Skip to content

Latest commit

 

History

History
443 lines (342 loc) · 50 KB

File metadata and controls

443 lines (342 loc) · 50 KB

Third-Party Licenses

RedAmon integrates, bundles, or dynamically invokes the following third-party open-source software. Each component is governed by its own license. The authors of RedAmon do not own, maintain, or provide warranty for any of these tools. This file documents all third-party components, their licenses, and where to obtain their source code.

AGPL-3.0 Notice: Several tools bundled in RedAmon's Docker images are licensed under the GNU Affero General Public License v3.0. Under AGPL-3.0, the complete corresponding source code for these tools must be made available to any user who interacts with them. Source code for all AGPL-licensed components is available at their respective repositories listed below.


ProjectDiscovery Tools

These tools are either installed in Docker images or pulled as Docker containers at runtime.

Tool Purpose License Source Repository How Used
Naabu Port scanning AGPL-3.0 https://github.com/projectdiscovery/naabu Installed via go install in mcp/kali-sandbox/Dockerfile; also pulled as Docker image projectdiscovery/naabu:latest at runtime
Nuclei Template-based vulnerability scanning (9,000+ templates) AGPL-3.0 https://github.com/projectdiscovery/nuclei Installed via go install in mcp/kali-sandbox/Dockerfile; also pulled as Docker image projectdiscovery/nuclei:latest at runtime
Nuclei Templates Community vulnerability detection templates MIT https://github.com/projectdiscovery/nuclei-templates Downloaded via nuclei -update-templates in mcp/kali-sandbox/entrypoint.sh
Katana Web crawling and endpoint discovery AGPL-3.0 https://github.com/projectdiscovery/katana Pulled as Docker image projectdiscovery/katana:latest at runtime
HTTPx HTTP probing and technology detection AGPL-3.0 https://github.com/projectdiscovery/httpx Installed via go install in mcp/kali-sandbox/Dockerfile; also pulled as Docker image projectdiscovery/httpx:latest at runtime
tlsx TLS certificate grabbing and posture on open non-HTTP ports (TLS Certificate Grab, recon GROUP 3.6); complements HTTPx, which only grabs certificates on the HTTPS ports it dials MIT https://github.com/projectdiscovery/tlsx Pulled as Docker image projectdiscovery/tlsx:latest at runtime (recon/entrypoint.sh, recon/main_recon_modules/tls_scan.py); the image is on the docker-broker allowlist (services/docker_broker/broker.py) and the configured value is pinned back to an allowlisted image before use
Subfinder Subdomain enumeration via passive sources AGPL-3.0 https://github.com/projectdiscovery/subfinder Pulled as Docker image projectdiscovery/subfinder:latest at runtime
DNSx Fast DNS toolkit (resolution, bruteforce, wildcard filtering) AGPL-3.0 https://github.com/projectdiscovery/dnsx Pulled as Docker image projectdiscovery/dnsx:latest at runtime
uncover Exposed-host discovery via search-engine APIs (Shodan, Censys, FOFA, Quake, Hunter, etc.) for target expansion MIT https://github.com/projectdiscovery/uncover Pulled as Docker image projectdiscovery/uncover:latest at runtime (recon/main_recon_modules/uncover_enrich.py, recon/entrypoint.sh); provider API keys injected at call time
Interactsh OOB (Out-of-Band) interaction gathering MIT https://github.com/projectdiscovery/interactsh Installed via go install in mcp/kali-sandbox/Dockerfile
vulnx CVE intelligence (NVD + CISA KEV + EPSS + HackerOne + GitHub PoCs + Nuclei template availability). Successor to cvemap. MIT https://github.com/projectdiscovery/vulnx Installed via go install in mcp/kali-sandbox/Dockerfile. Invoked as a subprocess by the cve_intel agent tool (mcp/servers/network_recon_server.py). Optional PDCP API key (configured per-user in Global Settings) is injected at call time as PDCP_API_KEY env var; never logged or committed.

