Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
scanner-cli — 项目安全/漏洞/风险扫描工具 | Kitploit
工具/GitHubGitHub/hawkeyesec/scanner-cli
静态分析漏洞扫描器容器安全代码分析DevSecOps秘密检测Archived
GitHubhawkeyesec/scanner-cli

scanner-cli

项目安全/漏洞/风险扫描工具

查看仓库
36186205年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

弃用通知:Hawkeye 已到达生命周期终点。

目前已有更多现代化方案可供您和您的项目使用。如果您希望接手该项目的维护工作,请随时与我联系。您可以在我的个人主页上找到我的联系方式。

.

.

.

.

.

.

Hawkeye scanner-cli 是一个项目安全、漏洞及通用风险突出工具。它旨在集成到您的预提交钩子和流水线中。

运行和配置扫描器

Hawkeye scanner-cli 假定您的目录结构将工具链的文件放在顶层。大致而言,它遵循以下原则:

  • Node.js 项目在顶层有 package.json
  • Ruby 项目在顶层有 Gemfile
  • Python 项目在顶层有 requirements.txt
  • PHP 项目在顶层有 composer.lock
  • Java 项目包含 build(gradle)或 target(maven)文件夹,并包含 .java 和 .jar 文件
  • Kotlin 项目包含 build(gradle)或 target(maven)文件夹,并包含 .kt 和 .jar 文件
  • Scala 项目包含 target(使用 sbt-native-packager 或 sbt-assembly 插件的 sbt)文件夹,并包含 .scala 和 .jar 文件。请查看此仓库获取运行演示。
  • Rust 项目在顶层有 Cargo.toml

这并非详尽无遗,有时工具需要额外的文件才能存在。要了解模块如何决定是否能处理项目,请查看工作原理部分和 modules 文件夹。

Docker(推荐)

Docker 镜像毫无疑问是使用扫描器最简单的方式。请注意,您的项目根目录(例如 $PWD)需要挂载到 /target。

docker run --rm -v $PWD:/target hawkeyesec/scanner-cli:latest

如果您使用扫描器生成 JSON(通过 -j 和 --json CLI 标志以及 .hawkeyerc 中的 json 设置),请确保通过 docker run -u $(id -u):$(id -g) 使用正确的 UID 和 GID。否则可能会导致无法删除的文件,例如在 Jenkins 中运行时。

Docker 构建也是在 CI 流水线中运行扫描器的推荐方式。以下是在 GoCD 中对一个项目运行 Hawkeye 的示例:

<pipeline name="security-scan">
  <stage name="Hawkeye" cleanWorkingDir="true">
    <jobs>
      <job name="scan">
        <tasks>
          <exec command="docker">
            <arg>pull</arg>
            <arg>hawkeyesec/scanner-cli</arg>
            <runif status="passed" />
          </exec>
          <exec command="bash">
            <arg>-c</arg>
            <arg>docker run --rm -v $PWD:/target hawkeyesec/scanner-cli:latest</arg>
            <runif status="passed" />
          </exec>
        </tasks>
      </job>
    </jobs>
  </stage>
</pipeline>

npm

您可以在 Node.js 项目中安装并运行 hawkeye:

npm install --save-dev @hawkeyesec/scanner-cli
npx hawkeye scan

此方法推荐用于不需要其他工具链(例如 python、ruby)的 Node.js 项目。

使用此方法时,还建议在 git 预提交钩子中调用扫描器(例如通过 pre-commit 包),以便在发现问题时阻止提交。

配置文件(推荐)

您可以通过项目根目录下的 .hawkeyerc 和 .hawkeyeignore 文件配置扫描器。

.hawkeyerc 文件是一个 JSON 文件,允许您配置……

  • 要运行的模块,
  • 要使用的输出器,
  • 以及失败阈值
{
    "all": true|false,
    "staged": true|false,
    "modules": ["files-ccnumber", "java-owasp", "java-find-secbugs"],
    "sumo": "http://your.sumologic.foobar/collector",
    "http": "http://your.logger.foobar/collector",
    "json": "log/results.json",
    "failOn": "low"|"medium"|"high"|"critical",
    "showCode": true|false
}

.hawkeyeignore 文件是一个正则表达式集合,用于匹配要从扫描中排除的路径和模块错误码,相当于使用 --exclude 标志。以 # 开头的行被视为注释。

请注意,正则表达式中保留的特殊字符(-[]{}()*+?.,^$|#\s)在用作字面量时需要转义!

