Skip to main content

stackscan

Full web stack, infrastructure, DNS, port, subdomain and CVE analyzer — one command, one colorized report.

License Python Platform black ruff pyright Stars Last Commit


stackscan takes one or more targets, fetches them over HTTP(S), and prints a single colorized panel report covering the technology stack, the edge and network infrastructure, full DNS, IP ownership, open ports, subdomains, and known CVEs. A signature database and a compressed CVE database ship inside the package, so it works out of the box.

Every default pass only reads what a server voluntarily returns. The active passes — --ports and --default-creds — open connections the target did not solicit and are opt-in. Only scan systems you are authorized to test.


📦 Installation

pip install "stackscan"

# optional extra
pip install "stackscan[geo]"   # offline IP geolocation via geoip2 + a MaxMind .mmdb

nmap is used for port scans when present; without it a pure-Python scanner is used automatically.

Inside the reekeer shell

stackscan is also a reekeer plugin, mounted at /tools/recon/stackscan (alias ss):

reekeer exec /plugins install reekeer/stackscan

Hosted there it drops the banner and the window title and hands the scan back as data for reekeer to render in the shell's own tables, so it reads as a command of the shell rather than a script being shelled out to. Every flag behaves the same, and standalone (pip, uvx stackscan) is unchanged.

In reekeer's window the scan also gets a form. stackscan says which of its flags are worth a control — the targets, the four switches that decide how deep a scan goes, and the bounds worth changing when one is too slow — and reekeer draws those. The rest are not hidden: the argument line under the form still takes anything argparse takes, --help included.


✨ Features

🧩 Stack & infrastructure

  • Technologies — 7.5k-technology bundled sigdb, classified by category.
  • Edge — CDN, WAF, reverse proxy and server software from response metadata.
  • TLS — certificate issuer, SANs, validity window, protocol and cipher.

🌐 Network & DNS

  • Full DNS — A/AAAA, reverse DNS, CNAME, MX, NS, TXT, SOA, CAA.
  • IP intelligence — hosting org / ISP / ASN / location for non-CDN origins via ipwho.is.
  • Subdomains — AXFR + the popularity-ranked SecLists DNS list over a fast async resolver pool, with wildcard filtering + TLS SANs.

🔎 Ports & vulnerabilities

  • Ports — nmap -sV via python-nmap, or a built-in async connect scan with banner/HTTP/RTSP fingerprinting.
  • CVEs — offline NVD-sourced database with per-match confidence % and CVSS severity; --cve-online adds a live lookup.
  • Default creds / open devices — a bounded, authorized-only check for cameras / routers / panels reachable without a password or with factory-default logins (SecLists default-credentials).

🎛 Output

  • Colorized per-target panels, a --compact table, or --json.
  • Every run prints the banner and the total scan time.

🚀 Usage

# Scan one or more targets
stackscan example.com https://another.example

# Everything at once: ports, subdomains, online CVEs, IP info, default-cred check
stackscan --full example.com

# Individual deep passes
stackscan --ports --subdomains example.com
stackscan --cve-online example.com

# Speed / coverage knobs
stackscan --full --workers 500 --subdomain-limit 10000 example.com
stackscan --full --site-limit 20 --workers 200 example.com

# JSON (full detail, includes timing) or a compact table
stackscan --json example.com
stackscan --compact a.example b.example

Bare hostnames are normalized to https://.

⚡ Benchmark

Below are performance benchmarks conducted on two production targets using different scanning options (tested on Python 3.12 / macOS).

1. github.com Scan Performance

Scan Mode Command / Arguments Execution Time (s) Execution Time (ms) Speed vs. Default (Baseline)
Minimal Scan --no-dns --no-tls --no-geo --no-ip-info --no-cve --no-probe 0.69s 690 ms +86.09% faster (7.2x)
Default Scan None (baseline) 4.96s 4960 ms Baseline
Port Scan --ports 6.10s 6100 ms -22.98% slower
Full Active Scan --full 64.99s 64990 ms -1210.28% slower

2. kmtn.ru Deep Scan Performance

Scan Mode Command / Arguments Execution Time Findings
Full Active Scan --full --subdomain-limit 50 --site-limit 20 1m 8.4s (68s) 269 CVE(s), 64 critical, 29 port(s), 41 subdomain(s), 11 site(s)
Fast Full Scan --full --subdomain-limit 50 --workers 400 --site-limit 20 ~32s 247 CVE(s), 63 critical, 15 port(s), 41 subdomain(s), 9 site(s)

3. microsoft.com Scan Performance

Scan Mode Command / Arguments Execution Time (s) Execution Time (ms) Speed vs. Default (Baseline)
Minimal Scan --no-dns --no-tls --no-geo --no-ip-info --no-cve --no-probe 0.98s 980 ms +83.39% faster (6.0x)
Default Scan None (baseline) 5.90s 5900 ms Baseline
Port Scan --ports 6.95s 6950 ms -17.80% slower