Exploitation & Post-Exploitation Tools

Tool Purpose License Source Repository How Used
Metasploit Framework Exploitation, post-exploitation, and payload generation BSD-3-Clause (Rapid7) https://github.com/rapid7/metasploit-framework Installed via apt-get in mcp/kali-sandbox/Dockerfile
Hydra Network login brute-force (50+ protocols) AGPL-3.0 https://github.com/vanhauser-thc/thc-hydra Installed via apt-get in mcp/kali-sandbox/Dockerfile
SQLMap Automated SQL injection detection and exploitation GPL-2.0 https://github.com/sqlmapproject/sqlmap Installed via apt-get in mcp/kali-sandbox/Dockerfile
John the Ripper Password cracking GPL-2.0 https://github.com/openwall/john Installed via apt-get in mcp/kali-sandbox/Dockerfile
ExploitDB Public exploit archive and search GPL-2.0 https://gitlab.com/exploit-database/exploitdb Installed via apt-get in mcp/kali-sandbox/Dockerfile
Impacket Python classes for working with network protocols Apache-1.1 (modified) https://github.com/fortra/impacket Installed via pip in mcp/requirements.txt
Pwntools CTF framework and exploit development library MIT https://github.com/Gallopsled/pwntools Installed via pip in mcp/requirements.txt
Dalfox XSS vulnerability scanner and parameter analysis MIT https://github.com/hahwul/dalfox Installed via go install in mcp/kali-sandbox/Dockerfile
kxss Per-character XSS reflection probe Apache-2.0 https://github.com/Emoe/kxss Installed via go install in mcp/kali-sandbox/Dockerfile
commix Automated command injection detection and exploitation GPL-3.0 https://github.com/commixproject/commix Installed via apt-get in mcp/kali-sandbox/Dockerfile
ysoserial Java deserialization gadget chain generator MIT https://github.com/frohoff/ysoserial JAR downloaded from upstream releases in mcp/kali-sandbox/Dockerfile
phpggc PHP gadget chain generator (unserialize / PHAR exploitation) Apache-2.0 https://github.com/ambionics/phpggc Cloned from upstream in mcp/kali-sandbox/Dockerfile
Ruby Interpreter for Ruby Marshal / Rails (secret_key_base cookie) deserialization gadget crafting (Insecure Deserialization + RCE skills, Ruby track) Ruby License / BSD-2-Clause https://www.ruby-lang.org Installed via apt-get in mcp/kali-sandbox/Dockerfile (separate-process CLI invocation via kali_shell)
viewgen ASP.NET ViewState generator/decoder: forge a signed/encrypted __VIEWSTATE when the machineKey is leaked / default / known (Insecure Deserialization skill, .NET track) MIT https://github.com/0xacb/viewgen Installed via pip in mcp/kali-sandbox/Dockerfile
netexec Multi-protocol network exploitation (CrackMapExec successor) BSD-2-Clause https://github.com/Pennyw0rth/NetExec Installed via apt-get in mcp/kali-sandbox/Dockerfile
hashcat GPU-accelerated password cracking MIT https://github.com/hashcat/hashcat Installed via apt-get in mcp/kali-sandbox/Dockerfile
sshpass Non-interactive SSH password authentication GPL-2.0 https://sourceforge.net/projects/sshpass/ Installed via apt-get in mcp/kali-sandbox/Dockerfile
hashID Hash type identification (MD5, NTLM, bcrypt, etc.) GPL-3.0 https://github.com/psypanda/hashID Installed via pip in mcp/kali-sandbox/Dockerfile
WPScan WordPress vulnerability scanner WPScan Public Source License https://github.com/wpscanteam/wpscan Installed via apt-get in mcp/kali-sandbox/Dockerfile. Free for pentesting assessments and personal use; commercial use may require a separate license from https://wpscan.com.

Active Directory & Post-Exploitation (Python)

These are AD reconnaissance and abuse primitives installed in the Kali sandbox container, used by the AD kill-chain and Windows-priv-esc Chat Skills.

