Compare commits

...

130 Commits
v9.2 ... master

Author SHA1 Message Date
@xer0dayz a5450bc496 docs(README): link latest recon-methodology cluster + regroup guides (SEO/referral) 2026-07-04 16:33:28 -04:00
@xer0dayz 4130a58ccf docs(README): add June 2026 pillar/blog + latest YouTube links; SEO link audit 2026-06-24 17:16:13 -04:00
@xer0dayz a965fa4431 Merge branch 'master' of https://github.com/1N3/Sniper
# Conflicts:
#	README.md
2026-06-06 19:10:39 -04:00
@xer0dayz 91de0b310c docs(README): enrich anchor text with SEO target terms for /external-attack-surface-management-with-sn1per/, /passive-reconnaissance-techniques-for-penetration-testing/, /cve-2024-21733-... and /about/
- Add new "What Sn1per Is For" section near the top with 3 keyword-rich
  bullet links: External Attack Surface Management, Continuous Attack Surface
  Management, Automated Penetration Testing
- Top nav: Solutions → "Attack Surface Management", About → "About Sn1per"
- Documentation & Help: add Sn1per Documentation Hub + Passive Reconnaissance
  Techniques + CVE-2024-21733 Apache Tomcat writeup
- News & Releases: add EASM page as background reading
- Trailing About Sn1perSecurity: enrich author/publisher paragraph with
  keyword-rich "attack surface management and automated penetration testing
  platform" anchor

Background: v3.7 GSC analysis flagged 90% of GitHub-sourced anchor text as
raw URLs (zero keyword SEO equity) while github.com is the site's #1
traffic source (1,907 sessions/30d). These edits pass keyword-rich anchor
text to 4 landing pages that were optimized on 2026-06-06 (EASM rewrite,
Tier 2 snippet rewrites, About FAQ section, CVE post CTA).

No behavior change. README still reads as community documentation.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-06-06 18:52:18 -04:00
xer0dayz 32d1915f62
Update links in README.md for accuracy 2026-06-04 16:31:38 -07:00
@xer0dayz 7f8ec41102 Point primary CTAs at /product/sn1per-professional-2026-license/ and /request-a-quote/ 2026-06-04 19:25:26 -04:00
xer0dayz f9ce7051f8
Merge pull request #465 from 1N3/readme-modernize-2026
Modernize README for Sn1per Professional 2026 release
2026-04-29 13:27:02 -07:00
@xer0dayz 9fec4fc842 Modernize README for Sn1per Professional 2026 release
- Refresh hero banner + screenshots to 2026 visuals
- Add 'What's New in 2026' section + announcement blockquote
- Replace stale 2022 Enterprise screenshots
- Add Editions & Pricing table matching website pricing breakdown
- Mirror website top nav (Products, Solutions, About, News, Contact, Demo, Pricing, Shop)
- Convert Scan Modes to table, regroup Integrations by category
- Surface docs/*.md in new Documentation section
- Add Community, Contributing, expanded License sections
- Replace 150-word keyword block with About + topic tags
- Refresh News list with three most recent 2026 posts
- Fix WORSPACE_ALIAS typo and mislabeled LOOT RELOAD comment
- Add new 2026 CLI flag examples (-v, -db, -rr)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-29 16:19:56 -04:00
@xer0dayz 795557c52b Modernize README for Sn1per Professional 2026 release
- Refresh hero banner + screenshots to 2026 visuals
- Add 'What's New in 2026' section + announcement blockquote
- Replace stale 2022 Enterprise screenshots
- Add Editions & Pricing table matching website pricing breakdown
- Mirror website top nav (Products, Solutions, About, News, Contact, Demo, Pricing, Shop)
- Convert Scan Modes to table, regroup Integrations by category
- Surface docs/*.md in new Documentation section
- Add Community, Contributing, expanded License sections
- Replace 150-word keyword block with About + topic tags
- Refresh News list with three most recent 2026 posts
- Fix WORSPACE_ALIAS typo and mislabeled LOOT RELOAD comment
- Add new 2026 CLI flag examples (-v, -db, -rr)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-29 15:41:26 -04:00
xer0dayz 68282e0bcb
Fix link formatting for SILENTCHAIN AI release note 2026-02-15 09:14:28 -07:00
xer0dayz 7ffa671fff
Update README with new SILENTCHAIN AI version
Added news section for SILENTCHAIN AI Community Edition v1.1.3.
2026-02-15 09:13:55 -07:00
xer0dayz 34747b3576
Merge pull request #424 from abnerrizzi/feat-gh-action
GitHub action to build and push Docker image to GitHub registry
2026-01-12 12:58:06 -07:00
xer0dayz 16b2dfcbb4
Merge pull request #460 from gbiagomba/patch-2
Multi-Platform support
2026-01-12 12:44:06 -07:00
xer0dayz 14a0d6f448
Redirect errors for last command to /dev/null 2026-01-12 12:43:36 -07:00
xer0dayz 3059110ddf
Updating latest SE version 2026-01-09 10:30:19 -07:00
xer0dayz 6f22ff3f3a
Update news section in README.md
Removed outdated news about Sn1per SE v10.8 and updated the release note for Sn1per SE v11.0.
2026-01-09 10:22:43 -07:00
D4rth R3v4n 33f530d6c8
Multi-Platform support
Added support for Debian/Ubuntu, RHEL/CentOS/Fedora/Amazon Linux, Arch Linux, macOS
2025-12-17 11:29:14 -05:00
@xer0dayz cb4e7ceef1 Merge branch 'master' of https://github.com/1N3/Sniper 2025-09-28 14:27:40 -04:00
xer0dayz feeb5c6581
Update install.sh
Fixed webtech error
2025-09-27 15:57:43 -07:00
xer0dayz 345551590b
Update normal.sh
Fixed samrdump.py location
2025-09-27 15:54:23 -07:00
xer0dayz 0b464aeb32
Update install.sh
Updated vulners installer script
2025-09-27 15:51:02 -07:00
xer0dayz 163a6adf2b
Update install.sh
Updated base dependencies for minimal images
2025-09-27 15:24:19 -07:00
xer0dayz e93d435a54
Update install.sh
Fix python dependencies
2025-09-23 13:44:42 -07:00
xer0dayz ed440db38c
Updated Kali repo GPG key 2025-06-03 14:26:40 -07:00
xer0dayz 179ac1e783
Update README.md 2025-05-27 15:36:10 -07:00
xer0dayz 3d458e7b2b
Update README.md
Updated Docker privileges
2025-05-18 14:34:24 -07:00
xer0dayz 4ff7c0cc89
Update sniper 2025-02-28 14:52:43 -07:00
xer0dayz 699fa61051
Update README.md 2025-02-28 06:29:04 -07:00
xer0dayz 5c3aed59b3
Merge pull request #443 from h3xx/dry-help-message
DRY help message code
2025-01-01 14:50:27 -07:00
xer0dayz b40999a39b
Update sniper 2024-11-29 06:32:49 -07:00
xer0dayz ff3df6149e
Update README.md 2024-11-29 06:31:38 -07:00
Dan Church fa6171de7b
DRY help message code
Don't call 'echo' a bunch of times.
2024-11-15 11:48:51 -06:00
xer0dayz c66d2a158c
Update webscan.sh
Fixed Nuclei template scans
2024-10-21 14:36:48 -07:00
xer0dayz b10362bdab
Update install.sh
Removed old Metasploit GPG key from install.
2024-08-04 10:27:06 -07:00
xer0dayz 2b78432199
Update install.sh
Updated python deps
2024-08-02 14:35:01 -07:00
xer0dayz 308f22c6a2
Update install.sh
Cleaning up install files
2024-08-02 11:04:41 -07:00
xer0dayz 7f5657e8fe
Update install.sh
Updated PHP version.
2024-08-02 11:02:25 -07:00
xer0dayz 09c852993b
Update install.sh
Add wtmpdb for last command usage
2024-08-01 14:49:51 -07:00
semgrep.dev on behalf of @1N3 8058f3faa5 Add Semgrep CI 2024-07-15 12:02:04 +00:00
xer0dayz 36466220f9
Merge pull request #436 from eltociear/patch-1
docs: update README.md
2024-06-20 12:30:24 -07:00
xer0dayz beeac68f1a
Update README.md 2024-06-20 12:26:58 -07:00
Abner Rizzi 8cc3d5f25b Merge remote-tracking branch 'upstream/master' into feat-gh-action 2024-06-20 13:42:29 +00:00
Ikko Eltociear Ashimine 0f31b5b6c3
docs: update README.md
mutiple -> multiple
2024-06-08 23:37:32 +09:00
xer0dayz 7d53725462
Update sniper 2024-05-29 14:09:56 -07:00
xer0dayz ef0863c4f8
Update README.md 2024-05-29 14:08:34 -07:00
xer0dayz 7326756585
Merge pull request #435 from xalgord/patch-1
Gau Syntax Fix
2024-05-18 13:00:29 -07:00
Krishna Kaushal ca08f79ab2
Gau Syntax Fix
 `gau -subs $TARGET`
 `gau --subs $TARGET`
2024-05-07 16:31:52 +05:30
root 10917656ae Merge branch 'master' of https://github.com/1N3/Sn1per 2024-04-01 15:53:40 -07:00
xer0dayz bfd10578ad
Update sniper 2024-04-01 15:52:32 -07:00
root bdf8f1170f Merge branch 'master' of https://github.com/1N3/Sn1per 2024-04-01 15:51:35 -07:00
root 449eaf4173 Updating pro version number 2024-04-01 15:48:46 -07:00
Abner Rizzi 9233c70705 Merge remote-tracking branch 'origin/master' into feat-gh-action 2024-01-01 13:23:30 +00:00
Abner Rizzi e7a0698e74
merge (#3)
* Delete bin/inurlbr.php

