:49:38.948839+00:00, sha 949925262400)
- Data as of 2026-08-30T08:39:29.467469+00:00.
