Retour au classement

Autumn-27/ScopeSentry

Goscope-sentry.top

ScopeSentry-Cyberspace mapping, subdomain enumeration, port scanning, sensitive information discovery, vulnerability scanning, distributed nodes

bugbountybugbounty-toolcrawlerdirscannerpagemonitorsubdomain-enumerationsubdomain-takeoversurlscanvulnerability-scannersbug-bountyinfosecosint
Croissance des étoiles
Étoiles
1.5k
Forks
214
Croissance hebdomadaire
Issues
82
5001k1.5k
mai 2024janv. 2025oct. 2025juil. 2026
ArtefactsGo Modulesgo get github.com/Autumn-27/ScopeSentry
README

English | 中文

Ask DeepWiki

Introduction

Scope Sentry is a tool with functions such as asset mapping, subdomain enumeration, information leakage detection, vulnerability scanning, directory scanning, subdomain takeover, crawler, and page monitoring. By building multiple nodes, users can freely choose nodes to run scanning tasks. When new vulnerabilities emerge, it can quickly check whether the concerned assets have related components.

Distributed Implementation Reference Articles: https://mp.weixin.qq.com/s/xfgRxUjljoQ8KzacblktxA

Server Recommendation: lightnode

Discord:

https://discord.gg/GWVwSBBm48

Language

Server:python - FastApi

Scan:go

Front-end:vue - vue-element-plus-admin

Website

Install

git clone https://github.com/Autumn-27/ScopeSentry.git
cd ScopeSentry
# Change the MongoDB and Redis account passwords in the. env file.
docker-compose -f single-host-deployment.yml up -d

After running, there will be four containers: mongodb, redis, scope-sentry (server), and scopesentry-scan (scan). By default, there will be one scanning node.

View the initial user password and the secondary verification password of the plug-in

docker logs scope-sentry

Add new nodes(Optional)

git clone https://github.com/Autumn-27/ScopeSentry-Scan.git
cd ScopeSentry-Scan/build
# Edit the connection information for MongoDB and Redis in the .env file. NodeName is the node name, and each node name should be unique (if it is empty, it will be randomly generated, and you can change the name in the web interface).
docker-compose -f scan-docker-compose.yml up -d

Plugin Flowchart

Current Features

  • Plugin System (Add any tool through extension)
  • Subdomain Enumeration
  • Subdomain Takeover Detection
  • Port Scanning
  • Asset Identification
  • Directory Scanning
  • Vulnerability Scanning
  • Sensitive Information Leakage Detection
  • URL Extraction
  • Crawler
  • Page Monitoring
  • Custom WEB Fingerprint
  • POC Import
  • Asset Grouping
  • Multi-Node Scanning
  • Webhook

To Do

  • Weak Password Cracking

Installation

For installation instructions, see the official website

Communication

Discord:

https://discord.gg/agsYdAyN

Screenshots

Login

alt text

Homepage Dashboard

alt text

Plugin System

alt text alt text

Asset Data

Assets

alt text alt text alt text

alt text

Root Domain

alt text

Subdomains

alt text

Subdomain Takeover

alt text

APP

alt text

小程序

alt text

URL

alt text

Crawler

alt text

Sensitive Information

alt text

Directory Scanning

alt text

Vulnerabilities

alt text

Page Monitoring

alt text alt text

Projects

Project asset aggregation

Panel - Overview

Subdomains

Port

Service

Tasks

Task Progress

Nodes

#License

All branches of this project follow AGPL-3.0, and additional terms need to be followed:

  1. The commercial use of this software requires a separate commercial license.
  2. Companies, organizations, and for-profit entities must obtain a commercial license before using, distributing, or modifying this software. Individuals and non-profit organizations are free to use this software in accordance with the terms of AGPL-3.0.
  3. If you have any commercial license inquiries, please contact rainy-autumn@outlook.com .
Dépôts similaires
swisskyrepo/PayloadsAllTheThings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

PythonPyPIMIT Licensepentestpayload
swisskyrepo.github.io/PayloadsAllTheThings/
79.3k17.2k
maurosoria/dirsearch

Web path scanner

PythonPyPIfuzzerfuzzing
14.5k2.4k
projectdiscovery/subfinder

Fast passive subdomain enumeration tool.

GoGo ModulesMIT Licensesubdomain-enumerationosint
projectdiscovery.io
14k1.6k
projectdiscovery/nuclei-templates

Community curated list of templates for the nuclei engine to find security vulnerabilities.

JavaScriptnpmMIT Licensenuclei-templatesnuclei
github.com/projectdiscovery/nuclei
12.7k3.6k
nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters

A list of resources for those interested in getting started in bug bounties

bug-bounty-huntershackers
12.1k2.1k
dstotijn/hetty

An HTTP toolkit for security research.

GoGo ModulesMIT Licensemitmproxy
hetty.xyz
11.9k770
edoardottt/awesome-hacker-search-engines

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

ShellMIT Licenseawesomeawesome-list
awesome-hacker-search-engines.com
10.9k1k
blacklanternsecurity/bbot

The recursive internet scanner for hackers. 🧡

PythonPyPIGNU Affero General Public License v3.0hackingneo4j
blacklanternsecurity.com/bbot/
10.2k889
projectdiscovery/httpx

httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.

GoGo ModulesMIT Licensehttpbugbounty
docs.projectdiscovery.io/tools/httpx
10.2k1.1k
shmilylty/OneForAll

OneForAll是一款功能强大的子域收集工具

PythonPyPIGNU General Public License v3.0subdomainsubdomain-scanner
9.9k1.4k
OWASP/wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Creative Commons Attribution Share Alike 4.0 Internationalbest-practicesguide
owasp.org/www-project-web-security-testing-guide/
9.6k1.6k
yogeshojha/rengine

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.

HTMLGNU General Public License v3.0security-toolsosint
yogeshojha.github.io/rengine/
8.7k1.3k