* Update README.md

* Update README.md

---------

Co-authored-by: xer0dayz <1N3@hushmail.com>
2023-12-25 20:26:46 -03:00
xer0dayz b237711456
Update README.md 2023-10-30 15:25:30 -07:00
xer0dayz 843b2c46d6
Update README.md 2023-10-30 15:16:39 -07:00
xer0dayz d51dece161
Delete bin/inurlbr.php 2023-09-29 15:14:24 -07:00
Abner Rizzi a852a23bbc
Delete Dockerfile.base 2023-08-10 16:31:25 -03:00
Abner Rizzi 5d6a4336e3 testing 2023-08-10 16:21:53 -03:00
Abner Rizzi dbfa48b8a2 testing 2023-08-10 16:19:22 -03:00
Abner Rizzi e56263f4e4 testing 2023-08-10 16:18:29 -03:00
Abner Rizzi 54755d7193 testing 2023-08-10 16:17:48 -03:00
Abner Rizzi 1c894ecd14 testing 2023-08-10 16:16:27 -03:00
Abner Rizzi b0cf787f6d testing 2023-08-10 16:15:12 -03:00
Abner Rizzi d0c4ea461f testing 2023-08-10 15:45:27 -03:00
Abner Rizzi f5bbb36144 testing 2023-08-10 15:44:38 -03:00
Abner Rizzi 2e7af5d9c0 testing 2023-08-10 15:44:09 -03:00
Abner Rizzi 7dcf77b200 testing 2023-08-10 15:42:45 -03:00
Abner Rizzi 8a2dbc8fc8 testing 2023-08-10 15:40:22 -03:00
Abner Rizzi 9b98b209e8 testing 2023-08-10 15:39:45 -03:00
Abner Rizzi ed6af61352 test build and push 2023-08-10 09:26:34 -03:00
Abner Rizzi 971038eebb test build and push 2023-08-10 09:26:15 -03:00
Abner Rizzi 2cabdb512f test build and push 2023-08-10 09:23:47 -03:00
Abner Rizzi c1ea2a9b16 test build and push 2023-08-10 09:22:18 -03:00
Abner Rizzi d0d55d424c test build and push 2023-08-10 09:21:52 -03:00
Abner Rizzi 95fd7982fc test build and push 2023-08-10 09:20:58 -03:00
Abner Rizzi 6c1f0aec25 test build and push 2023-08-10 09:20:11 -03:00
Abner Rizzi 2cd7bbcbae test build and push 2023-08-10 09:17:10 -03:00
Abner Rizzi 20e2164e81 test build and push 2023-08-10 09:12:40 -03:00
Abner Rizzi 2f388766c6 test build and push 2023-08-10 09:10:19 -03:00
Abner Rizzi ea50061017 test build and push 2023-08-10 09:10:11 -03:00
Abner Rizzi 94619dda12 test build and push 2023-08-10 09:06:57 -03:00
Abner Rizzi a5eb2fab79 test build and push 2023-08-10 09:02:25 -03:00
Abner Rizzi bba3c457a3 test build and push 2023-08-10 08:59:44 -03:00
Abner Rizzi 3fbc49a027 test build and push 2023-08-10 08:59:11 -03:00
Abner Rizzi 1c7759d66f test build and push 2023-08-10 08:57:56 -03:00
Abner Rizzi 2e299ae46d test build and push 2023-08-10 08:57:52 -03:00
Abner Rizzi 16d201b017 test build and push 2023-08-10 08:57:33 -03:00
Abner Rizzi a91580b75f test build and push 2023-08-10 08:54:45 -03:00
Abner Rizzi f47afeaeb1 test build and push 2023-08-10 08:53:02 -03:00
Abner Rizzi 37f5589513 test build and push 2023-08-10 08:52:02 -03:00
Abner Rizzi 3fa0dfba46 test build and push 2023-08-10 08:51:21 -03:00
Abner Rizzi 481befa4fd test build and push 2023-08-10 08:50:46 -03:00
Abner Rizzi 42c97445ab test build and push 2023-08-10 08:50:06 -03:00
Abner Rizzi 17ea813c0d test build and push 2023-08-10 08:45:59 -03:00
Abner Rizzi 39584865ba test build and push 2023-08-10 08:45:27 -03:00
Abner Rizzi ade0a84fee test build and push 2023-08-10 08:44:04 -03:00
Abner Rizzi cb79d17e16 test build and push 2023-08-10 08:40:09 -03:00
Abner Rizzi 7ef0ad253a test build and push 2023-08-10 08:39:26 -03:00
Abner Rizzi c76e65bc03 test build and push 2023-08-10 08:38:48 -03:00
Abner Rizzi d916111983 test build and push 2023-08-10 08:38:26 -03:00
Abner Rizzi dfe1598d3f test build and push 2023-08-10 08:24:38 -03:00
Abner Rizzi 225588e7d2 test build and push 2023-08-10 07:50:05 -03:00
Abner Rizzi 7af1b65a01 test build and push 2023-08-10 07:47:35 -03:00
Abner Rizzi 5d97699938 test build and push 2023-08-10 07:46:44 -03:00
Abner Rizzi c2a344966b test build and push 2023-08-10 07:46:04 -03:00
Abner Rizzi 88c5b42818 test build and push 2023-08-10 07:44:51 -03:00
Abner Rizzi a34c29a08b test build and push 2023-08-10 07:43:35 -03:00
Abner Rizzi 00f0236c6e test build and push 2023-08-10 07:43:02 -03:00
Abner Rizzi 4a3b3dcecf test build and push 2023-08-10 07:42:36 -03:00
Abner Rizzi 5b75e094fe test build and push 2023-08-10 07:39:53 -03:00
Abner Rizzi cd3bcca565 test build and push 2023-08-10 07:38:47 -03:00
Abner Rizzi bd9b021a29 test build and push 2023-08-10 07:37:14 -03:00
Abner Rizzi dcddeaab2a test build and push 2023-08-10 07:36:37 -03:00
Abner Rizzi 11acd0ed92 test build and push 2023-08-10 07:36:12 -03:00
Abner Rizzi 10facebcdc test build and push 2023-08-10 07:35:33 -03:00
Abner Rizzi 3d1f82c275 test build and push 2023-08-10 07:34:45 -03:00
Abner Rizzi dd1e880dab test build and push 2023-08-10 07:33:33 -03:00
Abner Rizzi e4a6c2f69a test build and push 2023-08-10 07:31:02 -03:00
Abner Rizzi 9806956b95 test build and push 2023-08-10 07:29:16 -03:00
Abner Rizzi bc91d6e2f1 test build and push 2023-08-10 07:27:57 -03:00
Abner Rizzi db0f4844df test build and push 2023-08-10 07:26:02 -03:00
Abner Rizzi 7e9991e167 test build and push 2023-08-10 07:24:56 -03:00
Abner Rizzi 6594a7652d test build and push 2023-08-10 07:21:58 -03:00
Abner Rizzi 0ebabf0ee1 test build and push 2023-08-10 07:21:20 -03:00
Abner Rizzi 445e629131 test build and push 2023-08-10 07:17:16 -03:00
Abner Rizzi 2e90967757 test build and push 2023-08-10 07:16:33 -03:00
Abner Rizzi f6569151e8 test build and push 2023-08-10 07:14:22 -03:00
Abner Rizzi 641ee99f30 test build and push 2023-08-10 07:12:53 -03:00
Abner Rizzi 6b24418c29 test build and push 2023-08-10 07:10:16 -03:00
Abner Rizzi 78a3438501 test build and push 2023-08-10 07:09:16 -03:00
9 changed files with 1309 additions and 4481 deletions

