xssmap
oxo
| xssmap | oxo | |
|---|---|---|
| 1 | 3 | |
| 151 | 574 | |
| 0.0% | 1.9% | |
| 10.0 | 9.4 | |
| over 3 years ago | 11 days ago | |
| Python | Python | |
| Apache License 2.0 | Apache License 2.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
xssmap
-
Docker explained for pentesters
Let's take a look at an example. We assume that we want to create an environment to automate several tools, including xira. The contents of the directory holding our scripts:
oxo
-
Open-Source Detector of CISA's Known Exploitable Vulnerabilities
That repo also has no license information that I can tell, although the pip install is Apache 2 <https://github.com/Ostorlab/ostorlab#readme>
- Open-Source Distributed Security Scanning Platform
-
Is this tool worth it ?
A few days ago, they announced they went open-source, I gave it a try and it looks cool. I run a network scan with multiple tools at the same time(nmap,tsunami,nuclei) and got back a full report with just a few commands.
What are some alternatives?
dheater - D(HE)ater is a proof of concept implementation of the D(HE)at attack (CVE-2002-20001) through which denial-of-service can be performed by enforcing the Diffie-Hellman key exchange. (read-only clone of the original GitLab project)
KEV - Ostorlab KEV: One-command to detect most remotely known exploitable vulnerabilities. Sourced from CISA KEV, Google's Tsunami, Ostorlab's Asteroid and Bug Bounty programs.
masscan_as_a_service - masscan as a service
tartufo - Searches through git repositories for high entropy strings and secrets, digging deep into commit history
brs-xss - MIT license BRS-XSS is a modular Python CLI scanner for XSS vulnerabilities. Features context-aware payloads, WAF evasion, DOM analysis via Playwright, ML-based risk scoring, and export in HTML/JSON/SARIF. Designed for integration with Brabus Recon Suite (BRS).
malwarescanner - Simple Malware Scanner written in python