
Scanner di ricognizione e superficie d'attacco multi-fase che mappa domini, IP, ASN, asset cloud e CVE in un grafo di conoscenza con punteggi CVSS e mappatura di conformità.

Framework di intelligence per la sicurezza
Argus è un framework multi-fase di ricognizione e analisi della sicurezza, progettato per penetration test professionali e valutazione della superficie d'attacco. È completamente autonomo — nessuna chiave API richiesta, nessun servizio esterno, nessun account. Un singolo comando produce un quadro completo dell'esposizione esterna di un'organizzazione.
argus/
├── sources/ Certificate Transparency, passive DNS, brute force
├── correlators/ DNS resolution, CDN bypass, port scanning
├── intelligence/ 43 analysis modules
│ ├── Core TLS, HTTP, email, content discovery, JS secrets
│ ├── Graph Attack paths, compliance, CVE, anomaly detection
│ ├── Advanced SSRF chains, OAuth/GraphQL/WebSocket, BGP, stealth
│ └── Intelligence Deep CVE, API enumeration, cloud storage, threat intel
├── ontology/ Knowledge graph (NetworkX), entity model, pivot engine
├── output/ HTML report, executive report, CSV, JSON, terminal
└── web/ FastAPI real-time dashboard with WebSocket
Il motore costruisce un Knowledge Graph di tutte le entità scoperte — domini, IP, certificati, organizzazioni, tecnologie, porte aperte — e delle relazioni tra di esse. Ogni riscontro è un'anomalia associata a un nodo del grafo con un punteggio CVSS 3.1, collegamento ai percorsi di attacco e mappatura della conformità.
| Intervallo | Categoria | Copertura |
|---|---|---|
| 1–9 | Ricognizione | Collezione log CT, DNS passivo, AXFR, brute force sui sottodomini (oltre 2.500 parole + permutazioni), risoluzione DNS, IPv6, intelligence ASN, bypass dell'origine CDN |
| 10–17 | Analisi della superficie | Fingerprinting TLS, analisi degli header HTTP, content discovery (oltre 100 percorsi), scansione dei segreti JavaScript, CVE della supply chain, cache poisoning, CORS, sonde di HTTP smuggling |
| 18–30 | Intelligence | Sicurezza email (SPF/DMARC/DKIM), Wayback Machine, reverse IP, fingerprinting JARM C2, rilevamento anomalie, punteggio CVSS 3.1, sintesi dei percorsi di attacco, mappatura della conformità (OWASP/GDPR/ISO 27001/NIST/PCI-DSS), correlazione CVE, analisi dei grafi, diff delle scansioni |
| 31–35 | Test attivi | HTTP request smuggling (CL.TE/TE.CL/TE.TE), correlazione tra organizzazioni, predizione dei sottodomini con GNN, analisi dell'autenticazione (form/JWT/Basic Auth), fuzzing dei parametri (SQLi/XSS/SSRF/IDOR/traversal) |
| 36–39 | Avanzate | Percorso BGP/AS + correlazione con i provider cloud, pivoting delle catene SSRF (metadata cloud, servizi interni, Gopher), fuzzing dei protocolli OAuth/GraphQL/WebSocket, rilevamento honeypot |
| 40–43 | Intelligence+ | Fingerprinting CVE avanzato (22 tecnologie), enumerazione API/OpenAPI/Swagger, enumerazione dello storage cloud (S3/Azure/GCS/DO), threat intelligence (blacklist DNS, nodi di uscita Tor, reputazione ASN) |
Requisiti: Python 3.9+, Linux/macOS/Termux
git clone https://github.com/DozerMx/Argus
cd Argus
pip install -r requirements.txt
Web UI (opzionale):
pip install fastapi uvicorn websockets
python argus.py -d TARGET [OPTIONS]
# CT log collection + DNS resolution + anomaly detection
python argus.py -d target.com
# Full 43-phase scan
python argus.py -d target.com --full
# Full scan with executive report
python argus.py -d target.com --full --output executive
# Full scan with authentication and fuzzing
python argus.py -d target.com --full --fuzz --auth
# Scan with known credentials
python argus.py -d target.com --full --auth --user admin --password admin123
# Subdomain brute force + AXFR
python argus.py -d target.com --brute --axfr
# Deep infrastructure: ASN + CDN bypass + ports
python argus.py -d target.com --deep --cdn-bypass --ports
# Stealth scan (paranoid jitter profile)
python argus.py -d target.com --full --stealth-profile paranoid
# Through Tor
python argus.py -d target.com --full --proxy socks5://127.0.0.1:9050
# Bulk scan from file
python argus.py -f targets.txt --full --output json
# Continuous monitoring with Slack alerts
python argus.py -d target.com --daemon --webhook https://hooks.slack.com/...
# Web UI dashboard
python argus.py --serve --ui-port 8080
Target:
-d DOMAIN Single target domain
-f FILE File with one domain per line
Scan Modules:
--full Enable all modules
--deep ASN, cloud detection, Wayback, reverse IP
--brute Subdomain brute force + permutations
--axfr DNS zone transfer
--cdn-bypass CDN/WAF origin IP discovery
--ports TCP port scan + banner grab (178 ports)
--jarm JARM TLS fingerprinting
--fuzz Parameter fuzzing (SQLi, XSS, SSRF, IDOR, traversal)
--auth Authentication analysis
--user USER Username for authenticated scanning
--password PASS Password for authenticated scanning
Output:
--output FORMAT terminal | html | executive | json | csv
--outfile PATH Output file path
-v Verbose logging
-q Quiet mode
Performance:
--threads N Concurrent threads (default: 30)
--timeout N Request timeout in seconds (default: 10)
--proxy URL Proxy (socks5://host:port or http://host:port)
--no-cache Disable disk cache
--stealth-profile paranoid | careful | normal | aggressive
Web UI:
--serve Launch real-time web dashboard
--ui-port N Web UI port (default: 8080)
Daemon:
--daemon Continuous monitoring mode
--webhook URL Webhook URL for alerts (Slack/Telegram)
--interval N Scan interval in hours (default: 6)