58
.github/workflows/build-push-ghcr.yml vendored Normal file
View File

@ -0,0 +1,58 @@
name: Build and Push
on:
push:
branches:
- main
- development
- feat*
tags:
- "v*"
pull_request:
branches:
- master
env:
REGISTRY: ghcr.io
IMAGE_NAME: ${{ github.repository }}
jobs:
docker-build:
permissions:
contents: read
packages: write
runs-on: ubuntu-latest
steps:
- name: Setting environment variables
run: |
echo "repo_name=${{ env.IMAGE_NAME }}" >> $GITHUB_ENV
- uses: actions/checkout@v3
- name: Docker meta
id: meta
uses: docker/metadata-action@v4
with:
images: ${{ env.REGISTRY}}/${{ env.repo_name }}
flavor: latest=true
tags: |
type=ref,event=branch
type=ref,event=pr
type=semver,pattern={{version}}
- name: Login to image repository
uses: docker/login-action@v2
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Build and push
uses: docker/build-push-action@v3
with:
context: .
file: Dockerfile
push: ${{ github.ref_type == 'tag' || github.ref_name == 'main' || startsWith(github.ref_name, 'feat-')}}
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}

24
.github/workflows/semgrep.yml vendored Normal file
View File

@ -0,0 +1,24 @@
on:
workflow_dispatch: {}
pull_request: {}
push:
branches:
- main
- master
paths:
- .github/workflows/semgrep.yml
schedule:
# random HH:MM to avoid a load spike on GitHub Actions at 00:00
- cron: 2 23 * * *
name: Semgrep
jobs:
semgrep:
name: semgrep/ci
runs-on: ubuntu-20.04
env:
SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }}
container:
image: returntocorp/semgrep
steps:
- uses: actions/checkout@v3
- run: semgrep ci

