WIP Project
Attack Surface Management + Automated Pentesting CLI
Survex is a modular 28-module pipeline for external attack surface mapping and automated security testing. It supports domains, subdomains, IPs, CIDRs, and host files, then produces risk-scored findings, scan diffs, structured JSON artifacts, and a dark-theme HTML report.
View Repositorycore_pipeline
Recon + vuln workflows covering subdomain enum, DNS/TLS/WAF, web security checks, active testing, nuclei coverage, and scan history/diff operations.
risk_scoring
Built-in severity logic for exposed services, web misconfigurations, CORS/cookie issues, cloud exposure, takeover indicators, leaked secrets, and critical vuln signals from active modules.
alerting_output
Sends Discord/Slack webhook notifications and writes per-scan outputs under reports with `summary.json`, `findings.json`, module results, screenshot metadata, and an HTML dashboard.
cicd_ready
Supports fail thresholds (`--fail-on`) for pipeline gating and continuous monitoring via `watch` mode. Designed for weekly scheduled scans and regression tracking between runs.
modules (28)