Tool Purpose License Source Repository How Used
BloodHound (Python collector) Active Directory relationship collector MIT https://github.com/dirkjanm/BloodHound.py Installed via pip in mcp/kali-sandbox/Dockerfile (CLI use only; no Python imports in RedAmon source)
certipy-ad AD Certificate Services exploitation (ESC1-ESC13) MIT https://github.com/ly4k/Certipy Installed via pip in mcp/kali-sandbox/Dockerfile
ldapdomaindump LDAP enumeration (users, groups, password policies) MIT https://github.com/dirkjanm/ldapdomaindump Installed via pip in mcp/kali-sandbox/Dockerfile
bloodyAD Live AD abuse primitives (password reset, group add, SPN set) MIT https://github.com/CravateRouge/bloodyAD Installed via pip in mcp/kali-sandbox/Dockerfile
gMSADumper Read gMSA passwords (BloodHound ReadGMSAPassword edge) GPL-3.0 https://github.com/micahvandeusen/gMSADumper Cloned from upstream in mcp/kali-sandbox/Dockerfile (separate-process invocation, mere aggregation)
kerbrute Kerberos pre-auth user enumeration + password spraying Apache-2.0 https://github.com/ropnop/kerbrute Installed via go install in mcp/kali-sandbox/Dockerfile
enum4linux-ng SMB / Windows / AD enumeration GPL-3.0 https://github.com/cddmp/enum4linux-ng Installed via apt-get in mcp/kali-sandbox/Dockerfile
dnsrecon DNS enumeration (zone transfers, SRV, DNSSEC walk) GPL-2.0 https://github.com/darkoperator/dnsrecon Installed via apt-get in mcp/kali-sandbox/Dockerfile
smbclient (Samba) SMB client for share enumeration and access GPL-3.0 https://gitlab.com/samba-team/samba Installed via apt-get (samba-common-bin) in mcp/kali-sandbox/Dockerfile
ldap3 Pure-Python LDAP client library LGPL-3.0 https://github.com/cannatag/ldap3 Installed via pip in mcp/kali-sandbox/Dockerfile

Cloud Provider SDKs (Cloud-Attack Chat Skills)

These SDKs are installed in the Kali sandbox container and used by cloud-enumeration / cloud-attack Chat Skills for Entra ID / Azure / GCP probing.

Library Purpose License Source Repository How Used
MSAL (msal) Microsoft Authentication Library (Entra ID token acquisition) MIT https://github.com/AzureAD/microsoft-authentication-library-for-python Installed via pip in mcp/kali-sandbox/Dockerfile
azure-identity Azure credential / token provider MIT https://github.com/Azure/azure-sdk-for-python Installed via pip in mcp/kali-sandbox/Dockerfile
azure-mgmt-resource Azure Resource Manager client MIT https://github.com/Azure/azure-sdk-for-python Installed via pip in mcp/kali-sandbox/Dockerfile
google-auth Google authentication library Apache-2.0 https://github.com/googleapis/google-auth-library-python Installed via pip in mcp/kali-sandbox/Dockerfile
google-api-python-client Google APIs client library Apache-2.0 https://github.com/googleapis/google-api-python-client Installed via pip in mcp/kali-sandbox/Dockerfile
google-cloud-storage Google Cloud Storage client Apache-2.0 https://github.com/googleapis/python-storage Installed via pip in mcp/kali-sandbox/Dockerfile

Privilege Escalation Helpers (Staged Binaries)

These scripts and binaries are downloaded into /opt/tools/{linux,windows}/ and served by the agent to a foothold host (HTTP, SMB, or upload primitive). They are not linked against RedAmon code; they are unmodified upstream artifacts staged for delivery.