346
README.md
View File

@ -1,115 +1,161 @@
[![Sn1perSecurity](https://sn1persecurity.com/images/Sn1perSecurity-Attack-Surface-Management-header2.png)](https://sn1persecurity.com)
[![Sn1per](https://sn1persecurity.com/wordpress/wp-content/uploads/2026/04/sn1per-professional-2026-hero-banner.png)](https://sn1persecurity.com/wordpress/product/sn1per-professional-2026-license/)
[![GitHub release](https://img.shields.io/github/release/1N3/Sn1per.svg)](https://github.com/1N3/Sn1per/releases)
[![License](https://img.shields.io/github/license/1N3/Sn1per.svg)](https://github.com/1N3/Sn1per/blob/master/LICENSE.md)
[![GitHub issues](https://img.shields.io/github/issues/1N3/Sn1per.svg)](https://github.com/1N3/Sn1per/issues)
[![Github Stars](https://img.shields.io/github/stars/1N3/Sn1per.svg?style=social&label=Stars)](https://github.com/1N3/Sn1per/)
[![GitHub Followers](https://img.shields.io/github/followers/1N3.svg?style=social&label=Follow)](https://github.com/1N3/Sn1per/)
[![Tweet](https://img.shields.io/twitter/url/http/xer0dayz.svg?style=social)](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fdeveloper.twitter.com%2Fen%2Fdocs%2Ftwitter-for-websites%2Ftweet-button%2Foverview&ref_src=twsrc%5Etfw&text=Sn1per%20-%20Automated%20Pentest%20Recon%20Scanner&tw_p=tweetbutton&url=https%3A%2F%2Fgithub.com%2F1N3%2FSn1per)
[![Last commit](https://img.shields.io/github/last-commit/1N3/Sn1per.svg)](https://github.com/1N3/Sn1per/commits/master)
[![Contributors](https://img.shields.io/github/contributors/1N3/Sn1per.svg)](https://github.com/1N3/Sn1per/graphs/contributors)
[![GitHub Stars](https://img.shields.io/github/stars/1N3/Sn1per.svg?style=social&label=Stars)](https://github.com/1N3/Sn1per/stargazers)
[![GitHub Forks](https://img.shields.io/github/forks/1N3/Sn1per.svg?style=social&label=Forks)](https://github.com/1N3/Sn1per/network/members)
[![GitHub Followers](https://img.shields.io/github/followers/1N3.svg?style=social&label=Follow)](https://github.com/1N3)
[![Follow on Twitter](https://img.shields.io/twitter/follow/xer0dayz.svg?style=social&label=Follow)](https://twitter.com/intent/follow?screen_name=xer0dayz)
[[Website](https://sn1persecurity.com/wordpress/)] [[Blog](https://sn1persecurity.com/wordpress/blog/)] [[Shop](https://sn1persecurity.com/wordpress/shop)] [[Documentation](https://sn1persecurity.com/wordpress/documentation/)] [[Demo](https://www.youtube.com/c/Sn1perSecurity/videos)] [[Find Out More](https://sn1persecurity.com/wordpress/external-attack-surface-management-with-sn1per/)]
[[Products](https://sn1persecurity.com/wordpress/shop/)] [[Attack Surface Management](https://sn1persecurity.com/wordpress/use-cases/)] [[About Sn1per](https://sn1persecurity.com/wordpress/about/)] [[News](https://sn1persecurity.com/wordpress/blog/)] [[Contact](https://sn1persecurity.com/wordpress/home/contact/)] [[Demo](https://sn1persecurity.com/wordpress/#video)] [[Pricing](https://sn1persecurity.com/wordpress/product/sn1per-professional-2026-license/)] [[Shop](https://sn1persecurity.com/wordpress/shop/)]
# Sn1per — The Offensive-Security Platform for Modern Teams
## Attack Surface Management Platform
> Recon, scanning, exploitation, and reporting in a single workspace — whether you're a solo pentester or a global SOC.
### Discover hidden assets and vulnerabilities in your environment
> ## Sn1per Professional 2026 is here
>
> The largest release since v10.0 — Docker-first deployment, Bootstrap 5 / Tabler UI, Workspace Navigator, Workspace + Host Reports with CSV / Excel / PDF export, JSON API v1.0, an Offcanvas Quick Commands sidebar with 13 panels, and expanded modules for ReverseAPK, MassPwn, Threat Intel, Nessus, and Burp.
>
> [Read the release notes →](https://sn1persecurity.com/wordpress/sn1per-professional-2026-release/) · [View pricing →](https://sn1persecurity.com/wordpress/product/sn1per-professional-2026-license/)
#### [[Find out more](https://sn1persecurity.com/wordpress/shop)]
## Table of Contents
[![](https://sn1persecurity.com/wordpress/wp-content/uploads/2022/05/Sn1per-Enterprise-workspace-navigator1-3.png)](https://sn1persecurity.com/)
- [About](#about-sn1per)
- [What Sn1per Is For](#what-sn1per-is-for)
- [What's New in 2026](#whats-new-in-2026)
- [Editions & Pricing](#editions--pricing)
- [Install](#install)
- [Quick Start](#quick-start)
- [Usage](#usage)
- [Scan Modes](#scan-modes)
- [Integrations](#integrations)
- [Documentation & Help](#documentation--help)
- [News & Releases](#news--releases)
- [Community & Support](#community--support)
- [Contributing](#contributing)
- [License & Legal](#license--legal)
## The ultimate pentesting toolkit
## About Sn1per
Integrate with the leading commercial and open source vulnerability scanners to scan for the latest CVEs and vulnerabilities.
Sn1per is an offensive-security platform that consolidates reconnaissance, vulnerability scanning, exploitation, and reporting into a single workspace. Built by pentesters since 2015, it ships in three editions — a free Community Edition (source-available, custom EULA — see LICENSE.md) in this repository, a paid Professional edition for individual operators and small teams, and an Enterprise edition for global SOCs — all backed by the same core scanning engine.
[![](https://sn1persecurity.com/wordpress/wp-content/uploads/2022/05/Sn1per-Enterprise-workspace-report1-3.png)](https://sn1persecurity.com/)
Sn1per orchestrates 90+ third-party tools, ships with 600+ exploits and 10,000+ detections, and is used by 500+ teams worldwide. Battle-tested by the community. Built by pentesters, for pentesters.
### Automate the most powerful tools
**500+** Teams · **90+** Integrations · **10,000+** Detections · **600+** Exploits · Trusted since **2015**
Security tools are expensive and time-consuming, but with Sn1per, you can save time by automating the execution of these open source and commercial tools to discover vulnerabilities across your entire attack surface.
## What Sn1per Is For
[![](https://sn1persecurity.com/wordpress/wp-content/uploads/2022/05/Sn1per-Enterprise-host-list3-1.png)](https://sn1persecurity.com/)
Sn1per ships as one platform that covers the core jobs offensive security teams otherwise stitch together from a dozen tools:
### Find what you can't see
- **[External Attack Surface Management](https://sn1persecurity.com/wordpress/external-attack-surface-management-with-sn1per/)** - continuous discovery, monitoring, and active exploitation of every internet-facing asset your organization owns, including the ones nobody on your team knows about.
- **[Continuous Attack Surface Management](https://sn1persecurity.com/wordpress/continuous-attack-surface-management-with-sn1per-professional/)** - daily-cadence rescans that diff yesterday's surface against today's so new exposures hit your SOC within hours, not the next quarterly pentest.
- **[Automated Penetration Testing](https://sn1persecurity.com/wordpress/automated-penetration-testing/)** - 600+ exploits and 10,000+ detections orchestrated as a single workflow, with active verification eliminating the false positives version-only scanners ship as "critical."
- **[Reconnaissance & Attack Surface Discovery](https://sn1persecurity.com/wordpress/reconnaissance-methodology/)** - the full phased recon workflow, from OSINT and subdomain enumeration through live-host discovery and fingerprinting, run as one automated pass.
Hacking is a problem that's only getting worse. But, with Sn1per, you can find what you cant see—hidden assets and vulnerabilities in your environment.
## What's New in 2026
[![](https://sn1persecurity.com/wordpress/wp-content/uploads/2022/05/Sn1per-Enterprise-host-list2-1.png)](https://sn1persecurity.com/)
[![Sn1per Pro 2026 Workspace Navigator](https://sn1persecurity.com/wordpress/wp-content/uploads/2026/04/sn1per-pro-2026-workspace-navigator.png)](https://sn1persecurity.com/wordpress/sn1per-professional-2026-release/)
### Discover and prioritize risks in your organization
*Workspace Navigator — switch contexts across hosts, scopes, and engagements.*
Sn1per is a next-generation information gathering tool that provides automated, deep, and continuous security for organizations of all sizes.
[![Sn1per Pro 2026 Dashboard](https://sn1persecurity.com/wordpress/wp-content/uploads/2026/04/sn1per-pro-2026-dashboard.png)](https://sn1persecurity.com/wordpress/sn1per-professional-2026-release/)
[![](https://sn1persecurity.com/wordpress/wp-content/uploads/2022/05/Sn1per-Enterprise-vulnerability-report1-3.png)](https://sn1persecurity.com/)
*Dashboard — at-a-glance scan posture, top findings, and exploitable assets.*
### See Sn1per in action
### Highlights
[![](https://sn1persecurity.com/wordpress/wp-content/uploads/2022/10/Sn1perbootcampseries1.png)](https://www.youtube.com/c/Sn1perSecurity/videos)
- **Docker-first deployment** — same image, every distro
- **Bootstrap 5 / Tabler UI** — refreshed responsive interface with light + dark mode
- **Workspace Navigator** — fast workspace switching with state preservation
- **Workspace & Host Reports** — CSV, Excel, and PDF export
- **JSON API v1.0** — programmatic access for CI / SOAR / SIEM pipelines
- **Offcanvas Quick Commands** — 13 panels, every common action one click away
- **Expanded modules** — ReverseAPK, MassPwn, Threat Intel, Nessus, Burp Suite
- **Maturing SC0PE framework** — more parsers, better noise reduction
- **Hardened PHP library stack** — modern dependencies, audited components
- **New CLI flags**`-v` (verbose), `-db` (debug), `-rr` (remove resume files)
### News
> *"Sn1per Professional 2026 is the largest release since the v10.0 line."*
- #### [Automated Penetration Testing Guide - Your Ultimate Resource](https://sn1persecurity.com/wordpress/penetration-testing-guide/)
