
Multi-phase reconnaissance and attack-surface scanner that maps domains, IPs, ASNs, cloud assets, and CVEs into a knowledge graph with CVSS scoring and compliance mapping.

Security Intelligence Framework
Argus is a multi-phase security reconnaissance and analysis framework built for professional penetration testing and attack surface assessment. It runs fully autonomous — no API keys required, no external services, no accounts. A single command produces a complete picture of an organization's external exposure.
argus/
├── sources/ Certificate Transparency, passive DNS, brute force
├── correlators/ DNS resolution, CDN bypass, port scanning
├── intelligence/ 43 analysis modules
│ ├── Core TLS, HTTP, email, content discovery, JS secrets
│ ├── Graph Attack paths, compliance, CVE, anomaly detection
│ ├── Advanced SSRF chains, OAuth/GraphQL/WebSocket, BGP, stealth
│ └── Intelligence Deep CVE, API enumeration, cloud storage, threat intel
├── ontology/ Knowledge graph (NetworkX), entity model, pivot engine
├── output/ HTML report, executive report, CSV, JSON, terminal
└── web/ FastAPI real-time dashboard with WebSocket
The engine builds a Knowledge Graph of all discovered entities — domains, IPs, certificates, organizations, technologies, open ports — and the relationships between them. Every finding is an anomaly attached to a graph node with a CVSS 3.1 score, attack path linkage, and compliance mapping.
| Range | Category | Coverage |
|---|---|---|
| 1–9 | Reconnaissance | CT log collection, passive DNS, AXFR, subdomain brute force (2,500+ words + permutations), DNS resolution, IPv6, ASN intelligence, CDN origin bypass |
| 10–17 | Surface Analysis | TLS fingerprinting, HTTP header analysis, content discovery (100+ paths), JavaScript secret scanning, supply chain CVEs, cache poisoning, CORS, HTTP smuggling probes |
| 18–30 | Intelligence | Email security (SPF/DMARC/DKIM), Wayback Machine, reverse IP, JARM C2 fingerprinting, anomaly detection, CVSS 3.1 scoring, attack path synthesis, compliance mapping (OWASP/GDPR/ISO 27001/NIST/PCI-DSS), CVE correlation, graph analytics, scan diff |
| 31–35 | Active Testing | HTTP request smuggling (CL.TE/TE.CL/TE.TE), cross-org correlation, GNN subdomain prediction, authentication analysis (forms/JWT/Basic Auth), parameter fuzzing (SQLi/XSS/SSRF/IDOR/traversal) |
| 36–39 | Advanced | BGP/AS path + cloud provider correlation, SSRF chain pivoting (cloud metadata, internal services, Gopher), OAuth/GraphQL/WebSocket protocol fuzzing, honeypot detection |
| 40–43 | Intelligence+ | Deep CVE fingerprinting (22 technologies), API/OpenAPI/Swagger enumeration, cloud storage enumeration (S3/Azure/GCS/DO), threat intelligence (DNS blacklists, Tor exits, ASN reputation) |
Requirements: Python 3.9+, Linux/macOS/Termux
git clone https://github.com/DozerMx/Argus
cd Argus
pip install -r requirements.txt
Web UI (optional):
pip install fastapi uvicorn websockets
python argus.py -d TARGET [OPTIONS]
# CT log collection + DNS resolution + anomaly detection
python argus.py -d target.com
# Full 43-phase scan
python argus.py -d target.com --full
# Full scan with executive report
python argus.py -d target.com --full --output executive
# Full scan with authentication and fuzzing
python argus.py -d target.com --full --fuzz --auth
# Scan with known credentials
python argus.py -d target.com --full --auth --user admin --password admin123
# Subdomain brute force + AXFR
python argus.py -d target.com --brute --axfr
# Deep infrastructure: ASN + CDN bypass + ports
python argus.py -d target.com --deep --cdn-bypass --ports
# Stealth scan (paranoid jitter profile)
python argus.py -d target.com --full --stealth-profile paranoid
# Through Tor
python argus.py -d target.com --full --proxy socks5://127.0.0.1:9050
# Bulk scan from file
python argus.py -f targets.txt --full --output json
# Continuous monitoring with Slack alerts
python argus.py -d target.com --daemon --webhook https://hooks.slack.com/...
# Web UI dashboard
python argus.py --serve --ui-port 8080
Target:
-d DOMAIN Single target domain
-f FILE File with one domain per line
Scan Modules:
--full Enable all modules
--deep ASN, cloud detection, Wayback, reverse IP
--brute Subdomain brute force + permutations
--axfr DNS zone transfer
--cdn-bypass CDN/WAF origin IP discovery
--ports TCP port scan + banner grab (178 ports)
--jarm JARM TLS fingerprinting
--fuzz Parameter fuzzing (SQLi, XSS, SSRF, IDOR, traversal)
--auth Authentication analysis
--user USER Username for authenticated scanning
--password PASS Password for authenticated scanning
Output:
--output FORMAT terminal | html | executive | json | csv
--outfile PATH Output file path
-v Verbose logging
-q Quiet mode
Performance:
--threads N Concurrent threads (default: 30)
--timeout N Request timeout in seconds (default: 10)
--proxy URL Proxy (socks5://host:port or http://host:port)
--no-cache Disable disk cache
--stealth-profile paranoid | careful | normal | aggressive
Web UI:
--serve Launch real-time web dashboard
--ui-port N Web UI port (default: 8080)
Daemon:
--daemon Continuous monitoring mode
--webhook URL Webhook URL for alerts (Slack/Telegram)
--interval N Scan interval in hours (default: 6)
Interactive graph visualization of the full infrastructure with findings, risk scoring, and relationship mapping. Self-contained single file.
Business-language summary with attack path narrative, compliance violations by framework, prioritized remediation roadmap, and risk matrix.