Tool Purpose License Source Repository How Used
PEASS-ng (linpeas / winPEAS) Linux + Windows privesc auditors GPL-2.0 https://github.com/peass-ng/PEASS-ng Binaries downloaded in mcp/kali-sandbox/Dockerfile, staged in /opt/tools/{linux,windows}/ (unmodified upstream artifact, served to foothold hosts; not linked against RedAmon)
LinEnum Linux enumeration helper script MIT https://github.com/rebootuser/LinEnum Script downloaded in mcp/kali-sandbox/Dockerfile, staged in /opt/tools/linux/
pspy Real-time process snooper (no root needed) GPL-3.0 https://github.com/DominicBreuker/pspy Binary downloaded in mcp/kali-sandbox/Dockerfile, staged in /opt/tools/linux/ (unmodified upstream artifact, served to foothold hosts; not linked against RedAmon)
deepce Docker container escape primitive scanner Apache-2.0 https://github.com/stealthcopter/deepce Script downloaded in mcp/kali-sandbox/Dockerfile, staged in /opt/tools/linux/
PowerUp.ps1 (PowerSploit) Windows local privilege escalation toolkit BSD-3-Clause https://github.com/PowerShellMafia/PowerSploit Script downloaded in mcp/kali-sandbox/Dockerfile, staged in /opt/tools/windows/
PrivescCheck.ps1 Windows privilege escalation audit script BSD-3-Clause https://github.com/itm4n/PrivescCheck Script downloaded in mcp/kali-sandbox/Dockerfile, staged in /opt/tools/windows/

Network Scanning & Reconnaissance Tools

Tool Purpose License Source Repository How Used
Nmap Network scanning and service detection NPSL (Nmap Public Source License) https://github.com/nmap/nmap Installed via apt-get in mcp/kali-sandbox/Dockerfile
Masscan Asynchronous TCP port scanner AGPL-3.0 https://github.com/robertdavidgraham/masscan Built from source in recon/Dockerfile; also installed via apt-get in mcp/kali-sandbox/Dockerfile
Amass In-depth subdomain enumeration Apache-2.0 https://github.com/owasp-amass/amass Pulled as Docker image caffix/amass:latest at runtime
Knockpy Subdomain enumeration via wordlist GPL-3.0 https://github.com/guelfoweb/knock Installed via pip in recon/Dockerfile. Invoked as a CLI subprocess only (knockpy -d ... in recon/main_recon_modules/domain_recon.py); never imported into RedAmon source, so its GPL scope does not extend to RedAmon's code (mere aggregation).
puredns DNS wildcard filtering and resolution GPL-3.0 https://github.com/d3mondev/puredns Pulled as Docker image frost19k/puredns:latest at runtime
Hakrawler Web crawling and link discovery MIT https://github.com/hakluke/hakrawler Pulled as Docker image jauderho/hakrawler:latest at runtime
GAU (GetAllUrls) Passive URL discovery from web archives MIT https://github.com/lc/gau Pulled as Docker image sxcurity/gau:latest at runtime
Kiterunner API endpoint discovery AGPL-3.0 https://github.com/assetnote/kiterunner Binary downloaded from GitHub releases at runtime
jsluice JavaScript file analysis for endpoints and secrets MIT https://github.com/BishopFox/jsluice Built from source via go install in recon/Dockerfile (multi-stage)
ffuf Web fuzzer (directories, parameters, vhosts) MIT https://github.com/ffuf/ffuf Built from source in recon/Dockerfile; also installed via go install in mcp/kali-sandbox/Dockerfile
Arjun HTTP hidden parameter discovery AGPL-3.0 https://github.com/s0md3v/Arjun Installed via pip in recon/requirements.txt. Invoked as a CLI subprocess only (shutil.which('arjun') + subprocess(['arjun', ...]) in recon/helpers/resource_enum/arjun_helpers.py); never imported into RedAmon source, so its AGPL scope does not extend to RedAmon's code (mere aggregation).
ParamSpider URL parameter mining from web archives MIT https://github.com/devanshbatham/ParamSpider Installed via pip (git) in recon/requirements.txt
TruffleHog Credential and secret scanning AGPL-3.0 https://github.com/trufflesecurity/trufflehog Pulled as Docker image trufflesecurity/trufflehog:latest at runtime; also installed as binary in scanners/trufflehog_scan/Dockerfile
betterleaks Git repository secret scanner (API keys, passwords, tokens); gitleaks successor from the same author MIT https://github.com/betterleaks/betterleaks Installed via go install in mcp/kali-sandbox/Dockerfile
subzy Subdomain takeover fingerprint scanner (90+ providers) GPL-2.0 https://github.com/PentestPad/subzy Installed via go install in mcp/kali-sandbox/Dockerfile (separate-process invocation, mere aggregation)
Nikto Web server vulnerability scanner GPL-3.0 (database files non-GPL, distributable only with Nikto) https://github.com/sullo/nikto Installed via apt-get in mcp/kali-sandbox/Dockerfile
WhatWeb Web technology fingerprinting GPL-2.0 https://github.com/urbanadventurer/WhatWeb Installed via apt-get in mcp/kali-sandbox/Dockerfile
testssl.sh SSL/TLS configuration auditing GPL-2.0 https://github.com/drwetter/testssl.sh Installed via apt-get in mcp/kali-sandbox/Dockerfile
CeWL Custom wordlist generator from target websites CC-BY-SA-2.0 UK (with GPL-3.0+ alternative offered by upstream) https://github.com/digininja/CeWL Installed via apt-get in mcp/kali-sandbox/Dockerfile
Subjack Subdomain takeover detection (CNAME/NS/MX/SPF + stale A records) Apache-2.0 https://github.com/haccer/subjack Built from source via go install in recon/Dockerfile (multi-stage); invoked as native binary inside the recon container
BadDNS Deep DNS takeover detection (CNAME/NS/MX/TXT/SPF/DMARC/MTA-STS/wildcard/NSEC/references/zonetransfer modules) AGPL-3.0 https://github.com/blacklanternsecurity/baddns Isolated in its own Docker image redamon-baddns:latest (built from scanners/baddns_scan/Dockerfile via pip install baddns). RedAmon never imports from this package. The recon container spawns the sidecar via docker run --rm and receives results as NDJSON on stdout. The process + filesystem boundary preserves the AGPL-3.0 license scope. Upstream source code is available at the linked repository.