- #### [Sn1per Enterprise v20230516 Released!](https://sn1persecurity.com/wordpress/sn1per-enterprise-v20230516-released/)
- #### [Dark Web Monitoring: Securing Your External Attack Surface](https://sn1persecurity.com/wordpress/dark-web-monitoring-securing-your-external-attack-surface/)
- #### [Sn1per Scan Engine v10.4 Released!](https://sn1persecurity.com/wordpress/sn1per-scan-engine-v10-4-released/)
- #### [Sn1per: The Next Generation of Tools for Security Professionals](https://sn1persecurity.com/wordpress/sn1per-the-next-generation-of-tools-for-security-professionals/)
- #### [Sn1per Scan Engine v10.3 Released!](https://sn1persecurity.com/wordpress/sn1per-scan-engine-v10-3-released/)
- #### [5 Ways Sn1per Can Automate Your Security Workflow](https://sn1persecurity.com/wordpress/5-ways-sn1per-can-automate-your-security-workflow/)
- #### [External Attack Surface Management with Sn1per](https://sn1persecurity.com/wordpress/external-attack-surface-management-with-sn1per/)
- #### [Sn1per Scan Engine v10.2 Released!](https://sn1persecurity.com/wordpress/sn1per-scan-engine-v10-2-update/)
- #### [Sn1per Enterprise Released!](https://sn1persecurity.com/wordpress/sn1per-enterprise-released/)
- #### [Sn1per Professional v10.0 Released!](https://sn1persecurity.com/wordpress/sn1per-professional-v10-released/)
[Read the full release notes →](https://sn1persecurity.com/wordpress/sn1per-professional-2026-release/)
## Kali/Ubuntu/Debian/Parrot Linux Install
## Editions & Pricing
```
git clone https://github.com/1N3/Sn1per
The [Community Edition](https://sn1persecurity.com/wordpress/sn1per-community-edition/) is free and lives in this repository. The Professional and Enterprise editions add a Web UI, commercial integrations, and email support.
| | **Sn1per Professional** | **Sn1per Enterprise** |
|---|---|---|
| **Price** | $984 / year (per seat) | Get a quote |
| **Subscription** | 1 year | 1 year |
| **— Included —** | | |
| Web UI | Professional Web UI | Enterprise Web UI |
| Scan Engine & UI Updates | ✓ | ✓ |
| All Modules & Integrations | ✓ | ✓ |
| On-Prem (Self Hosted) | ✓ | ✓ |
| Email Support | 1 Year | 1 Year |
| Improved Speed & Scalability | — | ✓ |
| Cutting-Edge Features | — | ✓ |
| **— Limits & Quotas —** | | |
| Max Scans | Unlimited | Unlimited |
| Max Assets / Workspace | 30 | Unlimited |
| Max Workspaces | 5 | Unlimited |
| Total Assets | 150 | 500+ |
| Licensed Systems | 1 | 1 |
[Buy a Sn1per Professional license →](https://sn1persecurity.com/wordpress/product/sn1per-professional-2026-license/) · [Get an Enterprise quote →](https://sn1persecurity.com/wordpress/request-a-quote/)
## Install
### Linux (Kali / Ubuntu / Debian / Parrot)
```bash
git clone https://github.com/1N3/Sn1per.git
cd Sn1per
bash install.sh
sudo bash install.sh
```
## AWS AMI (Free Tier) VPS Install
> Sn1per installs to `/usr/share/sniper` and requires root. Use `sudo bash install.sh force` to skip the confirmation prompt.
[![](https://sn1persecurity.com/wordpress/wp-content/uploads/2022/06/AWS-Marketplace.png)](https://aws.amazon.com/marketplace/pp/prodview-rmloab6wnymno)
### Docker
To install Sn1per using an AWS EC2 instance:
[Sn1per on Docker Hub →](https://hub.docker.com/r/sn1persecurity/sn1per)
1. Go to <https://aws.amazon.com/marketplace/pp/prodview-rmloab6wnymno> and click the “Continue to Subscribe” button
2. Click the “Continue to Configuration” button
3. Click the “Continue to Launch” button
4. Login via SSH using the public IP of the new EC2 instance
#### Kali Linux base
## Docker Install
```bash
sudo docker compose up
sudo docker run --privileged -it sn1per-kali-linux /bin/bash
```
[![](https://sn1persecurity.com/images/docker-logo.png)](https://hub.docker.com/r/sn1persecurity/sn1per)
#### BlackArch base
### Kali Linux-based Sn1per
```bash
sudo docker compose -f docker-compose-blackarch.yml up
sudo docker run --privileged -it sn1per-blackarch /bin/bash
```
1. Run the Docker Compose file
### AWS Marketplace (EC2 AMI)
```bash
sudo docker compose up
```
Subscribe via [AWS Marketplace](https://aws.amazon.com/marketplace/pp/prodview-rmloab6wnymno):
1. Run the container
1. Click **Continue to Subscribe**
2. Click **Continue to Configuration**, choose region/instance type
3. Click **Continue to Launch**
4. SSH to the EC2 public IP — Sn1per is preinstalled
```bash
sudo docker run -it sn1per-kali-linux /bin/bash
```
## Quick Start
### BlackArch-based Sn1per
```bash
sudo bash install.sh
sniper -t example.com -m normal
```
1. Run the Docker Compose file
```bash
sudo docker compose -f docker-compose-blackarch.yml up
```
1. Run the container
```bash
sudo docker run -it sn1per-blackarch /bin/bash
```
Results land in `/usr/share/sniper/loot/<workspace>/`. See [Usage](#usage) for more modes.
## Usage
@ -124,7 +170,7 @@ sniper -t <TARGET> -o -re
sniper -t <TARGET> -m stealth -o -re
[*] DISCOVER MODE
sniper -t <CIDR> -m discover -w <WORSPACE_ALIAS>
sniper -t <CIDR> -m discover -w <WORKSPACE_ALIAS>
[*] SCAN ONLY SPECIFIC PORT
sniper -t <TARGET> -m port -p <portnum>
@ -142,7 +188,7 @@ sniper -t <TARGET> -m webporthttp -p <port>
sniper -t <TARGET> -m webporthttps -p <port>
[*] HTTP WEBSCAN MODE
sniper -t <TARGET> -m webscan
sniper -t <TARGET> -m webscan
[*] ENABLE BRUTEFORCE
sniper -t <TARGET> -b
@ -186,7 +232,7 @@ sniper -w <WORKSPACE_ALIAS> --reimport
[*] LOOT REIMPORTALL FUNCTION
sniper -w <WORKSPACE_ALIAS> --reimportall
[*] LOOT REIMPORT FUNCTION
[*] LOOT RELOAD FUNCTION
sniper -w <WORKSPACE_ALIAS> --reload
[*] LOOT EXPORT FUNCTION
@ -200,58 +246,130 @@ sniper -c /path/to/sniper.conf -t <TARGET> -w <WORKSPACE_ALIAS>
[*] UPDATE SNIPER
sniper -u|--update
[*] VERBOSE OUTPUT (NEW IN 2026)
sniper -t <TARGET> -m airstrike -v
[*] DEBUG OUTPUT (NEW IN 2026)
sniper -t <TARGET> -m normal -db
[*] REMOVE RESUME FILES (NEW IN 2026)
sniper -t <TARGET> -m airstrike -v -rr
```
## Modes
## Scan Modes
- **NORMAL:** Performs basic scan of targets and open ports using both active and passive checks for optimal performance.
| Mode | Description |
|------|-------------|
| `normal` | Active + passive scan of the target and its open ports |
| `stealth` | Quick, mostly non-intrusive enumeration to avoid WAF / IPS |
| `flyover` | Fast multi-threaded high-level scans of many hosts |
| `airstrike` | Open-port enumeration + basic fingerprinting against a host file |
| `nuke` | Full audit across all targets in a host file |
| `discover` | Walks a CIDR and runs Sn1per on every live host |
| `port` | Targeted scan of a specific port |
| `fullportonly` | Full TCP port scan, results saved to XML |
| `web` | Web app scan on `80/tcp` + `443/tcp` only |
| `webporthttp` / `webporthttps` | Web app scan on a specific HTTP / HTTPS port |
| `webscan` | Full HTTP + HTTPS web app scan via Burp Suite + Arachni |
| `vulnscan` | OpenVAS vulnerability scan |
| `mass*` | Multi-target variants of the above (`-f targets.txt`) |
- **STEALTH:** Quickly enumerate single targets using mostly non-intrusive scans to avoid WAF/IPS blocking.
- **FLYOVER:** Fast multi-threaded high level scans of multiple targets (useful for collecting high level data on many hosts quickly).
- **AIRSTRIKE:** Quickly enumerates open ports/services on multiple hosts and performs basic fingerprinting. To use, specify the full location of the file which contains all hosts, IPs that need to be scanned and run ./sn1per /full/path/to/targets.txt airstrike to begin scanning.
- **NUKE:** Launch full audit of multiple hosts specified in text file of choice. Usage example: ./sniper /pentest/loot/targets.txt nuke.
- **DISCOVER:** Parses all hosts on a subnet/CIDR (ie. 192.168.0.0/16) and initiates a sniper scan against each host. Useful for internal network scans.
- **PORT:** Scans a specific port for vulnerabilities. Reporting is not currently available in this mode.
- **FULLPORTONLY:** Performs a full detailed port scan and saves results to XML.
- **MASSPORTSCAN:** Runs a "fullportonly" scan on mutiple targets specified via the "-f" switch.
- **WEB:** Adds full automatic web application scans to the results (port 80/tcp & 443/tcp only). Ideal for web applications but may increase scan time significantly.
- **MASSWEB:** Runs "web" mode scans on multiple targets specified via the "-f" switch.
- **WEBPORTHTTP:** Launches a full HTTP web application scan against a specific host and port.
- **WEBPORTHTTPS:** Launches a full HTTPS web application scan against a specific host and port.
- **WEBSCAN:** Launches a full HTTP & HTTPS web application scan against via Burpsuite and Arachni.
- **MASSWEBSCAN:** Runs "webscan" mode scans of multiple targets specified via the "-f" switch.
- **VULNSCAN:** Launches a OpenVAS vulnerability scan.
- **MASSVULNSCAN:** Launches a "vulnscan" mode scans on multiple targets specified via the "-f" switch.
## Integrations
## Help Topics
Sn1per ships with native integrations for **90+ tools and services**. Featured partners:
- [x] Plugins & Tools (<https://github.com/1N3/Sn1per/wiki/Plugins-&-Tools>)
- [x] Scheduled scans (<https://github.com/1N3/Sn1per/wiki/Scheduled-Scans>)
- [x] Sn1per Configuration Options (<https://github.com/1N3/Sn1per/wiki/Sn1per-Configuration-Options>)
- [x] Sn1per Configuration Templates (<https://github.com/1N3/Sn1per/wiki/Sn1per-Configuration-Templates>)
- [x] Sc0pe Templates (<https://github.com/1N3/Sn1per/wiki/Sc0pe-Templates>)
| Category | Integrations |
|----------|--------------|
| **Vulnerability scanners** | [Nessus](https://github.com/1N3/Sn1per/wiki/Nessus-Integration) · [OpenVAS](https://github.com/1N3/Sn1per/wiki/OpenVAS-Integration) · [GVM 21.x](https://github.com/1N3/Sn1per/wiki/GVM-21.x-Integration) · Nuclei |
