Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
aimap — Discover Exposed AI Services | Kitploit
Tools/GitHubGitHub/bishopfox/aimap
OSINT (Open Source Intelligence)ReconnaissanceVulnerability ScannersWeb Application ExploitationInformation GatheringWeb SecurityPenetration TestingRed TeamingAI Security
GitHubbishopfox/aimap

aimap

Discover Exposed AI Services

31146195 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

AIMap

Internet-scale discovery and security testing platform for exposed AI agent infrastructure.

AIMap UI Tour

AIMap finds, fingerprints, and security-tests publicly exposed AI endpoints — MCP servers, Ollama instances, vLLM/LiteLLM proxies, LangServe chains, Gradio apps, ComfyUI nodes, and more. Think Shodan, but purpose-built for the AI agent attack surface.

Built by Bishop Fox.

Warning This tool is intended for authorized penetration testing and security research only. You must only use AIMap against systems you own or have explicit written permission to test. Unauthorized access to computer systems is illegal. Bishop Fox assumes no liability and is not responsible for any misuse or damage caused by this tool. Use responsibly.


What It Does

  1. Discover — Queries Shodan with 32+ curated search queries to find exposed AI/ML endpoints across the internet
  2. Fingerprint — Probes each endpoint with Nuclei templates and live HTTP checks to identify the protocol, framework, auth status, tools, models, and system prompts
  3. Score — Computes a 0–10 risk score based on authentication, tool exposure, CORS policy, TLS, system prompt leakage, and dangerous capability combinations
  4. Test — Launches protocol-specific attack suites (MCP tool abuse, Ollama model extraction, prompt injection) with real-time streaming results
  5. Visualize — 3D globe showing every discovered endpoint, searchable with a Shodan-style query language

Architecture

┌─────────────┐     ┌──────────────┐     ┌───────────┐
│  React SPA  │────▶│  FastAPI      │────▶│  MongoDB  │
│  (Vite)     │ WS  │  Backend      │     │           │
└─────────────┘     └──────┬───────┘     └───────────┘
                           │
              ┌────────────┼────────────┐
              ▼            ▼            ▼
        ┌──────────┐ ┌──────────┐ ┌──────────┐
        │  Shodan  │ │  Nuclei  │ │  Redis   │
        │  API     │ │  Scanner │ │  Streams │
        └──────────┘ └──────────┘ └──────────┘

Backend — Python/FastAPI with async MongoDB (Motor), Redis Streams for attack log streaming, and a discovery engine that orchestrates Shodan queries → httpx liveness checks → Nuclei template scans → enrichment pipeline.

Frontend — React 18 + TypeScript + Tailwind CSS + shadcn/ui. Features a 3D globe (globe.gl), real-time attack streaming via WebSocket, and a Shodan-style search interface.

Scanning — 5 custom Nuclei YAML templates for MCP server detection, MCP tool enumeration, OpenAI-compatible API detection, LangServe detection, and prompt leak testing.


Supported Protocols

ProtocolDetection MethodShodan Queries
MCP (Model Context Protocol)SSE transport, JSON-RPC, /mcp/sse paths4 queries
OllamaDefault port 11434, product fingerprint3 queries
vLLM / LiteLLM / LocalAI/v1/models, /v1/chat/completions endpoints4 queries
LangServe / LangChainPlayground endpoints, langserve markers2 queries
OpenClaw / ClawdbotControl dashboard, port 187893 queries
Open WebUI / LibreChatTitle-based detection2 queries
GradioTitle, footer watermark, favicon hash3 queries
StreamlitTitle, favicon hash2 queries
ComfyUI / Stable DiffusionTitle, port-based detection4 queries
HuggingFace TGIHTML markers1 query
Generic inference/api/generate, /api/tags paths2 queries

Risk Scoring

Each endpoint receives a 0–10 risk score computed from:

FactorScore Impact
No authentication+4.0
Unknown auth status+1.0
10+ tools exposed+2.0
5+ tools exposed+1.0
Critical-risk tool (e.g., exec_code, run_shell)+1.0 each
High-risk tool (e.g., query_db, file_read)+0.5 each
Open CORS (*)+1.0
No TLS+0.5
System prompt leaked+0.5
Models exposed+1.0
Uncensored model detected+2.0
Signup enabled (no invite required)+1.5
Dangerous combo (e.g., no auth + code exec tool)+1.0 each

Setup

Prerequisites

  • Python 3.12+
  • Node.js 18+
  • MongoDB 7+
  • Redis 7+ (optional — falls back to in-memory for local dev)
  • Nuclei (optional — needed for active scanning)
  • A Shodan API key (required for discovery scans)

Quick Start (Docker Compose)

# Clone
git clone [email protected]:BishopFox/aimap.git
cd aimap

# Configure
cp .env.example .env
# Edit .env — at minimum set SHODAN_API_KEY

# Launch
docker compose up --build

This starts 4 services:

  • MongoDB on port 27017
  • Redis on port 6379
  • Backend on port 8000
  • Frontend on port 80

Open http://localhost to access the UI.

Local Development (without Docker)

# Backend
cd backend
python -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
uvicorn app.main:app --reload --port 8000

# Frontend (separate terminal)
cd frontend
npm install
npm run dev   # starts on http://localhost:5173

Make sure MongoDB is running locally on port 27017. Redis is optional — the backend falls back to in-memory buffers when Redis is unavailable.

Environment Variables

Create a .env file in the project root:

# Required
SHODAN_API_KEY=your_shodan_api_key

# Optional — Censys as an additional discovery source
CENSYS_API_ID=
CENSYS_API_SECRET=

# Optional — enables AI-powered attack analysis
ANTHROPIC_API_KEY=

# MongoDB (defaults work for local dev)
MONGODB_URI=mongodb://localhost:27017
MONGODB_DB=aimap

# Redis (defaults work for local dev; optional)
REDIS_URL=redis://localhost:6379/0

# CORS (default allows all origins)
CORS_ORIGINS=*

# Modal serverless (dispatches scans/attacks to Modal containers)
MODAL_ENABLED=false

# Clerk auth — see below
CLERK_ISSUER=

Authentication (Clerk)

AIMap uses Clerk for authentication. To enable:

  1. Create a Clerk application at clerk.com
  2. Set the backend issuer URL:
    # .env (project root)
    CLERK_ISSUER=https://your-app.clerk.accounts.dev
    
  3. Set the frontend publishable key:
    # frontend/.env.local
    VITE_CLERK_PUBLISHABLE_KEY=pk_test_...
    

To disable authentication (local dev, demos): leave CLERK_ISSUER empty or unset. The backend will accept all requests with a synthetic local user identity.


Usage

Running a Discovery Scan

  1. Navigate to Scans in the sidebar
  2. Click New Scan
  3. Select query presets (e.g., ollama, mcp_protocol, vllm) or enter a custom Shodan query
  4. Optionally scope to a CIDR range (the orchestrator prepends net:<cidr> to each query)
  5. Click Run — the scan pipeline executes:
    • Shodan search — pulls matching hosts
    • httpx sweep — verifies hosts are alive
    • Nuclei scan — runs custom templates against live hosts
    • Enrichment — framework detection, auth probing, risk scoring
  6. Monitor progress via the real-time WebSocket status bar or by polling the scan detail page

Searching Endpoints

Use the search bar with Shodan-style query syntax:

Download Tool