Web Application & API Security Tools

Tool Purpose License Source Repository How Used
jwt_tool JWT token testing and exploitation GPL-3.0 https://github.com/ticarpi/jwt_tool Installed via pip (git) in mcp/kali-sandbox/Dockerfile
graphql-cop GraphQL security auditing BSD-3-Clause https://github.com/dolevf/graphql-cop Installed via pip (git) in mcp/kali-sandbox/Dockerfile
GraphQLmap GraphQL endpoint exploitation MIT https://github.com/swisskyrepo/GraphQLmap Installed via pip (git) in mcp/kali-sandbox/Dockerfile
SSTImap Server-Side Template Injection detection & exploitation GPL-3.0 https://github.com/vladko312/SSTImap Cloned from upstream in mcp/kali-sandbox/Dockerfile (separate-process invocation, mere aggregation)
tplmap SSTI scanner (Smarty / Velocity coverage) GPL-3.0 https://github.com/epinna/tplmap Cloned from upstream in mcp/kali-sandbox/Dockerfile (isolated venv)
semgrep Source-aware static analysis (SAST) LGPL-2.1 https://github.com/semgrep/semgrep Installed via pip in mcp/kali-sandbox/Dockerfile. Used by the source-aware-sast Chat Skill on operator-provided repos.
Playwright Browser automation (Chromium) for web recon Apache-2.0 https://github.com/microsoft/playwright-python Installed via pip in mcp/kali-sandbox/Dockerfile
zeep Python SOAP client (WS-Security / XSW probing in the SOAP Chat Skill) MIT https://github.com/mvantellingen/python-zeep Installed via pip in mcp/kali-sandbox/Dockerfile
python3-saml SAML toolkit (XSW / Comment Injection / Golden SAML construction in the SAML Chat Skill) MIT https://github.com/SAML-Toolkits/python3-saml Installed via pip in mcp/kali-sandbox/Dockerfile
OWASP ZAP (Zed Attack Proxy) Browser-driven (headless Firefox) Ajax Spider for resource enumeration of JS-heavy SPAs Apache-2.0 https://github.com/zaproxy/zaproxy Pulled as Docker image ghcr.io/zaproxy/zaproxy:stable at runtime by the recon container (recon/helpers/resource_enum/zap_ajax_spider_helpers.py); run with --net=host via the ZAP Automation Framework. RedAmon never imports from ZAP; results are parsed from an exported artifact (process + filesystem boundary).
Web Cache Vulnerability Scanner (WCVS) Web cache poisoning & deception scanning (header/parameter cache-key probing) for the cache-poisoning recon module Apache-2.0 https://github.com/Hackmanit/Web-Cache-Vulnerability-Scanner Go binary built from source into the local image redamon-wcvs:latest (scanners/wcvs/Dockerfile); run as a separate docker run subprocess from the recon container (recon/cache_scan/wcvs_runner.py). RedAmon never links WCVS code; output is parsed from JSON (process boundary, mere aggregation).