| **Web app testing** | [Burp Suite Pro](https://github.com/1N3/Sn1per/wiki/Burpsuite-Professional-2.x-Integration) · [OWASP ZAP](https://github.com/1N3/Sn1per/wiki/OWASP-ZAP-Integration) · [WPScan](https://github.com/1N3/Sn1per/wiki/WPScan-API-Integration) |
| **Exploitation** | [Metasploit](https://github.com/1N3/Sn1per/wiki/Metasploit-Integration) |
| **Reconnaissance** | [Shodan](https://github.com/1N3/Sn1per/wiki/Shodan-Integration) · [Censys](https://github.com/1N3/Sn1per/wiki/Censys-API-Integration) · [Hunter.io](https://github.com/1N3/Sn1per/wiki/Hunter.io-API-Integration) · VirusTotal · Nmap |
| **AI / LLM** | OpenAI · Claude · Gemini |
| **Notifications & DevOps** | [Slack](https://github.com/1N3/Sn1per/wiki/Slack-API-Integration) · [GitHub API](https://github.com/1N3/Sn1per/wiki/Github-API-Integration) |
## Integration Guides
[Browse all integrations on the wiki →](https://github.com/1N3/Sn1per/wiki)
- [x] Github API integration (<https://github.com/1N3/Sn1per/wiki/Github-API-Integration>)
- [x] Burpsuite Professional 2.x integration (<https://github.com/1N3/Sn1per/wiki/Burpsuite-Professional-2.x-Integration>)
- [x] OWASP ZAP integration (<https://github.com/1N3/Sn1per/wiki/OWASP-ZAP-Integration>)
- [x] Shodan API integration (<https://github.com/1N3/Sn1per/wiki/Shodan-Integration>)
- [x] Censys API integration (<https://github.com/1N3/Sn1per/wiki/Censys-API-Integration>)
- [x] Hunter.io API integration (<https://github.com/1N3/Sn1per/wiki/Hunter.io-API-Integration>)
- [x] Metasploit integration (<https://github.com/1N3/Sn1per/wiki/Metasploit-Integration>)
- [x] Nessus integration (<https://github.com/1N3/Sn1per/wiki/Nessus-Integration>)
- [x] OpenVAS API integration (<https://github.com/1N3/Sn1per/wiki/OpenVAS-Integration>)
- [x] GVM 21.x integration (<https://github.com/1N3/Sn1per/wiki/GVM-21.x-Integration>)
- [x] Slack API integration (<https://github.com/1N3/Sn1per/wiki/Slack-API-Integration>)
- [x] WPScan API integration (<https://github.com/1N3/Sn1per/wiki/WPScan-API-Integration>)
## Documentation & Help
## License & Legal Agreement
- [Getting Started](docs/getting-started.md)
- [Installation](docs/installation.md)
- [Configuration](docs/configuration.md)
- [Usage](docs/usage.md)
- [Architecture](docs/architecture.md)
- [Integrations](docs/integrations.md)
- [Troubleshooting](docs/troubleshooting.md)
- [Wiki — full reference](https://github.com/1N3/Sn1per/wiki)
- [Sn1per Documentation Hub](https://sn1persecurity.com/wordpress/documentation/)
- [Passive Reconnaissance Techniques for Penetration Testers](https://sn1persecurity.com/wordpress/passive-reconnaissance-techniques-for-penetration-testing/)
- [CVE-2024-21733 — Apache Tomcat HTTP Request Smuggling writeup](https://sn1persecurity.com/wordpress/cve-2024-21733-apache-tomcat-http-request-smuggling/)
For license and legal information, refer to the LICENSE.md (<https://github.com/1N3/Sn1per/blob/master/LICENSE.md>) file in this repository.
### Configuration & Templates
## Purchase Sn1per Professional
- [Plugins & Tools](https://github.com/1N3/Sn1per/wiki/Plugins-&-Tools)
- [Scheduled Scans](https://github.com/1N3/Sn1per/wiki/Scheduled-Scans)
- [Sn1per Configuration Options](https://github.com/1N3/Sn1per/wiki/Sn1per-Configuration-Options)
- [Sn1per Configuration Templates](https://github.com/1N3/Sn1per/wiki/Sn1per-Configuration-Templates)
- [Sc0pe Templates](https://github.com/1N3/Sn1per/wiki/Sc0pe-Templates)
To obtain a Sn1per Professional license, go to <https://sn1persecurity.com>.
## News & Releases
External attack surface management, Attack surface monitoring, Attack Surface Management Platform, Attack Surface Management Solutions, Vulnerability management, Threat intelligence, Cybersecurity risk assessment, Security posture assessment, Digital footprint analysis, Attack surface mapping, Web application security, Network security, Infrastructure security, Cloud security, Third-party risk management, Incident response, Penetration testing, Asset discovery, Patch management, Security scanning, Firewall configuration, Intrusion detection system, Security awareness training, Data breach prevention, Web server security, Endpoint security, Phishing protection, Vulnerability assessment, Network security, Web application testing, Ethical hacking, Security assessment, Information security, Red teaming, Cybersecurity testing, Pen testing tools, Exploitation techniques, Wireless network testing, Social engineering, Security auditing, Incident response, Intrusion detection, Firewall testing, Security assessment methodology, Risk assessment, Security controls, Web vulnerability scanning, Password cracking, Security testing services, Security architecture, System hardening, Network reconnaissance, Red teaming, Penetration testing, Cybersecurity, Vulnerability assessment, Attack simulation, Threat intelligence, Risk assessment, Security testing, Adversarial tactics, Incident response, Security assessment, Network security, Defensive measures, Security controls, Social engineering, Exploitation techniques, Security awareness, Defensive strategies, Risk mitigation, Blue teaming, Security operations, Intrusion detection, Security frameworks, Cyber defense, Information security
- **[Sn1per Professional 2026 Released](https://sn1persecurity.com/wordpress/sn1per-professional-2026-release/)** - April 26, 2026
- [Introducing SILENTCHAIN AI Community Edition v1.1.3](https://sn1persecurity.com/wordpress/introducing-silentchain-ai-community-edition-v1-1-3/) - February 11, 2026
- [Sn1per SE v11.0 Now Available](https://sn1persecurity.com/wordpress/sn1per-se-v11-released/) - January 8, 2026
### Guides & deep dives (2026)
**Reconnaissance**
- [Reconnaissance Methodology](https://sn1persecurity.com/wordpress/reconnaissance-methodology/) - Sn1per's full recon-to-report workflow, phase by phase, from OSINT to reporting
- [Subdomain Enumeration](https://sn1persecurity.com/wordpress/subdomain-enumeration/) - passive sources, active brute force, and subdomain-takeover checks
- [Active Reconnaissance](https://sn1persecurity.com/wordpress/active-reconnaissance/) - port scanning, service and technology fingerprinting, and endpoint discovery
**Penetration testing**
- [Automated Penetration Testing](https://sn1persecurity.com/wordpress/automated-penetration-testing/) - the method, the tooling, and the continuous-testing model
- [Best Automated Pentest Tools](https://sn1persecurity.com/wordpress/automated-pentest-tools/) - the 2026 open-source and all-in-one pentest tooling landscape
- [Continuous Penetration Testing (PTaaS)](https://sn1persecurity.com/wordpress/continuous-penetration-testing/) - the always-on model beyond the once-a-year pentest
**Attack surface management**
- [Red Team Attack Surface Management](https://sn1persecurity.com/wordpress/red-team-attack-surface-management/) - running Sn1per as a continuous red-team and adversarial-exposure-validation workflow
- [Adversarial Exposure Validation](https://sn1persecurity.com/wordpress/adversarial-exposure-validation/) - proving which exposures are actually exploitable, not just present
- [Continuous Attack Surface Testing](https://sn1persecurity.com/wordpress/continuous-attack-surface-testing/) - daily-cadence rescans that diff yesterday's surface against today's
- [On-Prem External Attack Surface Management](https://sn1persecurity.com/wordpress/best-on-prem-external-attack-surface-management-platform/) - self-hosted, air-gapped ASM with zero data leaving your perimeter
- [Open-Source Self-Hosted ASM Tools](https://sn1persecurity.com/wordpress/open-source-self-hosted-attack-surface-management-tools/) - the self-hosted attack surface management tooling landscape
- [External Attack Surface Management with Sn1per](https://sn1persecurity.com/wordpress/external-attack-surface-management-with-sn1per/) - background reading on the ASM use case
[All releases & blog posts →](https://sn1persecurity.com/wordpress/blog/)
## Community & Support
- **Bugs:** [Open an issue](https://github.com/1N3/Sn1per/issues)
- **Twitter:** [@xer0dayz](https://twitter.com/xer0dayz)
- **YouTube:** [Sn1per Security](https://www.youtube.com/c/Sn1perSecurity/videos) - latest demo: [Continuous Attack Surface Testing](https://youtu.be/GBr7vjbGRBA)
- **Email (Pro / Enterprise customers):** see your license email
## Contributing
Pull requests welcome. For substantial changes, open an issue first to discuss the design.
- Mode scripts live in [`modes/`](modes/) — one bash file per scan mode
- Test changes against a controlled target before opening a PR
- Follow [Keep a Changelog](https://keepachangelog.com/en/1.1.0/) format in [`CHANGELOG.md`](CHANGELOG.md)
35 contributors and counting. Thank you.
## License & Legal
- **Code:** see [`LICENSE.md`](LICENSE.md) and [`THIRD_PARTY_LICENSES.md`](THIRD_PARTY_LICENSES.md)
- **Notices:** see [`NOTICE`](NOTICE)
- **Trademark:** "Sn1per" and the Sn1per logo are trademarks of Sn1perSecurity LLC. Use in derivative works requires permission. Contact: [sn1persecurity.com](https://sn1persecurity.com)
---
## About Sn1perSecurity
Sn1per is built and maintained by [Sn1perSecurity](https://sn1persecurity.com), the team behind the [Sn1per attack surface management and automated penetration testing platform](https://sn1persecurity.com/wordpress/external-attack-surface-management-with-sn1per/). Small team of pentesters shipping offensive-security tooling since 2015. We focus on the workflows we want to use ourselves — fast recon, ergonomic reporting, honest pricing, and a Community Edition that genuinely keeps up with the commercial editions. If that resonates, [say hi](https://twitter.com/xer0dayz).
**Topics:** `penetration-testing` · `offensive-security` · `attack-surface-management` · `vulnerability-scanner` · `recon` · `osint` · `red-team` · `bug-bounty` · `security-tools`