🧭 Options

Option Default Description
--full off Enable ports, subdomains, online CVEs, IP info, default-cred check.
--ports / --no-nmap off Active port scan (nmap, else Python) / force the Python scanner.
--subdomains off Enumerate subdomains (AXFR + wordlist + TLS SANs).
--subdomain-limit 5000 Max ranked labels to resolve (0 = full list).
--site-limit 50 Max derived sites to analyze from discovered open ports (0 = unlimited).
--cve-min-confidence 50 Hide CVE matches with confidence below N (0 shows all).
--default-creds off Bounded default-credential / open-device check (prompts before brute-forcing).
--full-auto off Auto-accept every brute prompt on discovered devices (enables default-cred checks).
--cred-limit 50 Max default-credential pairs per device (0 = full SecLists list).
--cve-online off Also query NVD live for detected products.
--parse-social off Extract social media and contact links from the page.
--workers 350 Parallel workers for ports/subdomains/creds.
--concurrency 10 Concurrent targets.
--sigdb / --no-builtin / --no-sources – Signature database selection.
--geoip-db – MaxMind .mmdb for offline IP geolocation.
--no-dns / --no-tls / --no-geo / --no-probe / --no-cve / --no-ip-info off Skip a pass.
--json / --compact / --no-banner / --show-empty off Output control.
-f, --file / --timeout / --port-timeout / --version – Misc.

⚙️ Configuration

  • Signature sources: stackscan sigdb add|list|update|remove … (recorded under $XDG_CONFIG_HOME/stackscan/).
  • Downloaded wordlists (SecLists DNS list, default-credential list): cached under ~/.local/stackscan/db/.
  • Refresh the CVE database: python scripts/build_cve_db.py.

🛰 Runner mode

stackscan --runner turns the scanner into a worker for a StackScan panel: it claims jobs (POST /api/jobs/claim), fingerprints each target with the normal engine, and posts the results back (POST /api/results). It needs nothing but network access to the panel — no database, no Redis, no shared filesystem.

STACKSCAN_BACKEND_URL=https://panel.example STACKSCAN_WORKER_TOKEN=… \
  stackscan --runner
Variable Default What it is
STACKSCAN_BACKEND_URL http://localhost:8787 Panel base URL
STACKSCAN_WORKER_TOKEN — Shared worker token, sent as X-Worker-Token
STACKSCAN_RUNNER_ID runner-<host>-<pid> Stable id for this runner
STACKSCAN_RUNNER_BATCH 5 Jobs claimed per cycle
STACKSCAN_RUNNER_IDLE 5 Seconds to wait when the queue is empty
STACKSCAN_RUNNER — Truthy value selects runner mode without the flag

Every one has a flag (--backend, --worker-token, --runner-id, --batch, --sigdb, --user-agent), and --once runs a single claim/scan/report cycle, which is what you want in a cron job or a smoke test. The runner profile is deliberately lean — DNS, TLS, geo and IP info, no ports, CVEs or brute passes — because it is meant for volume rather than depth.

Packaged for it:

docker build -t stackscan:latest .
docker run --rm -e STACKSCAN_BACKEND_URL=http://panel:8787 \
  -e STACKSCAN_WORKER_TOKEN=… stackscan:latest

Runner mode is refused inside the reekeer shell: it is a loop that runs until it is killed, and a shell command that never answers is not a command.


🚀 Smart Scan Pipeline

The Smart Scan engine performs multiple analysis stages to collect infrastructure, technology, and security information about the target before generating the final report.

flowchart TD

    A["🎯 Target<br/>Domain / URL"]

    subgraph S1["1. Target Resolution"]
        B["Normalize Target"]
        C["DNS Resolution"]
        C1["IPv4 / IPv6"]
        C2["DNS Records<br/>MX • NS • TXT • CNAME • SOA • CAA"]
        C3["Reverse PTR"]
        B --> C
        C --> C1
        C --> C2
        C --> C3
    end

    subgraph S2["2. HTTP Discovery"]
        D["HTTPS Request"]
        D1{"TLS Error?"}
        D2["HTTP Fallback"]
        D3["Headers • Body • Cookies"]
        D --> D1
        D1 -->|Yes| D2
        D1 -->|No| D3
        D2 --> D3
    end

    subgraph S3["3. Infrastructure Detection"]
        E["Header & Cookie Analysis"]
        F["IP Intelligence"]
        G{"CDN / WAF / Proxy"}
        E --> G
        F --> G
    end

    subgraph S4["4. Port Discovery"]
        H{"Smart Scan"}
        I["Target Scan"]
        J["Enumerate Subdomains<br/>Collect All IPs"]
        K["Nmap / Async Connect"]
        L["Banner & HTTP Fingerprinting"]
        H -->|Disabled| I
        H -->|Enabled| J
        I --> K
        J --> K
        K --> L
    end

