Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
DakshSCRA β€” Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and suppression baselines. | Kitploit
Tools/GitHubGitHub/coffeeandsecurity/dakshscra
Static AnalysisVulnerability ScannersStatic Code Analysis (SAST)Vulnerability AnalysisCode AnalysisWeb SecurityPenetration TestingDevSecOpsMobile SecurityLearning & Education
GitHubcoffeeandsecurity/dakshscra
4571144 days agoReviewed by Kitploit

DakshSCRA

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and suppression baselines.

View Repository

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

Daksh SCRA (Source Code Review Assist)

Author:
- Debasis Mohanty ([email protected])
- Twitter / X: @coffeensecurity
- www.coffeeandsecurity.com

About Daksh SCRA

Daksh SCRA (Source Code Review Assist) is built to enhance the efficiency of the source code review process, providing a well-structured and organised approach for code reviewers.

Rather than indiscriminately flagging everything as a potential issue, Daksh SCRA promotes thoughtful analysis, urging the investigation and confirmation of potential problems. This approach mitigates the scramble to tag every potential concern as a bug, cutting back on the confusion and wasted time spent on false positives.

Debut

Daksh SCRA was initially introduced during a source code review training session at Black Hat USA 2022 (August 6-9), where it was subtly presented to a specific audience. Its official public debut took place at Black Hat USA 2023 in Las Vegas.

Features and Functionalities

  • Identifies Areas of Interest in Source Code: Encourages focused investigation and confirmation rather than indiscriminately labelling everything as a bug.
  • Identifies Areas of Interest in File Paths (World's First): Recognises patterns in file paths to pinpoint relevant sections for review.
  • Software-Level Reconnaissance to Identify Technologies Utilised: Identifies project technologies, enabling code reviewers to conduct precise scans with appropriate rules.
  • Automated Scientific Effort Estimation for Code Review (World's First): Provides a measurable approach for estimating the effort required for a code review.
  • Framework-Aware Scanning: Automatically applies framework-specific rules when the project's framework is detected.
  • Taint Analysis Reports: Per-platform HTML taint flow reports with hacker-mode and professional-mode themes.
  • RDL (Rule Description Language): External rule logic referenced with rdl_ref and executed by the core/rdl_engine.py pipeline - supports file-aware gates, boolean expressions, project observations, and exported logic metadata in reports.
  • Scan State / Resume: Checkpoint long scans and resume after interruption.
  • Suppression Baseline: Generate and apply a baseline of known false positives to suppress them from future reports.
  • Web UI: Browser-based scan launcher with real-time console feed and job artifact browser.

Active enhancements are ongoing. Multiple new features and improvements are planned for upcoming releases.

Feel free to contribute towards updating or adding new rules and future development.

If you find any bugs, report them to [email protected].

Detailed documentation: https://dakshlabs.com/#docs


Getting Started

There are two ways to run Daksh SCRA - pick whichever fits your workflow:

Best forJump to
🌐 Web UI (Docker)The easiest way to get started - one command, a browser dashboard, live scan progress, and a report/artifact browser. Recommended for most users.Web UI (Docker)
πŸ’» CLI (Python)Scripting, CI pipelines, or running scans without Docker.CLI Setup

Both paths run the exact same scanning engine - the Web UI is a browser front end over the same CLI, so results are identical either way.


Web UI (Docker)

The fastest way to run Daksh SCRA is through its browser-based Web UI, launched with the host-aware Docker startup helper. It gives you a scan launcher, a live console feed, and a browsable history of past reports. The startup helper needs Python 3 (standard library only); the application and its dependencies run in Docker.

The Docker setup runs the Web UI and the CLI as independent services built from the same image, so you can use either (or both) from the same container.

Launch the Web UI

After downloading Daksh SCRA from GitHub, extract the ZIP archive first. Open a terminal (PowerShell or Command Prompt on Windows) inside the extracted project folder containing docker-compose.yml and dakshscra.py. Run all startup and Docker Compose commands below from that folder.

If your terminal opens elsewhere, change into the extracted folder first:

cd "path/to/extracted/DakshSCRA-folder"

Replace the example path with your actual download location and folder name. If you cloned the repository instead, run cd DakshSCRA from its parent folder.

The startup helper recognizes Windows, WSL, Linux and macOS, then mounts the host root, available Windows drives and common folders read-only before starting the containers. Run it on the computer running Docker.

Linux, macOS or WSL (foreground):

python3 tools/start_webui.py

Windows PowerShell or Command Prompt (foreground):

py tools/start_webui.py

Add --detach for background mode, or --dry-run to inspect detected paths. Existing .env path overrides are respected. Accounts, scans and the runtime volume are preserved when containers are recreated.

Docker Desktop may require permission to share the selected host paths. If it rejects a mount, allow that location in Docker Desktop and rerun the helper. A remote browser sees the Docker host's folders, not its own computer's drives. Automatic detection requires a local Docker engine; run the helper on the engine host when using a remote Docker context.

For manually configured mounts, docker compose up --build -d api web remains available. Its baseline mounts the repository at /scan-targets and ${DAKSH_HOST_MOUNT:-/} at /host/root. Use the helper for Windows drive discovery and common-folder shortcuts; plain Compose cannot detect the client OS.

Then open http://localhost:8080.

To use a different port:

DAKSH_PORT=9090 python3 tools/start_webui.py

Stop the stack with:

docker compose down

Logging in

The Web UI requires an account. On first startup, an initial admin account is created from DAKSH_ADMIN_USERNAME / DAKSH_ADMIN_PASSWORD (set these in .env); if DAKSH_ADMIN_PASSWORD is left unset, a random password is generated and printed once to the API's startup log - save it, since it cannot be recovered afterward.

You'll be required to set your own password (and, optionally, username) the first time you log in. An admin account can create further accounts via the POST /api/v1/auth/users API endpoint (no dedicated UI for this yet). See .env.example for the full list of authentication-related settings (session lifetime, cookie security, CORS).

What you get

  • Responsive command builder for scan, recon, estimate, recon+estimate, list, and PDF-from-JSON modes
  • Real-time console feed and live per-stage progress during execution
  • Per-job artifact snapshots for HTML / PDF / JSON outputs
  • Fast in-browser navigation across run form, live feed, artifacts, and recent jobs
  • Built-in directory browser for selecting target paths (OS-aware: Windows, macOS, Linux / Docker)

Under the hood, the CLI remains the source of truth - it does all the scanning and generates every HTML / PDF / JSON output. The Web UI runs one active job at a time and snapshots each completed job's outputs into runtime/webui/jobs/<job-id>/artifacts/ so past reports stay accessible.

Running the CLI in Docker

You don't need a local Python environment to use the CLI either - it's available as its own Compose service, built from the same image:

docker compose run --rm cli -h
docker compose run --rm cli -r auto -t /scan-targets/path/to/source

What's in the image

  • FastAPI backend + Web UI frontend
  • The full Daksh SCRA CLI, as a separate service
  • Playwright Chromium, for PDF generation
  • Persistent reports/ and runtime/ volumes
  • Host path mounts so scans can reach source trees from inside the container

Key mount points:

Download Tool