Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
NetLogic — NetLogic is an advanced network analysis and cybersecurity toolkit for traffic inspection, packet analysis, and threat detection | Kitploit
Tools/GitHubGitHub/dmitryflynn/netlogic
OSINT (Open Source Intelligence)ReconnaissanceVulnerability ScannersWeb SecurityNetwork SecurityPenetration TestingCloud SecuritySubdomain EnumerationDNS AnalysisAI Security
GitHubdmitryflynn/netlogic
1198 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

NetLogic

NetLogic is an advanced network analysis and cybersecurity toolkit for traffic inspection, packet analysis, and threat detection

View Repository

NetLogic

Cloud-Native Attack Surface Mapper & Vulnerability Correlator — v3.0

NetLogic is a network security platform combining active port scanning, CVE correlation (live NVD API), SSL/TLS analysis, HTTP security auditing, DNS/email security assessment, subdomain takeover detection, passive OSINT, active vulnerability probing, an AI-driven reasoning engine, cross-host attack chain discovery, and deep probe agent architecture — delivered as a web app (React dashboard + FastAPI). The core scan engine is pure Python 3.9+ stdlib with zero third-party dependencies.

Python 3.9+ License: MIT Platform


Features

ModuleDescription
Port ScannerTCP connect scan with 43/58 ports, 22 service probes, banner grabbing
CVE CorrelatorLive NVD API v2.0 + EPSS enrichment via FIRST.org
TLS AnalyzerProtocol versions, weak ciphers, POODLE/BEAST/CRIME/DROWN, cert expiry
HTTP Header AuditHSTS, CSP, X-Frame-Options, CORS, cookie flags; 0–100 score
Stack FingerprintCMS, framework, cloud provider, CDN, WAF detection from banner/header/body
DNS SecuritySPF, DKIM, DMARC, DNSSEC, zone transfer, spoofability score
Passive OSINTCertificate Transparency logs, DoH DNS, ASN lookup — no direct target contact
Service ProberUnauthenticated Redis/Mongo/ES/Docker/K8s/etcd probes, 33 admin paths
Takeover DetectorCT log subdomain discovery + 25 cloud provider CNAME fingerprints
Nuclei IntegrationWrapper for 13k+ community templates (CVE, tech, exposure, misconfig) — MIT license
Fusion PipelineMulti-sensor signal gate → deterministic agreement → AI adjudication → attack graph → 6-section report
Web FingerprintFavicon hash (Shodan-compatible mmh3), JS secrets, version markers, exposed files, default lander detection
AI AnalysisOpenAI / Anthropic / OpenRouter / Ollama / Gemini / Groq / Kimi / Qwen — token-streaming SSE
Reasoning EngineAdaptive observe→reason→act loop with EvidenceGraph, hypothesis engine, confidence decay, provenance, scheduler, playbooks, change detection, active validation
Deep ProbePer-service agent architecture: ScoutAgent (recon), ProbeAgent (targeted CVE checks), Coordinator, Sandbox
AI Investigation AgentReAct-style loop: after baseline sensors, the AI drives a curated, scope-gated, audited tool surface (~35 tools) to verify leads and build attack chains — with opt-in aggressive tools (crash probes, freeform proof, freeform exploit) for authorized targets
Verifier EngineAI-driven CVE re-verification: designs raw-HTTP probe plans from CVE context, executes via stdlib sockets
Multi-Host OrchestrationFull scan pipeline per host → cross-host context and reachability matrix → attack chain discovery
AI Sensor DirectorsLLM decides which sensors to prioritise based on open ports, tech stack, and CVEs
Authenticated SSHCredentialed ssh subprocess reads real installed package versions (60+ product mappings)
Service EnumProtocol-level attribute extraction (SSH KEX, SMBv1, RDP NLA, SNMP community, HTTP auth state)
Topology MapperReverse DNS, IPv6, traceroute, ASN/org/country via ip-api.com
Reachability ProberPost-compromise lateral movement matrix from subnet adjacency
Network ProberActive subnet sweep (/24 private neighbours) with two-phase discovery (live sweep → full port scan)
Scan DiffChange-over-time: diffs current scan against most recent prior JSON report per target
License ManagementCommercial license system with key activation (stub for Stripe/Paddle/Lemon Squeezy)
Per-Org AI ConfigEach org stores its own LLM credentials encrypted at rest via Fernet
OIDC / ClerkHuman logins via Clerk-issued session JWTs verified against public JWKS with auto-provisioning
PostgreSQLFull multi-tenant persistence with auto-applied migrations (scan jobs, org settings, reasoning state, audit)
Fusion BenchmarkOffline benchmark against recorded HTTP cassettes; precision/recall/critical-recall/FP-reduction metrics