另请注意,模块错误码通常不显示,因为它们对用户而言并非主要相关。如果您想排除某个误报,可以使用 --show-code 标志或 .hawkeyerc 中的 showCode 属性来显示模块错误码。

^test/

# this is a comment

^README.md

CLI

使用 hawkeye modules 列出可用的模块及其状态。

> npx hawkeye modules
[info] Version: v1.4.0
[info] Module Status
[info] Enabled:   files-ccnumber
[info]            Scans for suspicious file contents that are likely to contain credit card numbers
[info] Enabled:   files-contents
[info]            Scans for suspicious file contents that are likely to contain secrets
[info] Disabled:  files-entropy
[info]            Scans files for strings with high entropy that are likely to contain passwords
[info] Enabled:   files-secrets
[info]            Scans for suspicious filenames that are likely to contain secrets
[info] Enabled:   java-find-secbugs
[info]            Finds common security issues in Java code with findsecbugs
[info] Enabled:   java-owasp
[info]            Scans Java projects for gradle/maven dependencies with known vulnerabilities with the OWASP dependency checker
[info] Enabled:   node-npmaudit
[info]            Checks node projects for dependencies with known vulnerabilities
[info] Enabled:   node-npmoutdated
[info]            Checks node projects for outdated npm modules
[info] Enabled:   node-yarnaudit
[info]            Checks yarn projects for dependencies with known vulnerabilities
[info] Enabled:   node-yarnoutdated
[info]            Checks node projects for outdated yarn modules
[info] Enabled:   php-security-checker
[info]            Checks whether the composer.lock contains dependencies with known vulnerabilities using security-checker
[info] Enabled:   python-bandit
[info]            Scans for common security issues in Python code with bandit.
[info] Enabled:   python-piprot
[info]            Scans python dependencies for out of date packages
[info] Enabled:   python-safety
[info]            Checks python dependencies for known security vulnerabilities with the safety tool.
[info] Enabled:   ruby-brakeman
[info]            Statically analyzes Rails code for security issues with Brakeman.
[info] Enabled:   ruby-bundler-scan
[info]            Scan for Ruby gems with known vulnerabilities using bundler

使用 hawkeye scan 启动扫描:

> npx hawkeye scan --help
[info] Version: v1.3.0
Usage: hawkeye-scan [options]

Options:
  -a, --all                                       Scan all files, regardless if a git repo is found. Defaults to tracked files in git repositories.
  -t, --target [/path/to/project]                 The location to scan. Defaults to $PWD.
  -f, --fail-on [low|medium|high|critical]        Set the level at which hawkeye returns non-zero status codes. Defaults to low.
  -m, --module [module name]                      Run specific module. Defaults to all applicable modules.
  -e, --exclude [pattern]                         Specify one or more exclusion patterns (eg. test/*). Can be specified multiple times.
  -j, --json [/path/to/file.json]                 Write findings to file.
  -s, --sumo [https://sumologic-http-connector]   Write findings to SumoLogic.
  -H, --http [https://your-site.com/api/results]  Write findings to a given url.
  --show-code                                     Shows the code the module uses for reporting, useful for ignoring certain false positives
  -g, --staged                                    Scan only git-staged files.
  -h, --help                                      output usage information

结果

退出码

scanner-cli 响应以下退出码:

  • 退出码 0:未发现达到或超过最低阈值的发现。
  • 退出码 1:发现达到或超过最低阈值的问题。
  • 退出码 42:程序某处发生意外错误。这可能是 bug,不应发生。请检查日志输出并报告 bug。

重定向控制台输出

如果您希望重定向控制台日志输出,推荐的方法是挂接到 stdout。在此示例中,我们同时使用了 JSON 和 stdout 输出:

docker run --rm -v $PWD:/target hawkeyesec/scanner-cli:latest -j hawkeye-results.json -f critical 2>&1 | tee hawkeye-results.txt

控制台输出

默认情况下,扫描器以表格形式将结果输出到控制台。

Sumologic

结果可以发送到您选择的 SumoLogic 收集器。在此示例中,我们有一个带有单个 HTTP 源的收集器。

hawkeye scan --sumo https://collectors.us2.sumologic.com/receiver/v1/http/your-http-collector-url

在 SumoLogic 中,搜索 _collector="hawkeye" | json auto:

SumoLogic

任意 HTTP 端点

与 SumoLogic 示例类似,扫描器可以将结果发送到任何接受 POST 消息的 HTTP 端点。

hawkeye scan --http http://your.logging.foobar/endpoint

结果将使用 User-Agent: hawkeye 发送。与控制台输出类似,每个发现将 POST 以下 JSON:

{
  "module": "files-contents",
  "level": "critical",
  "offender": "testfile3.yml",
  "description": "Private key in file",
  "mitigation": "Check line number: 3"
}

工作原理

Hawkeye 被设计为可通过添加模块和输出器进行扩展。

  • 在 modules 文件夹中添加模块。
  • 在 writers 文件夹中添加输出器。

模块

模块本质上是实现自身逻辑或封装第三方工具并标准化输出的小段代码。它们仅在满足所需条件时运行。例如:npm outdated 模块仅当在扫描目标中检测到 package.json 时才会运行——因此,您无需告诉 Hawkeye 您正在扫描什么类型的项目。

通用模块

下载工具