    subgraph S5["5. Technology Detection"]
        M["Headers"]
        N["Cookies"]
        O["HTML & Meta"]
        P["JavaScript"]
        Q["URL Patterns"]
        R["SigDB (7500+ Signatures)"]
    end

    subgraph S6["6. Advanced Analysis"]
        S["Subdomain Enumeration"]
        T["CVE Matching"]
        U["Default Credentials"]
    end

    subgraph S7["7. Report"]
        V["Security Report"]
    end

    A --> B
    C --> D
    D3 --> E
    C1 --> F
    G --> H

    L --> M
    L --> N
    L --> O
    L --> P
    L --> Q
    L --> R

    M --> S
    N --> S
    O --> T
    P --> T
    Q --> U
    R --> U

    S --> V
    T --> V
    U --> V

    classDef start fill:#2563eb,color:#fff,stroke:#1d4ed8,stroke-width:2px;
    classDef phase fill:#7c3aed,color:#fff,stroke:#6d28d9,stroke-width:2px;
    classDef decision fill:#f59e0b,color:#fff,stroke:#b45309,stroke-width:2px;
    classDef finish fill:#16a34a,color:#fff,stroke:#166534,stroke-width:2px;

    class A start;
    class B,C,C1,C2,C3,D,D2,D3,E,F,I,J,K,L,M,N,O,P,Q,R,S,T,U phase;
    class D1,G,H decision;
    class V finish;

Pipeline Stages

Stage Description
1. Target Resolution Normalize the input target, resolve IPv4/IPv6 addresses, collect DNS records, and perform reverse PTR lookups.
2. HTTP Discovery Send an initial HTTPS request with automatic HTTP fallback and collect response headers, cookies, redirects, and HTML.
3. Infrastructure Detection Detect CDN, WAF, reverse proxies, and hosting providers using HTTP fingerprints and IP intelligence.
4. Port Discovery Scan services using Nmap or the built-in asynchronous scanner. Smart Scan expands the scan across all discovered IP addresses.
5. Technology Detection Fingerprint web technologies using headers, cookies, HTML, JavaScript, URL patterns, and the 7500+ signature database.
6. Advanced Analysis Enumerate subdomains, correlate detected software with CVEs, and test common default credentials.
7. Report Generation Merge all collected information into a comprehensive security report.

🗂 Structure

stackscan/
├── src/stackscan/
│   ├── analyzers/     ← tech, infra, security, exposure, cve, creds
│   ├── net/           ← dns, tls, geo, ipinfo, ports, fingerprint, subdomains
│   ├── config/        ← bundled + sourced sigdb loading
│   ├── data/          ← builtin.sigdb, cve.json.gz, subdomains.txt
│   ├── render.py      ← the colorized panel report
│   ├── embed.py       ← findings as data, and the form, for reekeer to draw
│   ├── runner.py      ← panel worker: claim jobs, scan, report back
│   ├── scan.py        ← per-target orchestration
│   └── cli.py         ← argument parsing and entry point
├── scripts/           ← build_cve_db.py (NVD → offline dataset)
└── tests/

🛠 Development

ruff check . && black --check . && pyright && pytest

MIT © reekeer

Metadata

Release files for stackscan 2.7.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for stackscan 2.7.2
File Size Uploaded
stackscan-2.7.2.tar.gz 2.3 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for stackscan 2.7.2
File Interpreter ABI Platform
stackscan-2.7.2-py3-none-any.whl Python 3 none any Details

Total release size: 4.6 MB

Release files / stackscan-2.7.2.tar.gz

Download URL stackscan-2.7.2.tar.gz
Size 2.3 MB
Tags Source
SHA-256 checksum
How to use checksums
e6d325829592cee4110aff94c07fa593a6a77280471e7f01a2e84a1afe9c72ac
BLAKE2b-256 checksum
How to use checksums
bd69fb17de2b77eaf496ac86dc28b9238f6672060b897e8a36e89338025afdfc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 29, 2026.

Transparency log

Release files / stackscan-2.7.2-py3-none-any.whl

Download URL stackscan-2.7.2-py3-none-any.whl
Size 2.3 MB
Tags Python 3
SHA-256 checksum
How to use checksums
29db960bcc296c466b2ab7887cd68e544cc43aedc53ec4cac8985e514558592f
BLAKE2b-256 checksum
How to use checksums
40f6e71ec5576d5662b76f1dbe0f8eef24530b15a776a4c4867954f212e0173e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 29, 2026.

Transparency log

Release history Release notifications | RSS feed

2.7.3

2 release files

This release

2.7.2 This release

2 release files

2.7.1

2 release files

2.6.3

2 release files

2.6.0

2 release files

2.5.0

2 release files

2.3.0

2 release files

2.2.2

2 release files

2.2.1

2 release files

2.2.0

2 release files

2.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page