HTTP Traffic Capture (TrafficMind)

These libraries power TrafficMind, RedAmon's engagement-scoped HTTP capture layer (the credential-free man-in-the-middle capture proxy and its trusted ingest worker). Both are installed into the redamon-capture-proxy image (scanners/capture_proxy/Dockerfile).

Library Purpose License Source Repository How Used
mitmproxy Interactive TLS-capable HTTP/HTTPS intercepting proxy MIT https://github.com/mitmproxy/mitmproxy Installed via pip (mitmproxy~=11.1) in scanners/capture_proxy/Dockerfile; run as mitmdump -s capture_addon.py on the target-facing network to intercept and record HTTP transactions
psycopg (psycopg[binary]) PostgreSQL adapter for Python LGPL-3.0 https://github.com/psycopg/psycopg Installed via pip (psycopg[binary]~=3.2) in scanners/capture_proxy/Dockerfile; used only by the trusted ingest worker (scanners/capture_proxy/ingest_worker.py) to INSERT captured transactions via a scoped, insert-only database role

Supply-Chain / Malicious-Package Detection

These tools power RedAmon's Supply-Chain Discovery module (malicious / vulnerable dependency detection across the three layers: L1 SBOM scan, L2 recon harvest, L3 agent tools). All are invoked as separate processes via run_argv (shell=False subprocess), never imported into RedAmon source, so their scope does not extend to RedAmon's MIT code (mere aggregation). All are permissively licensed and MIT-compatible.

Tool Purpose License Source Repository How Used
OSV-Scanner Offline verdict engine — flags packages as malicious (MAL-) or known-vulnerable (CVE/GHSA) against a local OSV database Apache-2.0 https://github.com/google/osv-scanner Go binary built from source (@v2.4.0) in scanners/supply_chain_analyzer/Dockerfile, scanners/supply_chain_scan/Dockerfile, recon/Dockerfile, and mcp/kali-sandbox/Dockerfile; invoked as a CLI subprocess via scanners/supply_chain_common/osv_runner.py with --offline (zero network egress)
GuardDog Behavioural malware analysis of a package (install hooks, obfuscation, exfil, typosquat) Apache-2.0 https://github.com/DataDog/guarddog Installed via pip (guarddog==3.0.1) in scanners/supply_chain_analyzer/Dockerfile; invoked as a CLI subprocess (guarddog <eco> scan) via scanners/supply_chain_common/guarddog_runner.py, only inside the hardened DIRTY analyzer image
Semgrep Static-analysis engine used internally by GuardDog LGPL-2.1 https://github.com/semgrep/semgrep Pulled in transitively by GuardDog inside supply_chain_analyzer; runs as a separate process, pip-replaceable
YARA Pattern-matching engine used internally by GuardDog BSD-3-Clause https://github.com/VirusTotal/yara Pulled in transitively by GuardDog inside supply_chain_analyzer
retire.js Black-box JS library + version harvest from target-served JavaScript (L2) Apache-2.0 https://github.com/RetireJS/retire.js Installed via npm install -g retire@5.4.3 in scanners/supply_chain_analyzer/Dockerfile; invoked as a CLI subprocess via scanners/supply_chain_common/retire_runner.py (runner wired; L2 activation is a follow-up release)

OSV database (data, not code). The offline OSV vulnerability database is downloaded at runtime by osv-scanner --download-offline-databases into the redamon-osv-db Docker volume (scanners/supply_chain_common/osv_db_sync.py); it is not bundled in any RedAmon image and is not redistributed by RedAmon. The aggregated OSV.dev data is published under CC-BY-4.0 (individual records carry their upstream advisory sources). See https://osv.dev.

