Back to projects

WIP Project

Survex

Attack Surface Management + Automated Pentesting CLI

Survex is a modular 28-module pipeline for external attack surface mapping and automated security testing. It supports domains, subdomains, IPs, CIDRs, and host files, then produces risk-scored findings, scan diffs, structured JSON artifacts, and a dark-theme HTML report.

View Repository

core_pipeline

Recon + vuln workflows covering subdomain enum, DNS/TLS/WAF, web security checks, active testing, nuclei coverage, and scan history/diff operations.

risk_scoring

Built-in severity logic for exposed services, web misconfigurations, CORS/cookie issues, cloud exposure, takeover indicators, leaked secrets, and critical vuln signals from active modules.

alerting_output

Sends Discord/Slack webhook notifications and writes per-scan outputs under reports with `summary.json`, `findings.json`, module results, screenshot metadata, and an HTML dashboard.

cicd_ready

Supports fail thresholds (`--fail-on`) for pipeline gating and continuous monitoring via `watch` mode. Designed for weekly scheduled scans and regression tracking between runs.

modules (28)

subfinderamasscrtsdnsdnsbrutenmaphttpxtlswafheaderscorscookiess3takeoveremailgaukatanajsscanapidiscoverygraphqlopenredirectffufdalfoxsqlmapnucleiscreenshotshodangithub