File diff suppressed because it is too large Load Diff

1291
install.sh

File diff suppressed because it is too large Load Diff

View File

@ -511,7 +511,7 @@ else
echo -e "$OKRED RUNNING SMB ENUMERATION $RESET"
echo -e "${OKGREEN}====================================================================================${RESET}•x${OKGREEN}[`date +"%Y-%m-%d](%H:%M)"`${RESET}x•"
enum4linux $TARGET | tee $LOOT_DIR/output/enum4linux-$TARGET-port139.txt
python3 $SAMRDUMP $TARGET | tee $LOOT_DIR/output/samrdump-$TARGET-port139.txt
python3 /usr/share/doc/python3-impacket/examples/samrdump.py $TARGET | tee $LOOT_DIR/output/samrdump-$TARGET-port139.txt
nbtscan $TARGET | tee $LOOT_DIR/output/nbtscan-$TARGET-port139.txt
fi
if [[ "$NMAP_SCRIPTS" = "1" ]]; then
@ -616,7 +616,7 @@ else
echo -e "$OKRED ENUMERATING SMB/NETBIOS $RESET"
echo -e "${OKGREEN}====================================================================================${RESET}•x${OKGREEN}[`date +"%Y-%m-%d](%H:%M)"`${RESET}x•"
enum4linux $TARGET | tee $LOOT_DIR/output/enum4linux-$TARGET-port445.txt
python3 $SAMRDUMP $TARGET | tee $LOOT_DIR/output/samrdump-$TARGET-port445.txt
python3 /usr/share/doc/python3-impacket/examples/samrdump.py $TARGET | tee $LOOT_DIR/output/samrdump-$TARGET-port445.txt
nbtscan $TARGET | tee $LOOT_DIR/output/nbtscan-$TARGET-port445.txt
fi
if [[ "$NMAP_SCRIPTS" = "1" ]]; then

View File

@ -229,7 +229,7 @@ if [[ "$MODE" = "stealth" ]]; then
echo -e "${OKGREEN}====================================================================================${RESET}•x${OKGREEN}[`date +"%Y-%m-%d](%H:%M)"`${RESET}x•"
echo -e "$OKRED FETCHING GUA URLS $RESET"
echo -e "${OKGREEN}====================================================================================${RESET}•x${OKGREEN}[`date +"%Y-%m-%d](%H:%M)"`${RESET}x•"
gau -subs $TARGET | tee $LOOT_DIR/web/gua-$TARGET.txt 2> /dev/null | head -n 250
gau --subs $TARGET | tee $LOOT_DIR/web/gua-$TARGET.txt 2> /dev/null | head -n 250
fi
if [[ "$BLACKWIDOW" == "1" ]]; then
echo -e "${OKGREEN}====================================================================================${RESET}•x${OKGREEN}[`date +"%Y-%m-%d](%H:%M)"`${RESET}x•"
@ -387,7 +387,7 @@ if [[ "$MODE" = "stealth" ]]; then
echo -e "${OKGREEN}====================================================================================${RESET}•x${OKGREEN}[`date +"%Y-%m-%d](%H:%M)"`${RESET}x•"
echo -e "$OKRED FETCHING GUA URLS $RESET"
echo -e "${OKGREEN}====================================================================================${RESET}•x${OKGREEN}[`date +"%Y-%m-%d](%H:%M)"`${RESET}x•"
gau -subs $TARGET | tee $LOOT_DIR/web/gua-$TARGET.txt 2> /dev/null | head -n 250
gau --subs $TARGET | tee $LOOT_DIR/web/gua-$TARGET.txt 2> /dev/null | head -n 250
fi
if [[ "$BLACKWIDOW" == "1" ]]; then
echo -e "${OKGREEN}====================================================================================${RESET}•x${OKGREEN}[`date +"%Y-%m-%d](%H:%M)"`${RESET}x•"
@ -528,4 +528,4 @@ if [[ "$MODE" = "stealth" ]]; then
loot
fi
exit
fi
fi

View File

@ -130,8 +130,8 @@ if [[ "$MODE" = "webscan" ]]; then
echo -e "${OKGREEN}====================================================================================${RESET}•x${OKGREEN}[`date +"%Y-%m-%d](%H:%M)"`${RESET}x•"
echo -e "$OKRED RUNNING NUCLEI SCAN $RESET"
echo -e "${OKGREEN}====================================================================================${RESET}•x${OKGREEN}[`date +"%Y-%m-%d](%H:%M)"`${RESET}x•"
nuclei -silent -t /usr/share/sniper/plugins/nuclei-templates/ -c $THREADS -target http://$TARGET -o $LOOT_DIR/web/nuclei-http-${TARGET}-port80.txt
nuclei -silent -t /usr/share/sniper/plugins/nuclei-templates/ -c $THREADS -target https://$TARGET -o $LOOT_DIR/web/nuclei-https-${TARGET}-port443.txt
nuclei -silent -t /root/nuclei-templates/ -c $THREADS -target http://$TARGET -o $LOOT_DIR/web/nuclei-http-${TARGET}-port80.txt
nuclei -silent -t /root/nuclei-templates/ -c $THREADS -target https://$TARGET -o $LOOT_DIR/web/nuclei-https-${TARGET}-port443.txt
fi
if [[ "$SC0PE_VULNERABLITY_SCANNER" == "1" ]]; then
echo -e "${OKGREEN}====================================================================================${RESET}•x${OKGREEN}[`date +"%Y-%m-%d](%H:%M)"`${RESET}x•"
@ -162,4 +162,4 @@ if [[ "$MODE" = "webscan" ]]; then
fi
loot
exit
fi
fi

