scanrub
Platform

A pentester's workflow, fully automated.

ScanRub reasons about each target - mapping, planning, testing, and validating - then explains what it found and why it matters.

scanrub scan target.io
$ scanrub scan target.io --mode full
● recon - 23 subdomains, 14 live hosts, Express + Firebase
▸ planning - sequenced 20 modules (nuclei, ssrf, idor, xss…)
‹thinking› admin.target.io has no auth - testing defaults…
⚠ HIGH - default credentials accepted on admin panel
▸ validation gate - 6 candidates → 4 confirmed, 2 reclassified
✓ report ready - 1 critical, 3 high · quality 92/100
The pipeline

Five stages, fully automated

01
Reconnaissance

Subdomain enumeration, live-host probing, tech fingerprinting, and URL discovery build a full map of the attack surface in a few minutes.

02
Planning

A tool sequencer ranks 25 modules by the detected stack and pattern intelligence from disclosed reports - highest-value checks first.

03
Adaptive testing

Multi-pass testing that adapts based on results - selecting tools, observing output, and adjusting the approach like a human pentester, narrating as it goes.

04
Validation gate

Every candidate finding is checked by an LLM that reclassifies severity and removes false positives before it reaches you.

05
Report

Validated findings are assembled with evidence, impact, and remediation - plus a transparent scan-quality score.

Architecture

How data flows through the system

Each stage produces artifacts that feed the next - like a compiler pipeline for security.

Target DomainRecon EnginePlanningAdaptive TestingAI ValidationReportparallel
Coverage

What ScanRub tests for

Detection spans the full spectrum of web, API, infrastructure, and business-logic vulnerabilities.

Injection
▸SQL injection (error, boolean, time-based)
▸Command injection
▸SSTI (Server-Side Template Injection)
▸LDAP / XPath / NoSQL injection
Authentication & Authorization
▸IDOR / BOLA (Broken Object Auth)
▸JWT weaknesses (alg=none, weak secret)
▸OAuth misconfigurations
▸Broken access control
▸Session fixation & hijacking
Server-Side
▸Request smuggling
▸Insecure deserialization
Client-Side
▸CORS misconfiguration
▸CSRF (Cross-Site Request Forgery)
▸Clickjacking
▸Open redirect
Infrastructure
▸Exposed admin panels
▸Default credentials
▸Missing security headers
▸Weak TLS/SSL configuration
▸Publicly exposed cloud storage
Information Disclosure
▸.env / .git leaks
▸API key exposure in JS
▸Sourcemap leaks
▸Directory listing
▸Verbose error messages
2-5 min
To full attack-surface map
25
Integrated security tools
21
Vulnerability classes
Real-time
Streaming scan narrative

See the pipeline in action

Run a real scan against a target you control. Free - no card required.

Weekly security research

New vulnerability playbooks, tool updates, and bug bounty insights - delivered to your inbox. No spam.

Unsubscribe anytime. We respect your inbox.
Press ⌘K to search×