redveil
web vulnerability scanner. find vulns, validate safely, get a report you can actually send to a dev team.
⚠️ DANGER ZONE — DWYOR (Do With Your Own Risk)
READ THIS BEFORE USING REDVEIL.
Redveil is intended for authorized security testing only.
- ✅ You own the system, OR
- ✅ You have explicit written permission to test it
If neither applies: DO NOT USE THIS TOOL.
The authors are not responsible for misuse, damage, data loss, or unauthorized activity resulting from the use of this software.
You are responsible for legal and ethical compliance.
See DWYOR.md for the full statement.
⚠️ Installation requires a virtual environment or
pipx.Modern Linux distros (Debian 12+, Ubuntu 23.04+, Fedora, etc.) enforce PEP 668 and block system-wide
pip installwith the errorerror: externally-managed-environment. Use one of these:# Option 1: pipx (recommended, installs to isolated env, command globally available) pipx install redveil # Option 2: python venv python3 -m venv ~/redveil-env && source ~/redveil-env/bin/activate pip install redveilSee USER_GUIDE.md#install for distro-specific commands (apt, dnf, pacman, zypper, brew, etc.).
$ pip install redveil
$ redveil scan https://target.example --scope scope.yaml
$ redveil list-checks
install
Don't use bare pip install redveil on modern Linux — it'll fail with
error: externally-managed-environment (PEP 668). Use one of:
# pipx (easiest — installs to isolated env, command globally available)
pipx install redveil
# or python venv
python3 -m venv ~/redveil-env
source ~/redveil-env/bin/activate
pip install redveil
distro-specific:
- Debian/Ubuntu:
sudo apt install pipx && pipx install redveil - Fedora/RHEL:
sudo dnf install python3-pipx && pipx install redveil - Arch/Manjaro:
sudo pacman -S python-pipx && pipx install redveil - openSUSE:
sudo zypper install python3-pipx && pipx install redveil - macOS:
brew install pipx && pipx install redveil - Windows:
python -m venv redveil-env && .\redveil-env\Scripts\Activate.ps1 && pip install redveil
or from source (for development):
git clone https://github.com/FitzyPrjkt/Redveil
cd redveil
python3.12 -m venv .venv
source .venv/bin/activate
pip install -e ".[dev]"
requires python 3.12+.
quick start
# 1. write a scope file
cat > scope.yaml <<'EOF'
target:
base_url: https://staging.example.com
scope:
allowed_hosts:
- staging.example.com
allowed_paths:
- /api/*
- /account/*
limits:
requests_per_second: 2
max_requests: 500
authorization:
active_testing: false
acknowledged_safety_terms: false
profile: passive
EOF
# 2. scan
redveil scan https://staging.example.com --scope scope.yaml
# 3. results
ls reports/staging.example.com/
cat reports/staging.example.com/summary.md
open reports/staging.example.com/report.html
what you get
- 17 built-in checks — security headers, CORS, info disclosure, HTTP methods, open redirect indicators, source map exposure, XSS (canary reflection), SQLi (time-based), SSRF (OOB), command injection (time-based), path traversal (canary), BOLA/IDOR, BFLA, GraphQL, mass assignment, session/cookie config, subdomain discovery
- multi-format reports — markdown per finding, JSON for tooling, self-contained HTML
- strict scope enforcement — host + path allowlist, redirect chain validation, destructive path heuristic. plugins cannot bypass it
- multi-principal auth for BOLA testing — define Account A + Account B in scope, redveil compares what each can see
- evidence sanitization — JWTs, AWS keys, GitHub tokens, credit cards, cookies, emails all redacted before report
- local lab at
tests/lab/— a Flask app with 17 deliberately vulnerable endpoints for testing without hitting the internet
safety
redveil is a defensive tool. the active checks (XSS, SQLi, SSRF, command injection, path traversal) use bounded non-destructive payloads:
- XSS: alphanumeric canary strings. no
<script>, no execution - SQLi/command injection: time-based delay only (
sleep 3). no data extraction - SSRF: OOB callback to operator's own domain. no internal IP probing
- path traversal: unique canary filenames. no real file reads
runtime assertions in each check verify these constraints on every import. the test suite has explicit safety tests for every check.
you are responsible for authorization. redveil includes guards but they only matter if you actually have permission to test the target.
see SECURITY.md for the full safety model and how to report issues.
CLI
$ redveil --help # show all commands
$ redveil scan --help # scan command flags
$ redveil check --help # single-check flags
$ redveil list-checks # list 17 registered check plugins
$ redveil findings <dir> # show summary of a saved report
$ redveil report <dir> # re-render a report
redveil scan <url>
Run a full scan against a target. Flags:
| Flag | Description |
|---|---|
<url> |
Required. Target base URL, e.g. https://staging.example.com |
-s, --scope FILE |
Path to a scope YAML file. If omitted, a minimal single-host scope is built. |
-p, --profile PROFILE |
Safety profile: passive (default), low_impact, or active |
--max-requests N |
Hard cap on total requests (default 500) |
--rps N |
Requests per second (default 2.0) |
--active |
Enable ACTIVE checks. Requires acknowledged_safety_terms: true in scope. |
-g, --gate-mode MODE |
ActionGate mode: interactive, non_interactive (default), strict |
--allow-destructive |
Explicit opt-in to unlock destructive actions (each still needs per-action typed confirm) |
--max-destructive-level L |
Operator's ceiling. Short form L1-L6 or integer. Default 2 (data_modification). |
-o, --output DIR |
Output directory for reports (default reports/) |
redveil check <plugin-id> <url>
Run a single check plugin. Useful for targeted testing.
