Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
sif — the blazing-fast pentesting suite. | Kitploit
Tools/GitHubGitHub/vmfunc/sif
ReconnaissanceVulnerability ScannersPort ScanningExploitationInformation GatheringWeb SecurityPenetration TestingSubdomain EnumerationCrawlerDNS Analysis
GitHubvmfunc/sif
61427221 month agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

sif

the blazing-fast pentesting suite.

View Repository
sif



go version build license aur nixpkgs homebrew apt discord

install · usage · modules · docs · contribute

fast, concurrent recon to exploitation in one binary. every scanner shares one connection-pooled http client.


what is sif?

sif is a recon and exploitation scanner that runs the whole chain in one binary: subdomain enum, port scan, crawler, nuclei, framework/cve detection, js secret extraction, web-vuln probes (cors/xss/redirect), cloud and takeover checks. 25+ scan types, one command.

sif -u https://example.com -dnslist -ports -crawl -js -framework -nuclei

nuclei and colly are compiled in as libraries rather than shelled out to (there's no exec.Command in the tree), so it's a single static binary with no runtime dependencies and nothing to wire together.

every scanner runs through one shared http client and a work-stealing worker pool. -proxy, -H, -cookie and -rate-limit apply to the whole run at once, connections get pooled and reused across the scan (a single-host run reuses one connection for ~50 requests instead of dialing 50 times), and a slow host doesn't hold the rest up. that shared client is the practical reason to use it over piping a stack of separate tools together. port scanning is connect()-based, so rustscan and nmap are still faster at raw port scans.

it reads targets from stdin and prints findings one per line under -silent, so it composes:

subfinder -d example.com | sif -silent -crawl -js -nuclei | notify

-diff turns a re-scan into a monitor that only reports what changed, -notify posts to slack/discord/telegram/webhook, and runs export to sarif and markdown.

install

homebrew (macos)

brew tap vmfunc/sif
brew install sif

arch linux (aur)

install using your preferred aur helper:

yay -S sif
# or
paru -S sif

nix

# nixpkgs (declarative: add to configuration.nix or home-manager)
environment.systemPackages = [ pkgs.sif ];

# or imperatively
nix profile install nixpkgs#sif

# or just run it without installing
nix run nixpkgs#sif -- -u https://example.com -headers -sh -framework

the repo also ships a flake if you want to build from source:

nix run github:vmfunc/sif

debian/ubuntu (apt)

curl -1sLf 'https://dl.cloudsmith.io/public/sif/deb/setup.deb.sh' | sudo -E bash
sudo apt-get install sif

from releases

grab the latest binary from releases.

from source

git clone https://github.com/vmfunc/sif.git
cd sif
make

requires go 1.25+

aur (manual install)

git clone https://aur.archlinux.org/sif.git
cd sif
makepkg -si

usage

# basic scan
./sif -u https://example.com

# directory fuzzing
./sif -u https://example.com -dirlist medium

# subdomain enumeration
./sif -u https://example.com -dnslist medium

# port scanning
./sif -u https://example.com -ports common

# javascript framework detection + cloud misconfig
./sif -u https://example.com -js -c3

# shodan host intelligence (requires SHODAN_API_KEY env var)
./sif -u https://example.com -shodan

# securitytrails domain discovery (requires SECURITYTRAILS_API_KEY env var)
# discovers subdomains + associated domains, then scans all of them
./sif -u https://example.com -securitytrails -headers

# sql recon + lfi scanning
./sif -u https://example.com -sql -lfi

# web vuln probes (cors, open redirect, reflected xss)
./sif -u https://example.com -cors -redirect -xss

# framework detection (with cve lookup)
./sif -u https://example.com -framework

# a broad sweep
./sif -u https://example.com -dirlist small -dnslist small -ports common -headers -sh -cms -framework -git -whois

run ./sif -h for all options.

commands

a couple of subcommands run without scanning:

# print the version (release builds are stamped; local builds use git describe)
./sif version

# show the latest release notes (also -pn)
./sif patchnote

the first time you run a new release, sif prints that release's notes once. set SIF_NO_PATCHNOTES=1 to turn that off.

modules

sif has a modular architecture. modules are defined in yaml and can be extended by users.

built-in scan flags

flagdescription
-dirlistdirectory and file fuzzing (small/medium/large)
-mcdirlist: match these status codes (comma list, e.g. 200,301)
-fcdirlist: filter out these status codes (comma list)
-fsdirlist: filter out responses of these body sizes (comma list)
-fwdirlist: filter out responses with these word counts (comma list)
-frdirlist: filter out responses whose body matches this regex
-acauto-calibrate the soft-404 wildcard baseline (dirlist, sql)
-wdirlist: custom wordlist (local file or url; overrides -dirlist size)
-edirlist: extensions appended to each word (comma list, e.g. php,bak,env)
-dnslistsubdomain enumeration (small/medium/large)
-portsport scanning (common/full)
-nucleivulnerability scanning with nuclei templates
-dorkautomated google dorking
-jsjavascript analysis + secret and endpoint extraction
-c3cloud storage misconfiguration
-headershttp header analysis
-shsecurity header analysis (missing/weak headers)
-stsubdomain takeover detection
-cmscms detection
-whoiswhois lookups
-gitexposed git repository detection
-shodanshodan lookup (requires SHODAN_API_KEY)
-securitytrailsdomain discovery + target expansion (requires SECURITYTRAILS_API_KEY)
-sqlsql recon
-lfilocal file inclusion
-jwtjwt discovery + offline weakness analysis (alg:none, weak hmac, exp, sensitive claims)
-openapiopenapi/swagger spec exposure probe (enumerates paths + unauth endpoints)
-faviconfavicon hash fingerprinting (shodan-style mmh3, tech match + pivot query)
-corscors misconfiguration probe
-redirectopen redirect probe
-xssreflected xss probe
-frameworkframework detection with cve lookup
-crawlweb crawler (spider same-host links/scripts/forms)
-crawl-depthmax crawl recursion depth (default 2)
-passivepassive subdomain/url discovery (zero traffic to target)
-probelive-host probe (status, title, server, redirect chain)

http options

these apply to every outbound request across all scanners:

Download Tool