
Scanner de reconnaissance et de surface d’attaque multi-phase qui cartographie les domaines, les IP, les ASN, les actifs cloud et les CVE dans un graphe de connaissances avec notation CVSS et mise en correspondance de conformité.

Framework de renseignement en sécurité
Argus est un framework de reconnaissance et d'analyse de sécurité multi-phases conçu pour les tests d'intrusion professionnels et l'évaluation de la surface d'attaque. Il fonctionne de manière entièrement autonome — aucune clé API requise, aucun service externe, aucun compte. Une seule commande produit une image complète de l'exposition externe d'une organisation.
argus/
├── sources/ Certificate Transparency, passive DNS, brute force
├── correlators/ DNS resolution, CDN bypass, port scanning
├── intelligence/ 43 analysis modules
│ ├── Core TLS, HTTP, email, content discovery, JS secrets
│ ├── Graph Attack paths, compliance, CVE, anomaly detection
│ ├── Advanced SSRF chains, OAuth/GraphQL/WebSocket, BGP, stealth
│ └── Intelligence Deep CVE, API enumeration, cloud storage, threat intel
├── ontology/ Knowledge graph (NetworkX), entity model, pivot engine
├── output/ HTML report, executive report, CSV, JSON, terminal
└── web/ FastAPI real-time dashboard with WebSocket
Le moteur construit un graphe de connaissances de toutes les entités découvertes — domaines, IP, certificats, organisations, technologies, ports ouverts — et des relations entre elles. Chaque constat est une anomalie rattachée à un nœud du graphe avec un score CVSS 3.1, un lien avec les chemins d'attaque et un mappage de conformité.
| Plage | Catégorie | Couverture |
|---|---|---|
| 1–9 | Reconnaissance | Collecte de journaux CT, DNS passif, AXFR, force brute de sous-domaines (2 500+ mots + permutations), résolution DNS, IPv6, renseignement ASN, contournement de l'origine CDN |
| 10–17 | Analyse de surface | Empreinte TLS, analyse d'en-têtes HTTP, découverte de contenu (100+ chemins), analyse de secrets JavaScript, CVE de la chaîne d'approvisionnement, empoisonnement du cache, CORS, sondes de contrebande HTTP |
| 18–30 | Renseignement | Sécurité e-mail (SPF/DMARC/DKIM), Wayback Machine, IP inverse, empreinte JARM C2, détection d'anomalies, notation CVSS 3.1, synthèse de chemins d'attaque, mappage de conformité (OWASP/GDPR/ISO 27001/NIST/PCI-DSS), corrélation CVE, analyses de graphe, diff d'analyse |
| 31–35 | Tests actifs | Contrebande de requêtes HTTP (CL.TE/TE.CL/TE.TE), corrélation inter-organisations, prédiction de sous-domaines par GNN, analyse d'authentification (formulaires/JWT/Basic Auth), fuzzing de paramètres (SQLi/XSS/SSRF/IDOR/traversal) |
| 36–39 | Avancé | Corrélation chemin BGP/AS + fournisseur cloud, pivotement par chaînes SSRF (métadonnées cloud, services internes, Gopher), fuzzing de protocoles OAuth/GraphQL/WebSocket, détection de honeypots |
| 40–43 | Renseignement+ | Empreinte CVE approfondie (22 technologies), énumération API/OpenAPI/Swagger, énumération de stockage cloud (S3/Azure/GCS/DO), renseignement sur les menaces (listes noires DNS, nœuds de sortie Tor, réputation ASN) |
Prérequis : Python 3.9+, Linux/macOS/Termux
git clone https://github.com/DozerMx/Argus
cd Argus
pip install -r requirements.txt
Interface web (optionnel) :
pip install fastapi uvicorn websockets
python argus.py -d TARGET [OPTIONS]
# CT log collection + DNS resolution + anomaly detection
python argus.py -d target.com
# Full 43-phase scan
python argus.py -d target.com --full
# Full scan with executive report
python argus.py -d target.com --full --output executive
# Full scan with authentication and fuzzing
python argus.py -d target.com --full --fuzz --auth
# Scan with known credentials
python argus.py -d target.com --full --auth --user admin --password admin123
# Subdomain brute force + AXFR
python argus.py -d target.com --brute --axfr
# Deep infrastructure: ASN + CDN bypass + ports
python argus.py -d target.com --deep --cdn-bypass --ports
# Stealth scan (paranoid jitter profile)
python argus.py -d target.com --full --stealth-profile paranoid
# Through Tor
python argus.py -d target.com --full --proxy socks5://127.0.0.1:9050
# Bulk scan from file
python argus.py -f targets.txt --full --output json
# Continuous monitoring with Slack alerts
python argus.py -d target.com --daemon --webhook https://hooks.slack.com/...
# Web UI dashboard
python argus.py --serve --ui-port 8080
Target:
-d DOMAIN Single target domain
-f FILE File with one domain per line
Scan Modules:
--full Enable all modules
--deep ASN, cloud detection, Wayback, reverse IP
--brute Subdomain brute force + permutations
--axfr DNS zone transfer
--cdn-bypass CDN/WAF origin IP discovery
--ports TCP port scan + banner grab (178 ports)
--jarm JARM TLS fingerprinting
--fuzz Parameter fuzzing (SQLi, XSS, SSRF, IDOR, traversal)
--auth Authentication analysis
--user USER Username for authenticated scanning
--password PASS Password for authenticated scanning
Output:
--output FORMAT terminal | html | executive | json | csv
--outfile PATH Output file path
-v Verbose logging
-q Quiet mode
Performance:
--threads N Concurrent threads (default: 30)
--timeout N Request timeout in seconds (default: 10)
--proxy URL Proxy (socks5://host:port or http://host:port)
--no-cache Disable disk cache
--stealth-profile paranoid | careful | normal | aggressive
Web UI:
--serve Launch real-time web dashboard
--ui-port N Web UI port (default: 8080)
Daemon:
--daemon Continuous monitoring mode
--webhook URL Webhook URL for alerts (Slack/Telegram)
--interval N Scan interval in hours (default: 6)