ScanReview

Enumeration Tools

Tools that inspect reachable services, ports, directories, and infrastructure details.

Abstract external attack surface management visualization

Enumeration Tools

Open-source enumeration tools for port scanning, service discovery, and vulnerability assessment — inspect reachable services, ports, and infrastructure. Understand exactly what.s running and how it.s configured.

Port and service enumeration results

Port & Service Scanning

Discover open ports, running services, and operating system details across networks and individual hosts.

Nmap

The industry standard — port scanning, service/OS detection, scriptable with NSE for deep enumeration.

GitHub →

Masscan

Internet-scale port scanner — scans the entire IPv4 internet in under 6 minutes with 10M packets/sec.

GitHub →

RustScan

Blazingly fast port scanner — scans all 65,535 ports in seconds, auto-pipes results into Nmap for service detection.

GitHub →

Naabu

Fast SYN port scanner by ProjectDiscovery — high concurrency with minimal privileges required.

GitHub →
Web directory and content enumeration workflow

Web Content & Directory Enumeration

Brute-force and fuzz directories, files, API endpoints, and virtual hosts on web servers.

Dirsearch

Classic web path scanner — brute-forces directories and files with multi-threading and proxy support.

GitHub →

Gobuster

Fast Go-based directory, DNS, and VHOST brute-forcing — minimal setup, maximum speed.

GitHub →

Feroxbuster

Recursive content discovery written in Rust — auto-detects when to recurse, scans fast and smart.

GitHub →

Ffuf

Fuzz Faster U Fool — high-speed web fuzzer for directories, VHOSTs, headers, POST data, and parameters.

GitHub →

Wfuzz

Flexible web brute-forcing tool — fuzz URLs, headers, POST data, cookies, and authentication.

GitHub →

Dirb

Simple, reliable web content scanner — ships with well-curated wordlists for common paths and files.

GitHub →
High-speed internet-scale service scanning

Service & Web Fingerprinting

Identify server software, versions, configurations, and technology stacks without touching the application layer.

Nikto

Veteran web server scanner — checks for 6,700+ dangerous files, outdated versions, and server misconfigs.

GitHub →

WhatWeb

Website fingerprinting — identifies CMS, JS frameworks, analytics platforms, CDNs, and server software.

GitHub →

Wappalyzer

Technology profiler — detects 1,500+ web technologies including analytics, frameworks, and server stacks.

GitHub →

Web Crawling & Spidering

Automatically map website structure, discover endpoints, forms, and hidden resources through recursive crawling.

Katana

Next-gen crawling and spidering framework by ProjectDiscovery — passive and active modes with JS parsing.

GitHub →

Gospider

Fast web spider written in Go — extracts links, JS files, forms, and endpoints from parsed pages.

GitHub →

Hakrawler

Simple, fast web crawler designed for endpoint and asset discovery — plain links, JS, subdomains, and forms.

GitHub →

CMS & Web Application Scanning

Specialized scanners for content management systems — identify versions, plugins, themes, users, and known vulnerabilities.

WPScan

WordPress security scanner — enumerates plugins, themes, users, config backups, and known vulnerabilities.

GitHub →

JoomScan

OWASP Joomla vulnerability scanner — enumerates components, modules, and checks for known CVEs.

GitHub →

Droopescan

Plugin-based scanner for Drupal, SilverStripe, and Moodle — enumerates themes, modules, and versions.

GitHub →

Windows & SMB Enumeration

Enumerate Windows hosts, SMB shares, users, groups, and domain information across Windows networks.

Enum4linux-ng

Next-gen SMB enumeration — extracts users, shares, groups, OS info, and password policies from Windows/Samba.

GitHub →

SMBMap

SMB share enumeration — lists shares, checks permissions, searches contents, and executes remote commands.

GitHub →

NetExec

Swiss army knife for network enumeration — SMB, WMI, MSSQL, RDP, SSH, and more with modular architecture.

GitHub →

SNMP & Network Services

Query and enumerate SNMP-enabled devices, routers, printers, and other network infrastructure services.

SNMPWalk

Standard SNMP enumeration tool — walks the entire MIB tree to extract system info, running processes, and network config.

GitHub →

onesixtyone

Fast SNMP community string scanner — efficiently brute-forces SNMP community names across large networks.

GitHub →