Black-box service discovery, classification, and adaptive scan routing
Driftmux is a black-box auditing tool focused on service discovery, classification, and adaptive scan routing.
It starts by probing a target surface, identifies exposed services and technologies, and then routes each finding to the most suitable scanner. Instead of treating every host the same way, Driftmux adapts its scanning workflow based on what it discovers.
For example:
- generic network discovery with Nmap
- web and exposed service vulnerability checks with Nuclei
- WordPress-specific assessment with Plecost
Driftmux is designed as an orchestrator, not as a monolithic scanner.
Features
- Black-box service discovery
- Technology-aware scan routing
- Structured output for automation and CI
- Multiple output formats
- Modular scanner integration
- Lightweight CLI workflow
- Extensible architecture for new service detectors and scanners
Why driftmux?
Many security tools are powerful but noisy. driftmux focuses on orchestration and correlation: it uses existing tools, normalizes their output and decides what should run next.
| Feature | driftmux | Raw Nmap | Raw Nuclei | Full scanners |
|---|---|---|---|---|
| Service discovery | Yes | Yes | No | Yes |
| Version/CPE parsing | Yes | Yes | No | Yes |
| Vulnerability enrichment | Yes | No | Template-based | Yes |
| Targeted Nuclei execution | Yes | No | Manual | Varies |
| Scan planning | Yes | No | No | Varies |
| Lower-noise profiles | Yes | Manual | Manual | Varies |
| Structured final report | Yes | XML/text | JSONL/text | Varies |
| Lightweight and scriptable | Yes | Yes | Yes | Often heavier |
driftmux is not a replacement for Nmap, Nuclei or dedicated scanners. It is a thin coordination layer that makes them easier to combine.
How it works
Driftmux follows a simple pipeline:
- Discover exposed ports and services
- Classify detected applications and technologies
- Route targets to specialized scanners
- Aggregate findings into a common data model
- Render results as console output, JSON, CSV, or Markdown
Example routing logic:
- WordPress detected → Plecost
- HTTP/HTTPS services detected → Nuclei
- Generic open ports detected → Nmap fingerprints
Installation
Requirements
- Python 3.10+
nmapnucleiplecost
Clone the repository
git clone https://github.com/<your-user>/driftmux.git
cd driftmux
Install the Python package
python3 -m venv .venv
source .venv/bin/activate
pip install -e .
External tools
Depending on the features you use, install Nmap:
sudo apt install nmap
Nuclei and Plecost are optional, but required for their respective checks.
go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
pip install plecost
Optional OpenStack support
OpenStack auditing requires openstacksdk:
pip install openstacksdk
Usage
Basic scan:
driftmux --host example.org
Scan a specific IP:
driftmux --host 205.87.65.183
Scan known ports:
driftmux --host example.org --ports 80,443,8443
Run with NVD enrichment:
driftmux --host example.org \
--vuln-backend nvd \
--min-cvss 7.0
Run a fast profile:
driftmux --host example.org --profile fast
Run a passive profile:
driftmux --host example.org --profile passive
OpenStack Neutron security group audit
Driftmux can audit OpenStack Neutron security groups to detect public exposure of critical ports without accessing the guest virtual machines.
This mode queries the OpenStack API and analyses Neutron security group rules. It is useful for cloud administrators who want to detect risky network exposure at the OpenStack layer.
Example:
driftmux --openstack-sg-audit --os-cloud admin --format markdown
## Example output
```text
$ driftmux --host 205.87.65.183 --profile passive --vuln-backend nvd --min-cvss 7.0
[205.87.65.183]
Services: 1 | Findings: 4 | Errors: 1
- 22/tcp ssh OpenSSH 9.6p1 Ubuntu 3ubuntu13.16 [ssh]
* CRITICAL nvd: CVE-2008-3844 affects OpenSSH
* HIGH nvd: CVE-2024-6387 affects OpenSSH
* HIGH nvd: CVE-2026-35385 affects OpenSSH
* HIGH nvd: CVE-2023-51767 affects OpenSSH
Saved report to reports/driftmux-report.json
Scan profiles
| Profile | Purpose | Active checks |
|---|---|---|
passive |
Conservative discovery and enrichment | No |
passive + NVD |
Conservative discovery and enrichment | Yes |
fast |
Practical day-to-day checks | Limited |
deep |
Broader authorized assessment | More extensive |
Use passive for low-noise review, fast for regular checks and deep only when you have explicit authorization for a more complete assessment.
Roadmap
Planned or possible improvements:
- OS detection support from Nmap XML;
- clearer handling of
tcpwrappedservices; - improved Nuclei target planning;
- richer JSON and HTML reports;
- optional SARIF export;
- better test coverage for planners and scanners.
Disclaimer
driftmux is provided for defensive and authorized security work only. You are responsible for complying with all applicable laws, regulations and rules of engagement.
Metadata
Release files for driftmux 1.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| driftmux-1.1.1.tar.gz | 37.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| driftmux-1.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 74.5 kB
Release files / driftmux-1.1.1.tar.gz
| Download URL | driftmux-1.1.1.tar.gz |
|---|---|
| Size | 37.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
c88e25095cfb56b8a27b44332306b63b52200a3dd8f2c4e94d853fb3662ff415
|
|
BLAKE2b-256 checksum How to use checksums |
e5663e821acf5d0568868fee7925099569b9a3616457031ebaea2bfb7e52ee23
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on May 19, 2026.
Transparency logRelease files / driftmux-1.1.1-py3-none-any.whl
| Download URL | driftmux-1.1.1-py3-none-any.whl |
|---|---|
| Size | 37.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
cd3cb46d1180986381229cff382e8abcecf782bdcfc404b25192fb028b3a6fb1
|
|
BLAKE2b-256 checksum How to use checksums |
eaddea1750ccb5a7752317de8cfb457044e52f65077f59968e3673200fd28e56
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on May 19, 2026.
Transparency log