198
sniper
View File

@ -46,101 +46,105 @@ DISTRO=$(cat /etc/*-release | grep DISTRIB_ID= | cut -d'=' -f2)
function help {
logo
echo ""
echo -e "$OKBLUE[*]$RESET NORMAL MODE"
echo ' sniper -t <TARGET>'
echo ""
echo -e "$OKBLUE[*]$RESET SPECIFY CUSTOM CONFIG FILE"
echo ' sniper -c /full/path/to/sniper.conf -t <TARGET> -m <MODE> -w <WORKSPACE>'
echo ""
echo -e "$OKBLUE[*]$RESET NORMAL MODE + OSINT + RECON"
echo ' sniper -t <TARGET> -o -re'
echo ""
echo -e "$OKBLUE[*]$RESET STEALTH MODE + OSINT + RECON"
echo ' sniper -t <TARGET> -m stealth -o -re'
echo ""
echo -e "$OKBLUE[*]$RESET DISCOVER MODE"
echo ' sniper -t <CIDR> -m discover -w <WORSPACE_ALIAS>'
echo ""
echo -e "$OKBLUE[*]$RESET SCAN ONLY SPECIFIC PORT"
echo ' sniper -t <TARGET> -m port -p <portnum>'
echo ""
echo -e "$OKBLUE[*]$RESET FULLPORTONLY SCAN MODE"
echo ' sniper -t <TARGET> -fp'
echo ""
echo -e "$OKBLUE[*]$RESET WEB MODE - PORT 80 + 443 ONLY!"
echo ' sniper -t <TARGET> -m web'
echo ""
echo -e "$OKBLUE[*]$RESET HTTP WEB PORT MODE"
echo ' sniper -t <TARGET> -m webporthttp -p <port>'
echo ""
echo -e "$OKBLUE[*]$RESET HTTPS WEB PORT MODE"
echo ' sniper -t <TARGET> -m webporthttps -p <port>'
echo ""
echo -e "$OKBLUE[*]$RESET HTTP WEBSCAN MODE"
echo ' sniper -t <TARGET> -m webscan '
echo ""
echo -e "$OKBLUE[*]$RESET ENABLE BRUTEFORCE"
echo ' sniper -t <TARGET> -b'
echo ""
echo -e "$OKBLUE[*]$RESET AIRSTRIKE MODE"
echo ' sniper -f targets.txt -m airstrike'
echo ""
echo -e "$OKBLUE[*]$RESET NUKE MODE WITH TARGET LIST, BRUTEFORCE ENABLED, FULLPORTSCAN ENABLED, OSINT ENABLED, RECON ENABLED, WORKSPACE & LOOT ENABLED"
echo ' sniper -f targets.txt -m nuke -w <WORKSPACE_ALIAS>'
echo ""
echo -e "$OKBLUE[*]$RESET MASS PORT SCAN MODE"
echo ' sniper -f targets.txt -m massportscan -w <WORKSPACE_ALIAS>'
echo ""
echo -e "$OKBLUE[*]$RESET MASS WEB SCAN MODE"
echo ' sniper -f targets.txt -m massweb -w <WORKSPACE_ALIAS>'
echo ""
echo -e "$OKBLUE[*]$RESET MASS WEBSCAN SCAN MODE"
echo ' sniper -f targets.txt -m masswebscan -w <WORKSPACE_ALIAS>'
echo ""
echo -e "$OKBLUE[*]$RESET MASS VULN SCAN MODE"
echo ' sniper -f targets.txt -m massvulnscan -w <WORKSPACE_ALIAS>'
echo ""
echo -e "$OKBLUE[*]$RESET PORT SCAN MODE"
echo ' sniper -t <TARGET> -m port -p <PORT_NUM>'
echo ""
echo -e "$OKBLUE[*]$RESET LIST WORKSPACES"
echo ' sniper --list'
echo ""
echo -e "$OKBLUE[*]$RESET DELETE WORKSPACE"
echo ' sniper -w <WORKSPACE_ALIAS> -d'
echo ""
echo -e "$OKBLUE[*]$RESET DELETE HOST FROM WORKSPACE"
echo ' sniper -w <WORKSPACE_ALIAS> -t <TARGET> -dh'
echo ""
echo -e "$OKBLUE[*]$RESET DELETE TASKS FROM WORKSPACE"
echo ' sniper -w <WORKSPACE_ALIAS> -t <TARGET> -dt'
echo ""
echo -e "$OKBLUE[*]$RESET GET SNIPER SCAN STATUS"
echo ' sniper --status'
echo ""
echo -e "$OKBLUE[*]$RESET LOOT REIMPORT FUNCTION"
echo ' sniper -w <WORKSPACE_ALIAS> --reimport'
echo ""
echo -e "$OKBLUE[*]$RESET LOOT REIMPORTALL FUNCTION"
echo ' sniper -w <WORKSPACE_ALIAS> --reimportall'
echo ""
echo -e "$OKBLUE[*]$RESET LOOT REIMPORT FUNCTION"
echo ' sniper -w <WORKSPACE_ALIAS> --reload'
echo ""
echo -e "$OKBLUE[*]$RESET LOOT EXPORT FUNCTION"
echo ' sniper -w <WORKSPACE_ALIAS> --export'
echo ""
echo -e "$OKBLUE[*]$RESET SCHEDULED SCANS"
echo ' sniper -w <WORKSPACE_ALIAS> -s daily|weekly|monthly'
echo ""
echo -e "$OKBLUE[*]$RESET USE A CUSTOM CONFIG"
echo ' sniper -c /path/to/sniper.conf -t <TARGET> -w <WORKSPACE_ALIAS>'
echo ""
echo -e "$OKBLUE[*]$RESET UPDATE SNIPER"
echo ' sniper -u|--update'
echo ""
echo ""
local star
printf -v star "$OKBLUE[*]$RESET"
cat <<EOHELP
$star NORMAL MODE
sniper -t <TARGET>
$star SPECIFY CUSTOM CONFIG FILE
sniper -c /full/path/to/sniper.conf -t <TARGET> -m <MODE> -w <WORKSPACE>
$star NORMAL MODE + OSINT + RECON
sniper -t <TARGET> -o -re
$star STEALTH MODE + OSINT + RECON
sniper -t <TARGET> -m stealth -o -re
$star DISCOVER MODE
sniper -t <CIDR> -m discover -w <WORSPACE_ALIAS>
$star SCAN ONLY SPECIFIC PORT
sniper -t <TARGET> -m port -p <portnum>
$star FULLPORTONLY SCAN MODE
sniper -t <TARGET> -fp
$star WEB MODE - PORT 80 + 443 ONLY!
sniper -t <TARGET> -m web
$star HTTP WEB PORT MODE
sniper -t <TARGET> -m webporthttp -p <port>
$star HTTPS WEB PORT MODE
sniper -t <TARGET> -m webporthttps -p <port>
$star HTTP WEBSCAN MODE
sniper -t <TARGET> -m webscan
$star ENABLE BRUTEFORCE
sniper -t <TARGET> -b
$star AIRSTRIKE MODE
sniper -f targets.txt -m airstrike
$star NUKE MODE WITH TARGET LIST, BRUTEFORCE ENABLED, FULLPORTSCAN ENABLED, OSINT ENABLED, RECON ENABLED, WORKSPACE & LOOT ENABLED
sniper -f targets.txt -m nuke -w <WORKSPACE_ALIAS>
$star MASS PORT SCAN MODE
sniper -f targets.txt -m massportscan -w <WORKSPACE_ALIAS>
$star MASS WEB SCAN MODE
sniper -f targets.txt -m massweb -w <WORKSPACE_ALIAS>
$star MASS WEBSCAN SCAN MODE
sniper -f targets.txt -m masswebscan -w <WORKSPACE_ALIAS>
$star MASS VULN SCAN MODE
sniper -f targets.txt -m massvulnscan -w <WORKSPACE_ALIAS>
$star PORT SCAN MODE
sniper -t <TARGET> -m port -p <PORT_NUM>
$star LIST WORKSPACES
sniper --list
$star DELETE WORKSPACE
sniper -w <WORKSPACE_ALIAS> -d
$star DELETE HOST FROM WORKSPACE
sniper -w <WORKSPACE_ALIAS> -t <TARGET> -dh
$star DELETE TASKS FROM WORKSPACE
sniper -w <WORKSPACE_ALIAS> -t <TARGET> -dt
$star GET SNIPER SCAN STATUS
sniper --status
$star LOOT REIMPORT FUNCTION
sniper -w <WORKSPACE_ALIAS> --reimport
$star LOOT REIMPORTALL FUNCTION
sniper -w <WORKSPACE_ALIAS> --reimportall
$star LOOT REIMPORT FUNCTION
sniper -w <WORKSPACE_ALIAS> --reload
$star LOOT EXPORT FUNCTION
sniper -w <WORKSPACE_ALIAS> --export
$star SCHEDULED SCANS
sniper -w <WORKSPACE_ALIAS> -s daily|weekly|monthly
$star USE A CUSTOM CONFIG
sniper -c /path/to/sniper.conf -t <TARGET> -w <WORKSPACE_ALIAS>
$star UPDATE SNIPER
sniper -u|--update
EOHELP
exit
}
@ -460,7 +464,7 @@ function init {
service postgresql start 2> /dev/null > /dev/null
msfdb start 2> /dev/null > /dev/null
chown root /run/user/1000/gdm/Xauthority 2> /dev/null
LAST_USER=$(last | head -n 1 | awk '{print $1}')
LAST_USER=$(last 2> /dev/null | head -n 1 | awk '{print $1}')
sudo cp -a /home/$LAST_USER/.Xauthority /root/.Xauthority 2> /dev/null
sudo cp -a /root/.Xauthority /root/.Xauthority.bak 2> /dev/null
sudo cp -a /home/$USER/.Xauthority /root/.Xauthority 2> /dev/null
@ -590,7 +594,7 @@ function loot {
echo -e "$OKBLUE[$RESET${OKRED}i${RESET}$OKBLUE]$RESET $RESET"
echo -e "$OKBLUE[$RESET${OKRED}i${RESET}$OKBLUE]$RESET 💡 Don't miss out on important updates by using the Community version. $RESET"
echo -e "$OKBLUE[$RESET${OKRED}i${RESET}$OKBLUE]$RESET $RESET"
echo -e "$OKBLUE[$RESET${OKRED}i${RESET}$OKBLUE]$RESET 🔝 The latest Professional version ( ${OKRED}10.4 ${RESET}) offers unparalleled features, including: $RESET"
echo -e "$OKBLUE[$RESET${OKRED}i${RESET}$OKBLUE]$RESET 🔝 The latest Professional version ( ${OKRED}11.0 ${RESET}) offers unparalleled features, including: $RESET"
echo -e "$OKBLUE[$RESET${OKRED}i${RESET}$OKBLUE]$RESET $RESET"
echo -e "$OKBLUE[$RESET${OKRED}i${RESET}$OKBLUE]$RESET 💻 Sleek Web UI $RESET"
echo -e "$OKBLUE[$RESET${OKRED}i${RESET}$OKBLUE]$RESET 🛠️ Extensive add-ons $RESET"