CycloneDX SBOM format. RedAmon synthesizes CycloneDX-format SBOMs itself (scanners/supply_chain_common/artifact.py::to_cyclonedx) to feed osv-scanner; it does not bundle or depend on any CycloneDX library. The CycloneDX specification is an OWASP project under Apache-2.0 (https://github.com/CycloneDX). Only the open format is used.


Vulnerability Assessment (GVM/OpenVAS)

Tool Purpose License Source Repository How Used
GVM (Greenbone Vulnerability Management) Network vulnerability scanning (170,000+ NVTs) AGPL-3.0 https://github.com/greenbone Multiple Docker images from registry.community.greenbone.net in docker-compose.yml
gvmd GVM management daemon AGPL-3.0 https://github.com/greenbone/gvmd Docker image: registry.community.greenbone.net/community/gvmd:stable
ospd-openvas OpenVAS scanner daemon AGPL-3.0 https://github.com/greenbone/ospd-openvas Docker image: registry.community.greenbone.net/community/ospd-openvas:22.7.1
pg-gvm GVM PostgreSQL database AGPL-3.0 https://github.com/greenbone/pg-gvm Docker image: registry.community.greenbone.net/community/pg-gvm:stable
Greenbone Redis GVM data store AGPL-3.0 https://github.com/greenbone Docker image: registry.community.greenbone.net/community/redis-server:stable
Greenbone Feed Data Vulnerability tests, SCAP, CERT, NVT data AGPL-3.0 https://github.com/greenbone Docker images for vulnerability-tests, notus-data, scap-data, cert-bund-data, dfn-cert-data, data-objects, report-formats, gpg-data
python-gvm Python API client for GVM GPL-3.0 https://github.com/greenbone/python-gvm Installed via pip in scanners/gvm_scan/requirements.txt

AI Gauntlet (Offensive AI/LLM Testing)

These red-team tools power the AI Gauntlet (RedAmon v5.0.0), the offensive AI/LLM testing module. garak, PyRIT, and Giskard are installed in isolated per-tool Python virtualenvs inside the ai_attack_surface_scan Docker image; promptfoo is installed as a Node.js CLI. Each is invoked as a separate subprocess by the scan container (mere aggregation). All four are permissively licensed (Apache-2.0 / MIT). Grading is performed by a local model served via Ollama, with zero external egress.

Tool Purpose License Source Repository How Used
garak Broad LLM vulnerability scanner (40 probe families: prompt injection, jailbreaks, encoding bypass, data leakage, toxicity, and more) Apache-2.0 https://github.com/NVIDIA/garak Installed via pip into /opt/venv-garak in scanners/ai_attack_surface_scan/Dockerfile; invoked as python -m garak (REST generator) subprocess
PyRIT Bounded multi-turn LLM jailbreak / risk-identification framework (crescendo, skeleton-key, TAP, many-shot) MIT https://github.com/Azure/PyRIT Installed via pip into /opt/venv-pyrit; invoked via the pyrit_run.py runner as a subprocess
Giskard App-tailored LLM safety/quality scanner (prompt injection, info disclosure, hallucination, bias, sycophancy) Apache-2.0 https://github.com/Giskard-AI/giskard Installed via pip into /opt/venv-giskard; invoked via the giskard_run.py runner as a subprocess
promptfoo LLM red-team eval over public attack datasets, with local encoding strategies MIT https://github.com/promptfoo/promptfoo Installed via npm install -g promptfoo in scanners/ai_attack_surface_scan/Dockerfile; invoked as the promptfoo CLI (redteam generate + eval)
Ollama Local model runtime serving the judge/grader (zero-egress grading) MIT https://github.com/ollama/ollama Pulled as Docker image ollama/ollama:latest on demand by recon_orchestrator/local_llm_manager.py; queried over the local network only
LiteLLM Routes Giskard's judge / embedding calls to the local Ollama (ollama/<model>) MIT https://github.com/BerriAI/litellm Pulled in transitively by Giskard in /opt/venv-giskard; keeps all model calls local

Judge model & red-team datasets (fetched at runtime)

The judge/grader model and promptfoo's dataset plugins are downloaded at scan time (Ollama model pull / HuggingFace), not bundled in the RedAmon image. They are not redistributed by RedAmon; each is governed by its own upstream terms.

