
Scanner de reconhecimento e superfície de ataque em múltiplas fases que mapeia domínios, IPs, ASNs, ativos de nuvem e CVEs em um grafo de conhecimento com pontuação CVSS e mapeamento de conformidade.

Framework de Inteligência de Segurança
O Argus é um framework de reconhecimento e análise de segurança em múltiplas fases, construído para testes de penetração profissionais e avaliação de superfície de ataque. Ele opera de forma totalmente autônoma — sem necessidade de chaves de API, sem serviços externos, sem contas. Um único comando produz um panorama completo da exposição externa de uma organização.
argus/
├── sources/ Certificate Transparency, passive DNS, brute force
├── correlators/ DNS resolution, CDN bypass, port scanning
├── intelligence/ 43 analysis modules
│ ├── Core TLS, HTTP, email, content discovery, JS secrets
│ ├── Graph Attack paths, compliance, CVE, anomaly detection
│ ├── Advanced SSRF chains, OAuth/GraphQL/WebSocket, BGP, stealth
│ └── Intelligence Deep CVE, API enumeration, cloud storage, threat intel
├── ontology/ Knowledge graph (NetworkX), entity model, pivot engine
├── output/ HTML report, executive report, CSV, JSON, terminal
└── web/ FastAPI real-time dashboard with WebSocket
O mecanismo constrói um Grafo de Conhecimento de todas as entidades descobertas — domínios, IPs, certificados, organizações, tecnologias, portas abertas — e as relações entre elas. Cada achado é uma anomalia associada a um nó do grafo, com pontuação CVSS 3.1, vínculo com caminhos de ataque e mapeamento de conformidade.
| Intervalo | Categoria | Cobertura |
|---|---|---|
| 1–9 | Reconhecimento | Coleta de logs de CT, DNS passivo, AXFR, brute force de subdomínios (mais de 2.500 palavras + permutações), resolução de DNS, IPv6, inteligência de ASN, bypass de origem de CDN |
| 10–17 | Análise de Superfície | Fingerprinting de TLS, análise de cabeçalhos HTTP, descoberta de conteúdo (mais de 100 caminhos), varredura de segredos em JavaScript, CVEs de supply chain, cache poisoning, CORS, sondas de contrabando de HTTP |
| 18–30 | Inteligência | Segurança de e-mail (SPF/DMARC/DKIM), Wayback Machine, IP reverso, fingerprinting JARM de C2, detecção de anomalias, pontuação CVSS 3.1, síntese de caminhos de ataque, mapeamento de conformidade (OWASP/GDPR/ISO 27001/NIST/PCI-DSS), correlação de CVEs, análise de grafos, diff de varredura |
| 31–35 | Testes Ativos | Contrabando de requisições HTTP (CL.TE/TE.CL/TE.TE), correlação entre organizações, predição de subdomínios com GNN, análise de autenticação (formulários/JWT/Basic Auth), fuzzing de parâmetros (SQLi/XSS/SSRF/IDOR/traversal) |
| 36–39 | Avançado | Correlação de caminho AS/BGP + provedor de nuvem, pivô com cadeias de SSRF (metadados de nuvem, serviços internos, Gopher), fuzzing de protocolos OAuth/GraphQL/WebSocket, detecção de honeypot |
| 40–43 | Inteligência+ | Fingerprinting profundo de CVE (22 tecnologias), enumeração de API/OpenAPI/Swagger, enumeração de armazenamento em nuvem (S3/Azure/GCS/DO), inteligência de ameaças (listas negras de DNS, nós de saída Tor, reputação de ASN) |
Requisitos: Python 3.9+, Linux/macOS/Termux
git clone https://github.com/DozerMx/Argus
cd Argus
pip install -r requirements.txt
Interface Web (opcional):
pip install fastapi uvicorn websockets
python argus.py -d TARGET [OPTIONS]
# CT log collection + DNS resolution + anomaly detection
python argus.py -d target.com
# Full 43-phase scan
python argus.py -d target.com --full
# Full scan with executive report
python argus.py -d target.com --full --output executive
# Full scan with authentication and fuzzing
python argus.py -d target.com --full --fuzz --auth
# Scan with known credentials
python argus.py -d target.com --full --auth --user admin --password admin123
# Subdomain brute force + AXFR
python argus.py -d target.com --brute --axfr
# Deep infrastructure: ASN + CDN bypass + ports
python argus.py -d target.com --deep --cdn-bypass --ports
# Stealth scan (paranoid jitter profile)
python argus.py -d target.com --full --stealth-profile paranoid
# Through Tor
python argus.py -d target.com --full --proxy socks5://127.0.0.1:9050
# Bulk scan from file
python argus.py -f targets.txt --full --output json
# Continuous monitoring with Slack alerts
python argus.py -d target.com --daemon --webhook https://hooks.slack.com/...
# Web UI dashboard
python argus.py --serve --ui-port 8080
Target:
-d DOMAIN Single target domain
-f FILE File with one domain per line
Scan Modules:
--full Enable all modules
--deep ASN, cloud detection, Wayback, reverse IP
--brute Subdomain brute force + permutations
--axfr DNS zone transfer
--cdn-bypass CDN/WAF origin IP discovery
--ports TCP port scan + banner grab (178 ports)
--jarm JARM TLS fingerprinting
--fuzz Parameter fuzzing (SQLi, XSS, SSRF, IDOR, traversal)
--auth Authentication analysis
--user USER Username for authenticated scanning
--password PASS Password for authenticated scanning
Output:
--output FORMAT terminal | html | executive | json | csv
--outfile PATH Output file path
-v Verbose logging
-q Quiet mode
Performance:
--threads N Concurrent threads (default: 30)
--timeout N Request timeout in seconds (default: 10)
--proxy URL Proxy (socks5://host:port or http://host:port)
--no-cache Disable disk cache
--stealth-profile paranoid | careful | normal | aggressive
Web UI:
--serve Launch real-time web dashboard
--ui-port N Web UI port (default: 8080)
Daemon:
--daemon Continuous monitoring mode
--webhook URL Webhook URL for alerts (Slack/Telegram)
--interval N Scan interval in hours (default: 6)