# Tsunami Security Scanner

Tsunami is a general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high confidence.

Repository: https://github.com/google/tsunami-security-scanner
Canonical: https://ross.abutalabs.com/products/tsunami-security-scanner
Language: Java
License: Apache-2.0
License Family: permissive
Last push: 2026-06-23T16:05:00+00:00

## Health v2 (maintenance only)
Score: 74/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 89, release rhythm 39, longevity 100
- inputs: {"age_days": 2282, "days_push": 71, "days_rel": 195, "gap_med": null, "n_releases_24m": 1}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 8606, forks 924 (observed 2026-08-28T04:10:23.783155+00:00)

## What it is
Tsunami is a general-purpose network security scanner from Google that detects high-severity vulnerabilities with high confidence. It relies on an extensible plugin system, with publicly available plugins hosted in a companion repository.

## Use cases
- scan my network for high severity vulnerabilities
- detect vulnerable services on my infrastructure
- find exposed services with known CVEs
- run a plugin-based security scanner on my servers
- audit internal network for misconfigured services

## When to choose
- you need high-confidence detection of high-severity vulnerabilities rather than noisy broad scans
- you want an extensible scanner you can add custom detection plugins to
- you are scanning large internal or cloud networks for known vulnerable services

## When to avoid
- you need a full penetration testing or exploitation framework
- you want a lightweight point-and-click desktop scanner
- you need web application DAST with crawling and fuzzing out of the box

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, vulnerability-scanning, plugin-system, networking
- domain: security, penetration-testing, developer-tools
- platform: windows, jvm, cli
- tags: vulnerability-detection, network-scanner, java, extensible-plugins, google, linux, macos, docker

## Member repositories
- google/tsunami-security-scanner (main) score 74
- google/tsunami-security-scanner-plugins (plugin) score 77

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:10:23.783155+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:26:07.786542+00:00, confidence not recorded.
  - readme: https://github.com/google/tsunami-security-scanner (fetched 2026-08-28T04:10:23.783155+00:00, sha fe8c8c4765e6)
- Data as of 2026-08-30T08:39:29.467469+00:00.
