Ross ROSS = Recommend OSS · open-source software intelligence for agents

Ladon

Ladon大型内网渗透扫描器,PowerShell、Cobalt Strike插件、内存加载、无文件扫描。含端口扫描、服务识别、网络资产探测、密码审计、高危漏洞检测、漏洞利用、密码读取以及一键GetShell,支持批量A段/B段/C段以及跨网段扫描,支持URL、主机、域名列表扫描等。网络资产探测32种协议(ICMP\NBT\DNS\MAC\SMB\WMI\SSH\HTTP\HTTPS\Exchange\mssql\FTP\RDP)或方法快速获取目标网络存活主机IP、计算机名、工作组、共享资源、网卡地址、操作系统版本、网站、子域名、中间件、开放服务、路由器、交换机、数据库、打印机等,大量高危漏洞检测模块MS17010、Zimbra、Exchange observed · 2026-08-28

github.com/k8gege/Ladon · homepage · C# · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

29/100

  • Activity 13
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2496
  • days_rel: n/a
  • days_push: 527
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

5320 stars · 882 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Ladon is a large-scale internal network penetration scanner written in C#, offering port scanning, service identification, network asset discovery, password auditing, high-risk vulnerability detection, exploitation, and one-click GetShell. It supports PowerShell modules, Cobalt Strike plugin in-memory loading, fileless scanning, and cross-platform use via LadonGo.

Use cases

  • scan an internal network for live hosts and open services
  • detect high-risk vulnerabilities like MS17010 and SMBGhost across a subnet
  • brute-force passwords for SSH, databases, and Windows services
  • discover network assets across A/B/C class segments
  • perform lateral movement from a Cobalt Strike beacon
  • identify web fingerprints and middleware on discovered hosts
  • run fileless scans via PowerShell in-memory loading

When to choose

  • you need an all-in-one intranet penetration scanner with a tiny footprint
  • you want Cobalt Strike plugin integration for fileless lateral movement
  • you need batch scanning of large network ranges with low traffic
  • you want extensible POC/EXP plugins in .NET, DLL, or PowerShell

When to avoid

  • you need a passive or compliance-focused vulnerability scanner
  • you require a GUI-driven enterprise scanning platform
  • your targets are external internet-facing assets rather than internal networks
  • you need detailed reporting for remediation rather than exploitation

Facets

cli-tool · maturity active

penetration-testing vulnerability-scanning networking security search-engine penetration-testing security networking crawlers windows cli cross-platform port-scanner network-scanner cobalt-strike powershell lateral-movement password-audit exploit red-team csharp in-memory-loading linux macos

2 sources

Member repositories

RepositoryRoleHealth v2
k8gege/Ladonmain29
k8gege/LadonGomirror23
k8gege/Aggressorplugin23

For agents

markdown · JSON · MCP: product_card(name="k8gege/Ladon")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem