25 tools, one platform.
ScanRub orchestrates the best open-source security tools into one adaptive pipeline. No CLI setup, no dependency hell, no version pinning - we handle it all.
Reconnaissance
Fast passive subdomain enumeration using dozens of sources
Alternative subdomain discovery for cross-verification
DNS enumeration + certificate transparency logs
Fast port scanning pre-pass before deeper probing
Subdomain permutation from already-discovered names
Fast HTTP prober - status, tech, tls, hashes
Next-generation crawling & spider framework
Historical URLs from the Wayback Machine
Get all URLs from AlienVault OTX, Wayback, Common Crawl
Fingerprinting & Analysis
Web fingerprinting with 1,800+ plugins
Identify WAFs to inform testing strategy
Discover hidden HTTP parameters
Vulnerability Scanning
Template-based scanner with thousands of community templates
Advanced XSS scanner with context-aware payload generation
SQL injection detection and exploitation
Web server misconfiguration and known-vuln scanner
Fast web fuzzer for directories, params, and files
Scan Git repos for exposed secrets
High-entropy secret detection in JS bundles
TLS & Infrastructure
Port scanning and service detection
CMS-specific vulnerability detection
Cloud & Credentials
Find and check permissions on exposed cloud storage buckets
Enumerate exposed resources across AWS, Azure, and GCP
Password hash cracking for credential-strength checks
Browser Automation
Headless browser for DOM scanning, screenshots, session testing
Alerts and integrations
Real-time alerts to any channel via incoming webhook
Post scan completion + critical findings to Discord
Digest emails and instant alerts on critical findings
Generic outbound HTTP webhooks for custom integrations
Auto-create Jira tickets for high-severity findings
Sync findings to Linear as issues
Run scans in CI/CD, fail builds on critical findings
Native integration for GitLab pipelines
Why orchestration matters
Every tool listed here is powerful on its own. Running them individually is a full-time job - you need to install each, keep them updated, chain the output correctly, deduplicate findings, and interpret the results.
ScanRub runs them in the right order, feeds each tool's output into the next, validates findings with AI, and produces one clean report. It's the difference between having a toolbox and having a workshop.
Skip the setup. Start scanning.
Every tool above, already installed and wired together - you just point it at a target.