About this project
SpectraScan is a Python 3.9+ command-line framework that bundles network reconnaissance, service enumeration, OSINT lookups and passive dark-web reconnaissance into one modular tool with a Rich-powered interactive menu.
Core scanning: TCP connect, SYN/raw-socket and UDP probes, Nmap-style timing profiles T0–T5, firewall/IDS heuristics (RST and ICMP behaviour), OS fingerprinting via TTL, TCP window size and DF-bit heuristics, SSL/TLS certificate and cipher analysis, HTTP header and common-path discovery, plus ICMP sweeps and ARP table walking. A threaded engine uses ThreadPoolExecutor with a default cap of min(512, ports × targets); an additive asyncio/aiohttp AsyncPortScanner is available via --async-scan with configurable concurrency and timeout.
OSINT suite: domain WHOIS and DNS records, IP GeoIP/ASN/WHOIS with optional Shodan enrichment, phone carrier and line-type lookup, email reputation and breach/disposable-mail flags, image EXIF/IPTC/XMP extraction, and link/subdomain sniffing.
Protocol modules: SMB/CIFS, SNMP, LDAP/LDAPS, RDP, SMTP, DNS zone transfer, NFS, VNC, Redis, MongoDB, SIP, RTSP and database version detection, implemented mainly in Python with graceful fallbacks.
Active modules (explicit opt-in, authorization required): dictionary-based SSH/FTP credential testing with rate limiting and back-off, CVE correlation against the NVD CVE 2.0 API with local caching, and web directory/file enumeration with custom wordlists.
Dark-web recon is passive only: target auto-detection for .onion v2/v3, crypto addresses, emails, hashes and PGP blocks; onion banner/TLS collection through Tor SOCKS5; Bitcoin address profiling via Blockchair/Blockstream/Blockchain.info fallbacks; Ahmia search and Tor connectivity checks. It states no marketplace interaction, payload execution or automatic Tor startup, with a 30-second network timeout cap.
Reports are stored under ~/.local/share/SpectraScan/ (configurable via SPECTRASCAN_HOME) and can be exported as JSON, CSV or HTML, with timestamps and UUIDs, and listed or re-exported later. Optional dependencies include Tor, exiftool/exiv2, nmap, pysocks and cryptography; API keys are supplied through environment variables such as SHODAN_KEY, NVD_API_KEY and NUMVERIFY_KEY. The README positions the project as complementary to tools like Nmap, Recon-ng and SpiderFoot, and stresses that use is limited to systems you own or are explicitly permitted to test.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.