redveil check cors-policy https://staging.example.com
redveil check xss-reflected https://target.com --scope scope.yaml
redveil list-checks
List all 17 registered check plugins with their safety profile:
bfla BFLA / Function-Level Authorization Check
bola-idor BOLA / IDOR Check
command-injection Command Injection Check (Time-Based)
cors-policy CORS Policy Check
graphql GraphQL Check
http-methods HTTP Methods Check
information-disclosure Information Disclosure Check
mass-assignment Mass Assignment Check
open-redirect-indicator Open Redirect Indicator
path-traversal Path Traversal Check
security-headers Security Headers Check
session-cookie Session and Cookie Configuration Check
source-map-exposure Source Map Exposure Check
sqli-time-based Time-Based Blind SQL Injection Check
ssrf Server-Side Request Forgery Check
subdomain-finder Subdomain Finder
xss-reflected Reflected XSS Check
redveil findings <report-dir>
Print a summary of a previously-saved report.
redveil findings reports/staging.example.com/
# Output:
# 12 findings
# - [HIGH ] Missing X-Frame-Options Header
# - [MEDIUM ] Missing Content-Security-Policy Header
# ...
redveil report <report-dir>
Re-render a report from existing findings.json (in case you want to
regenerate the markdown/HTML after editing the JSON).
Safety profiles
passive(default) — only observation, no payload injectionlow_impact— safe probes (CORS preflight, method check, harmless reflection)active— requiresactive_testing: truein scope. Issues canary payloads, time-based delays, OOB callbacks, etc.
writing checks
a check is a Check subclass:
from redveil.plugins.base import Check, CheckCategory, CheckMeta, ...
class MyCheck(Check):
meta = CheckMeta(
id="my-check",
name="My Check",
category=CheckCategory.HEADERS,
safety_profile=SafetyProfile.PASSIVE,
)
async def discover(self, ctx): ...
async def validate(self, ctx, candidate): ...
async def collect_evidence(self, candidate): ...
async def assess(self, candidate): ...
register in pyproject.toml:
[project.entry-points."redveil.checks"]
my-check = "my_pkg.checks:MyCheck"
see CONTRIBUTING.md for the full plugin spec.
files
USER_GUIDE.md— installation, configuration, CLI reference, output interpretationCONTRIBUTING.md— how to add checksPUBLISH.md— how to publish a new releaseSECURITY.md— safety model, how to report issuesCHANGELOG.md— release notesdocs/architecture.md— internal designexamples/— scope files for common scenariostests/lab/— vulnerable Flask app for local testing
status
17 checks, ~1090 tests passing, 0 known safety violations. actively used against staging environments. the framework ships with curated, tested-safe payloads; destructive actions require per-action typed confirmation (no batch approval) and an explicit allow_destructive: true unlock in config.
what makes redveil different from sqlmap / nikto / burp scanner
| Aspect | traditional scanner | redveil |
|---|---|---|
| Payload | signature match (e.g. ' OR 1=1 --) |
time-based delay, OOB callback, canary reflection |
| Action | match pattern → flag | model target → hypothesis → controlled test → multi-signal correlation → confidence-scored finding |
| Confidence | hardcoded HIGH or LOW | computed: oracle × (1 + log2(distinct_dims)) × weight − env_penalty − uncertainty |
| Reproducibility | not verified | ReplayRecipe + ReplayEngine runs N samples |
| FP reduction | none | negative testing, flakiness detection, env awareness, uncertainty propagation |
| Root cause | one finding per endpoint | clustered across endpoints with same root cause |
| Destructive | implicit (run anyway) | blocked by default. tiered confirmation L1-L6. no Y-to-all. |
see USER_GUIDE.md and docs/architecture.md for details.
license
MIT. see LICENSE.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file redveil-1.9.4.tar.gz.
File metadata
- Download URL: redveil-1.9.4.tar.gz
- Upload date:
- Size: 303.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.13.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
eb8c3962476a142023da496bf10b8f92fdb409b0b521819a6a6eb92c9c410fec
|
|
| MD5 |
2406ad708955220b311895fba2e3a96b
|
|
| BLAKE2b-256 |
5be91db6545fe5298bf57cbec032c9e4b26059602784853b13b16646be87b4e0
|
File details
Details for the file redveil-1.9.4-py3-none-any.whl.
File metadata
- Download URL: redveil-1.9.4-py3-none-any.whl
- Upload date:
- Size: 245.1 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.13.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
b3894444f028e1dacc2745222542d430b6465f6a4e8b1e0c14bf5a2e666d9976
|
|
| MD5 |
21d997a086a619a87fbccdd2b45d3652
|
|
| BLAKE2b-256 |
bb1a02554735c071201b3fd0f1e5156573dae4c452c15fcfa0802ed840ce3f13
|