
자동화된 버그 바운티 및 정찰 프레임워크 — Subfinder, Naabu, Httpx, Nuclei, Nmap, CVEMap, Gowitness, Katana 등을 통합 웹 UI로 감싸는 도구
오픈소스 AI 기반 공격적 보안 플랫폼으로, 잘 알려진 보안 도구들을 통합 웹 UI 뒤에 래핑하며 분산 스캔, AI 생성 보고서, 스마트 스캔 플래너, 대화형 공격 그래프, 커뮤니티 플러그인 SDK를 제공합니다.
Google Play에서 ObsidianBox Modern도 확인해보세요.
| 섹션 | 설명 |
|---|---|
| Why | 동기와 철학 |
| Wrapped Tools | XPFarm이 조율하는 10개의 오픈소스 도구 |
| Architecture Map | 전체 시스템 아키텍처, 스캔 파이프라인, 데이터 흐름 |
| Overlord — AI Analysis | 바이너리/악성코드/웹 분석용 AI 에이전트 |
| Bug Bounty Reports | AI 생성 전문 공개 보고서 |
| AI Scan Planner | AI 최적화 정찰 및 익스플로잇 단계 플래너 |
| Distributed Workers | 여러 머신에서 병렬로 스캔 실행 |
| Scan Graph | 자산, 서비스, 취약점, 익스플로잇의 대화형 그래프 |
| Plugin SDK | 커뮤니티 확장 가능한 도구, 에이전트 및 파이프라인 시스템 |
| Finding Normalization Engine | 통합, 강화, 중복 제거된 보안 결과 |
| What's New | 최근 보안, 안정성 및 UX 개선 사항 |
| Setup | 빌드 및 배포 지침 |
| TODO | 계획된 기능 및 로드맵 |

Assetnote 같은 도구는 훌륭합니다 — 유지 보수가 잘 되어 있고, 최신 상태이며, 취약점 식별에 대해 투명합니다. 하지만 오픈소스가 아닙니다. 또한 이미 충분히 견고한 오픈소스 도구들이 존재하므로 바퀴를 재발명할 필요도 없습니다. XPFarm은 이들을 함께 래핑하여 덜 기업적이고 오픈소스인 취약점 스캐너를 제공합니다.
초점은 백그라운드에서 무엇이 실패하거나 제거되는지 확인할 수 있는 취약점 스캐너를 구축하는 데 있었으며, 미스터리에 대해 궁금해할 필요가 없도록 했습니다. 스캔 파이프라인이 수행하는 모든 것이 사용자에게 표시됩니다.

![]() Asjidkalam |
![]() jamoski3112 연구 |
flowchart TB
subgraph ENTRY["Entrypoint — main.go"]
M1["Parse Flags (-debug)"]
M2["InitDB — SQLite + WAL + GORM"]
M3["InitModules — 10 tool wrappers"]
M4["Load Plugins — normalization/all + plugins/all"]
M5["Health Check — auto-install missing tools"]
M6["CheckAndIndexTemplates — Nuclei versioning"]
M7["StartServer — Gin on :8888"]
M1 --> M2 --> M3 --> M4 --> M5 --> M6 --> M7
end
subgraph UI_LAYER["Web UI — internal/ui/server.go"]
direction TB
GIN["Gin HTTP Server\nEmbedded templates + static\nCSRF origin-check middleware"]
subgraph Pages["HTML Pages"]
P1["Dashboard — SSE live stage progress"]
P2["Assets & Targets"]
P3["Global Search — paginated + truncation"]
P4["Scan Graph — Cytoscape.js"]
P5["Bug Bounty Reports"]
P6["AI Scan Planner"]
P7["Workers & Jobs"]
P8["Overlord Chat + Binary Upload"]
P9["Modules"]
P10["Settings — AES-256-GCM encrypted"]
end
GIN --> Pages
end
subgraph SCAN_ENGINE["Scan Engine — internal/core/"]
direction TB
SM["ScanManager\nSingleton, mutex-guarded\nPanic recovery + SSE broadcast"]
subgraph PIPELINE["8-Stage Scanning Pipeline"]
direction TB
S1["1. Subfinder — Subdomain Discovery"]
S2["2. Filter & Save — Cloudflare / Localhost / Alive"]
S3["3. Naabu — Port Scanning (5-worker pool)"]
S4["4. Nmap — Service + Version Detection"]
S5["5. Httpx — HTTP Probing + Metadata"]
S6["6. Parallel Web — Screenshots, Crawl, URLs, Tech"]
S7["7. CVEMap — CVE lookup by product/tech"]
S8["8. Nuclei — Vulnerability Scanning"]
S1 --> S2 --> S3 --> S4 --> S5 --> S6 --> S7 --> S8
end
SM --> PIPELINE
end
subgraph REPORTS["Bug Bounty Reports — internal/reports/"]
RG["GenerateReport()\nCollects DB context + graph\nOverlord AI generation\nFallback built-in templates"]
RF["Formats: Markdown · PDF · HackerOne · Bugcrowd"]
RS["Storage: internal/storage/reports/"]
RG --> RF --> RS
end
subgraph PLANNER["AI Scan Planner — internal/planner/"]
PL["GenerateScanPlan()\nGathers asset/finding/graph context\nPolls Overlord for JSON plan\nFallback heuristic plan"]
PC["Capability Registry — 26 capabilities\n10 built-in modules + 16 Overlord agents\nRisk levels: safe / active / destructive"]
PS["ExecutePlanWithLogs()\nSSE log streaming per step\nRoutes builtin vs Overlord agent steps"]
PL --> PC --> PS
end
subgraph DISTRIBUTED["Distributed Workers — internal/distributed/"]
DW["Worker Binary — cmd/worker/main.go\n./xpfarm-worker -controller http://host:8888"]
DC["Controller — token auth, heartbeat monitor\nAtomically claims jobs from queue"]
DS["Scheduler — BestWorkerForTool()\nRoutes by capability + active job count"]
DJ["Job Queue — internal/storage/jobs/\nClaim via DB transaction, 30min timeout"]
DW --> DC --> DS --> DJ
end
subgraph OVERLORD["Overlord — AI Agent Subsystem"]
OV_PROXY["Overlord Proxy — internal/overlord/"]
subgraph OV_AGENTS["22 Specialized Agents"]
OA1["Binary RE — re-explorer, re-debugger, re-decompiler, re-scanner"]
OA2["APK — apk-recon, apk-dynamic, apk-decompiler"]
OA3["Web + Exploit — web-tester, re-exploiter, secrets-hunter, recon"]
end
subgraph OV_TOOLS["70+ TypeScript Tools"]
OT1["radare2, ghidra, binwalk, frida, angr, strings"]
OT2["semgrep, gitleaks, gau, corscanner, whatweb"]
OT3["git_dumper, js_scraper, crypto_solver, ropper"]
end
subgraph PROVIDERS["21 AI Providers"]
PR1["Anthropic · OpenAI · Groq · DeepSeek"]
PR2["Ollama (local) · xAI · OpenRouter · Cerebras"]
end
OV_PROXY --> OV_AGENTS
OV_PROXY --> OV_TOOLS
OV_PROXY --> PROVIDERS
end
subgraph SCAN_GRAPH["Scan Graph — internal/graph/"]
GB["BuildGraph() — queries 5 tables\nDeduplicates nodes + edges"]
subgraph GNODES["Node Types"]
GN1["asset #8b5cf6"]
GN2["target #0ea5e9"]
GN3["service #10b981"]
GN4["tech #f59e0b"]
GN5["vuln #ef4444"]
GN6["exploit #dc2626"]
end
GB --> GNODES
end