How to Run

There are exactly two ways to run NetLogic:

ModeCommandWhat it does
Web appnetlogic --guiStarts FastAPI + serves the React SPA + in-process scan agent, auto-generates secrets, and opens the dashboard in your browser. This is the only way to run the web app.
CLInetlogic <target> [flags]One-shot terminal scan (no server), prints/writes the report.

The product surface is the web app (React dashboard + FastAPI). The scan engine under src/ powers jobs started from the UI.


Quick Start

# One-time install
pip install -r requirements-api.txt
pip install -e .

# Run the web dashboard
netlogic --gui
# → Dashboard at http://localhost:8000, auto-generated secrets in ~/.netlogic/secrets.json
# (first run builds the dashboard automatically; requires Node.js)

# Or a one-shot CLI scan
netlogic scanme.nmap.org --full

CLI Reference

netlogic [target] [flags]

The entry point is api.cli:main (defined in pyproject.toml), which delegates to netlogic.py:main(). All scan logic is in src/.

Target specification

FormatExampleMode
Hostnameexample.comSingle-host scan
IPv410.0.0.5Single-host scan
CIDR192.168.1.0/24CIDR sweep (scanner only, no fusion)
Comma-separatedtarget1,target2Multi-host orchestration (cross-host context)

Scan scope

# Basic scan — 43 common ports + CVE correlation
netlogic example.com

# Full scan — all modules enabled
netlogic example.com --full

# Deep TLS + HTTP header audit
netlogic example.com --tls --headers

# Subdomain takeover detection
netlogic example.com --takeover

# Passive OSINT only
netlogic example.com --osint

# Technology stack + WAF fingerprinting
netlogic example.com --stack

# DNS/email security (SPF, DKIM, DMARC, DNSSEC)
netlogic example.com --dns

# Active service probing (unauthenticated access, default creds, CVE-specific checks)
netlogic 10.0.0.5 --probe

# Everything — all flags combined
netlogic example.com --full --probe

Port selection

# Quick — 43 common ports (default)
netlogic example.com --ports quick

# Full — 58 extended ports
netlogic example.com --ports full

# Custom list
netlogic example.com --ports custom=22,80,443,8080,9200

AI analysis

# OpenRouter (default)
netlogic example.com --ai --ai-key $KEY

# OpenAI
netlogic example.com --ai --ai-provider openai --ai-key $KEY --ai-model gpt-4o-mini

# Anthropic
netlogic example.com --ai --ai-provider anthropic --ai-key $KEY

# Gemini
netlogic example.com --ai --ai-provider gemini --ai-key $KEY --ai-model gemini-2.0-flash

# Local Ollama
netlogic example.com --ai --ai-provider ollama

# Custom OpenAI-compatible endpoint
netlogic example.com --ai --ai-provider custom --ai-base-url https://... --ai-model model-name

AI providers supported

ProviderDefault modelAPI style
openrouteranthropic/claude-sonnet-4OpenAI
openaigpt-4o-miniOpenAI
anthropicclaude-3-5-sonnet-20241022Anthropic Messages
kimi (Moonshot)kimi-k2.6OpenAI
qwen (Alibaba)qwen-plusOpenAI
groqllama-3.3-70b-versatileOpenAI
gemini (Google)gemini-2.0-flashOpenAI
ollamallama3OpenAI
customuser-specifiedOpenAI

Reasoning engine

Download Tool