Back to updates
New releaseOct 11, 2026

afrog v3.5.8

A Security Tool for Bug Bounty, Pentest and Red Teaming.

Share

afrog

A Security Tool for Bug Bounty, Pentest and Red Teaming

English • 中文

Go version Latest release GitHub stars License Issues

What is afrog

afrog is a high-performance security scanning toolkit built for bug bounty, pentest, and red team workflows. It combines fast target probing, built-in vulnerability checks, custom PoC authoring, and SDK-driven automation in a single Go-based workflow.

What afrog does

  • Fast and focused scanning for web targets and network services
  • Built-in and custom PoC support for practical security validation
  • Lower false-positive noise through precise rule design and checks
  • Flexible integration with Go applications, automation flows, and private PoC pipelines

Install

Dependencies

  • Go 1.27 or later

Binary release

Download the latest release from:

Build from source

git clone https://github.com/zan8in/afrog.git
cd afrog
go mod tidy
go build -o afrog cmd/afrog/main.go
./afrog -h

Go install

go install -v github.com/zan8in/afrog/v3/cmd/afrog@latest

Quick start

Scan a single target:

afrog -t https://example.com

Scan multiple targets from a file:

afrog -T targets.txt

Run only high and critical checks:

afrog -T targets.txt -S high,critical

Start the built-in web console (open http://127.0.0.1:16868 in a browser and sign in with the password printed to the terminal):

afrog -web

Documentation

The documentation is organized into five handbooks:

HandbookStart here
User GuideWhat afrog is and how to use it
Web ConsoleRun scans and manage results in a browser
PoC Authoring GuideWrite your first PoC
SDK Usage GuideEmbed afrog in your Go program
Curated PoCEnable licensed curated PoCs

PoC Contributors

Categories