Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
vuln-scanner — Vulnerability Assessment Scanner with Report Generation | Kitploit
Tools/GitHubGitHub/zappaboy/vuln-scanner
Vulnerability ScannersContainer SecurityStatic Code Analysis (SAST)API Security TestingConfiguration AuditingWeb SecurityNetwork SecurityPenetration TestingCloud SecurityDevSecOpsSecret DetectionDNS Analysis
11283 days agoNot yet reviewed
GitHubzappaboy/vuln-scanner

vuln-scanner

Vulnerability Assessment Scanner with Report Generation

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

vuln-scanner

An automated vulnerability assessment platform that orchestrates 210 open-source security tools, aggregates and deduplicates findings, optionally chains tools into a discovery data-flow graph, runs an optional OpenAI-compatible LLM analysis layer for triage, clustering, and remediation, generates proof-of-concept scripts, drives optional bug-bounty and pentester agents (Pydantic AI) to prove and PoC findings, and produces professional Markdown, HTML, JSON, and PDF reports — all from a single BlackArch Linux Docker image.


Table of Contents

  1. Architecture
  2. Tools
  3. Target Type Gating
  4. Scan Modes
  5. Tool Chaining
  6. Authenticated Scanning
  7. LLM Analysis
  8. PoC Generation and Execution
  9. Agentic Testing
  10. Plugin System
  11. Report Formats
  12. Quick Start
  13. scanner.sh — Docker Wrapper
  14. Configuration
  15. Environment Variables
  16. Project Structure
  17. Adding a New Tool
  18. Development
  19. DefectDojo Integration

Architecture

config.toml / env vars / CLI args
             ↓
       AppConfig (pydantic, 3-layer merge: TOML < env < CLI)
             ↓
     Plugin loader — auto-discovers ./plugins/ + ~/.vuln-scanner/plugins/
             ↓
     ScanOrchestrator
      • classify_target() → TargetType
      • tool.applies_to(target) — skips mismatched pairs
      • asyncio + ThreadPoolExecutor — parallel (tool × target) tasks
      • AuthConfig forwarded to every applicable tool
      • optional chaining: produces/consumes assets in a wave/fixpoint loop
             ↓
      ScanResult[]  →  Assessment  (+ chain_edges / assets_by_type)
             ↓
    LLMAnalyzer (optional)
      • Pass 1: triage + PoC design  (threaded, per result)
      • Pass 2: PoC generation       (PocGenerator, host-safe)
      • Pass 3: mitigation           (evidence-informed)
      • Pass 4: clustering + exec summary
             ↓
      PocRunner (container-only, VS_IN_CONTAINER=1 guard)
             ↓
    AgentOrchestrator (optional, container-only, sequential)
      • bug-bounty / pentester agents (Pydantic AI)
      • drive tools with custom args + run sandboxed code
      • scope-guarded, denylisted, audited → Assessment.agent_reports
             ↓
    ┌────────┬────────┬────────┐
    │   .md  │  .html │  .json │   (all formats written in parallel)
    └────────┴────────┴────────┘
             ↓
        DefectDojo (optional)

All scanning tools, PoC execution, and agent actions run inside a BlackArch Linux Docker container — nothing is installed on the host.


Tools

210 tools organized by category. Each tool declares the target types it supports; the orchestrator skips incompatible pairings automatically.

Network & Port Scanning

ToolNotes
nmapFull port scan with service/version detection
rustscanFast port scanner, feeds into nmap
masscanHigh-speed TCP/UDP scanner
naabuPort scanner with service detection
netdiscoverARP-based host discovery

Web Application

ToolNotes
nucleiTemplate-based vulnerability scanner
niktoWeb server misconfiguration scanner
wapitiBlack-box web vulnerability scanner
ffufFast web fuzzer (dirs, params, headers)
feroxbusterContent discovery with recursion
gobusterURI/DNS/vhost brute-forcer
wfuzzWeb application fuzzer
dalfoxXSS scanner with parameter analysis
xsstrikeAdvanced XSS detection engine
commixCommand injection exploiter
sqlmapAutomated SQL injection and takeover
nosqlmapNoSQL injection scanner
httpxHTTP probing and fingerprinting
whatwebWeb technology fingerprinter
wafw00fWAF detection and fingerprinting
wpscanWordPress vulnerability scanner
acunetixWeb vulnerability scanner (API-based)
arachniWeb application security scanner
zapOWASP ZAP DAST scanner
wapitiBlack-box vulnerability scanner
drheaderHTTP security header analyser
humbleHTTP header security checker
hakrawlerFast web crawler for URLs and endpoints
katanaNext-gen web crawling framework
gauKnown URL collector (AlienVault, WaybackMachine)
jsluiceJavaScript secrets and URL extractor
corscannerCORS misconfiguration scanner
crlfuzzCRLF injection scanner
smugglerHTTP request smuggling detector
linkfinderEndpoint discovery in JavaScript/HTML source
cariddiWeb crawler with secret and endpoint detection

API & GraphQL

ToolNotes
kiterunnerAPI route discovery with kite files
graphql_copGraphQL security auditor
restlerStateful REST API fuzzer
apifuzzerOpenAPI/Swagger-based fuzzer
cherrybombOpenAPI spec security linter
arjunHTTP parameter discovery
paramspiderParameter mining from wayback/sources

DNS & Reconnaissance

ToolNotes
amassSubdomain enumeration (passive + active)
subfinderFast passive subdomain enumeration
dnsxDNS resolver and probe toolkit
dnsreconDNS enumeration and zone transfer
fierceDNS reconnaissance and host discovery
theharvesterOSINT: emails, names, hosts, subdomains
purednsFast subdomain brute-forcer with wildcard filtering
alterxSubdomain permutation engine
waybackurlsHistorical URL collection from Wayback Machine
httprobeLive HTTP/HTTPS host prober

TLS / SSL

ToolNotes
testsslTLS configuration and cipher suite audit
sslyzeTLS scanner (cipher suites, Heartbleed, ROBOT)
sslscanSSL/TLS service scanner
tlsxFast TLS probing
tls_attackerTLS protocol attack tool
ssh_auditSSH configuration and algorithm auditor

SMB & Network Services

ToolNotes
smbmapSMB share enumeration and permissions
enum4linuxSMB/NetBIOS enumeration
crackmapexecActive Directory and SMB assessment
openvasOpenVAS vulnerability scanner

SAST & Code Analysis

ToolNotes
banditPython SAST — common security anti-patterns
semgrepMulti-language SAST with community rules
gosecGo security checker
bearerData-flow SAST with privacy and security rules
horusecMulti-language SAST engine
brakemanRuby on Rails SAST scanner
flawfinderC/C++ static analysis for common flaws
dependency_checkOWASP dependency vulnerability scanner
pip_auditPython package vulnerability checker

Software Composition Analysis (SCA)

ToolNotes
osv-scannerOpen Source Vulnerability database scanner
npm-auditNode.js package vulnerability audit
govulncheckGo module vulnerability checker

Secrets Detection

ToolNotes
gitleaksGit history secret scanner
trufflehogDeep entropy-based secret finder
secretfinderSecrets in JS files and endpoints
detect-secretsBaseline-based secret scanner
noseyparkerHigh-speed secret scanner with pattern rules

IaC & Configuration

ToolNotes
checkovTerraform/K8s/Dockerfile IaC scanner
tfsecTerraform static analysis
terrascanMulti-cloud IaC security scanner
hadolintDockerfile best-practice linter
Download Tool