
New releaseOct 11, 2026
afrog v3.5.8
A Security Tool for Bug Bounty, Pentest and Red Teaming.
A Security Tool for Bug Bounty, Pentest and Red Teaming
What is afrog
afrog is a high-performance security scanning toolkit built for bug bounty, pentest, and red team workflows. It combines fast target probing, built-in vulnerability checks, custom PoC authoring, and SDK-driven automation in a single Go-based workflow.
What afrog does
- Fast and focused scanning for web targets and network services
- Built-in and custom PoC support for practical security validation
- Lower false-positive noise through precise rule design and checks
- Flexible integration with Go applications, automation flows, and private PoC pipelines
Install
Dependencies
- Go 1.27 or later
Binary release
Download the latest release from:
Build from source
git clone https://github.com/zan8in/afrog.git
cd afrog
go mod tidy
go build -o afrog cmd/afrog/main.go
./afrog -h
Go install
go install -v github.com/zan8in/afrog/v3/cmd/afrog@latest
Quick start
Scan a single target:
afrog -t https://example.com
Scan multiple targets from a file:
afrog -T targets.txt
Run only high and critical checks:
afrog -T targets.txt -S high,critical
Start the built-in web console (open http://127.0.0.1:16868 in a browser and sign in with the password printed to the terminal):
afrog -web
Documentation
The documentation is organized into five handbooks:
| Handbook | Start here |
|---|---|
| User Guide | What afrog is and how to use it |
| Web Console | Run scans and manage results in a browser |
| PoC Authoring Guide | Write your first PoC |
| SDK Usage Guide | Embed afrog in your Go program |
| Curated PoC | Enable licensed curated PoCs |