scanrub
Platform

A pentester's workflow, fully automated.

ScanRub reasons about each target - mapping, planning, testing, and validating - then explains what it found and why it matters.

scanrub scan target.io
$ scanrub scan target.io --mode full
● recon - 23 subdomains, 14 live hosts, Express + Firebase
▸ planning - sequenced 20 modules (nuclei, ssrf, idor, xss…)
‹thinking› admin.target.io has no auth - testing defaults…
⚠ HIGH - default credentials accepted on admin panel
▸ validation gate - 6 candidates → 4 confirmed, 2 reclassified
✓ report ready - 1 critical, 3 high · quality 92/100
The pipeline

Five stages, fully automated

01
Reconnaissance

Subdomain enumeration, live-host probing, tech fingerprinting, and URL discovery build a full map of the attack surface in a few minutes.

02
Planning

A tool sequencer ranks 25 modules by the detected stack and pattern intelligence from disclosed reports - highest-value checks first.

03
Adaptive testing

Multi-pass testing that adapts based on results - selecting tools, observing output, and adjusting the approach like a human pentester, narrating as it goes.

04
Validation gate

Every candidate finding is checked by an LLM that reclassifies severity and removes false positives before it reaches you.

05
Report

Validated findings are assembled with evidence, impact, and remediation - plus a transparent scan-quality score.

Architecture

How data flows through the system

Each stage produces artifacts that feed the next - like a compiler pipeline for security.

Target DomainRecon EnginePlanningAdaptive TestingAI ValidationReportparallel
Coverage

What ScanRub tests for

Detection spans the full spectrum of web, API, infrastructure, and business-logic vulnerabilities.

Injection
SQL injection (error, boolean, time-based)
Command injection
SSTI (Server-Side Template Injection)
LDAP / XPath / NoSQL injection
Authentication & Authorization
IDOR / BOLA (Broken Object Auth)
JWT weaknesses (alg=none, weak secret)
OAuth misconfigurations
Broken access control
Session fixation & hijacking
Server-Side
Request smuggling
Insecure deserialization
Client-Side
CORS misconfiguration
CSRF (Cross-Site Request Forgery)
Clickjacking
Open redirect
Infrastructure
Exposed admin panels
Default credentials
Missing security headers
Weak TLS/SSL configuration
Publicly exposed cloud storage
Information Disclosure
.env / .git leaks
API key exposure in JS
Sourcemap leaks
Directory listing
Verbose error messages
2-5 min
To full attack-surface map
25
Integrated security tools
21
Vulnerability classes
Real-time
Streaming scan narrative

See the pipeline in action

Run a real scan against a target you control. Free - no card required.

Weekly security research

New vulnerability playbooks, tool updates, and bug bounty insights - delivered to your inbox. No spam.

Unsubscribe anytime. We respect your inbox.
Press ⌘K to search×