Resource Purpose License Source Notes
Qwen2.5-7B-Instruct Default local judge / grader model Apache-2.0 https://huggingface.co/Qwen/Qwen2.5-7B-Instruct Pulled by Ollama as qwen2.5:7b; operator-configurable
nomic-embed-text Embedding model for Giskard's detectors Apache-2.0 https://huggingface.co/nomic-ai/nomic-embed-text-v1.5 Pulled by Ollama when an embedding detector runs
BeaverTails promptfoo harmful-prompt dataset CC-BY-NC-4.0 https://huggingface.co/datasets/PKU-Alignment/BeaverTails Fetched at runtime. NonCommercial license — review before use in a commercial engagement
HarmBench promptfoo standardized harmful-behavior dataset MIT https://github.com/centerforaisafety/HarmBench Fetched at runtime
L1B3RT4S (Pliny) promptfoo jailbreak corpus See repository https://github.com/elder-plinius/L1B3RT4S Community jailbreak corpus, fetched at runtime; consult the repository for current terms

Tunneling

Tool Purpose License Source Repository How Used
Ngrok TCP tunneling for reverse shells (optional) Proprietary (free tier) https://ngrok.com/ Binary downloaded in mcp/kali-sandbox/Dockerfile
Chisel Multi-port TCP tunneling MIT https://github.com/jpillora/chisel Binary downloaded in mcp/kali-sandbox/Dockerfile

DoS / Stress Testing

Tool Purpose License Source Repository How Used
hping3 Packet crafting and stress testing GPL-2.0 https://github.com/antirez/hping Installed via apt-get in mcp/kali-sandbox/Dockerfile
slowhttptest Slow HTTP attack testing Apache-2.0 https://github.com/shekyan/slowhttptest Installed via apt-get in mcp/kali-sandbox/Dockerfile

Technology Fingerprinting

Tool Purpose License Source Repository How Used
python-Wappalyzer Technology detection on web targets GPL-3.0 https://github.com/chorsley/python-Wappalyzer Installed via pip in recon/Dockerfile

Databases

Tool Purpose License Source Repository How Used
Neo4j Community Graph database for attack surface mapping GPL-3.0 (Neo4j Community) https://github.com/neo4j/neo4j Docker image: neo4j:5.26-community in docker-compose.yml
PostgreSQL Relational database for project settings PostgreSQL License (BSD-like) https://github.com/postgres/postgres Docker image: postgres:16-alpine in docker-compose.yml

Wordlists & Data Resources

Resource Purpose License Source Repository How Used
SecLists Security assessment wordlists (directories, passwords, payloads) MIT https://github.com/danielmiessler/SecLists Downloaded in recon/Dockerfile for web content discovery
Trickest Resolvers Curated DNS resolver list MIT https://github.com/trickest/resolvers Downloaded at runtime in recon/entrypoint.sh
jhaddix all.txt Curated subdomain bruteforce wordlist Unspecified (public gist) https://gist.github.com/jhaddix/86a06c5dc309d08580a018c66354a056 Downloaded in recon/Dockerfile for subdomain discovery

Web Frameworks & Application Stack

These are libraries and frameworks used to build RedAmon's own web application, API servers, and agent system.

Library Purpose License Source Repository How Used
Next.js React framework for the web dashboard MIT https://github.com/vercel/next.js webapp/package.json
React UI component library MIT https://github.com/facebook/react webapp/package.json
Prisma Database ORM and schema management Apache-2.0 https://github.com/prisma/prisma webapp/package.json
FastAPI Python async web framework MIT https://github.com/tiangolo/fastapi recon_orchestrator/requirements.txt, agentic/requirements.txt
Uvicorn ASGI server BSD-3-Clause https://github.com/encode/uvicorn recon_orchestrator/requirements.txt, agentic/requirements.txt
Pydantic Data validation and settings management MIT https://github.com/pydantic/pydantic Multiple requirements.txt files

AI / Agent Framework

Library Purpose License Source Repository How Used
LangChain LLM application framework MIT https://github.com/langchain-ai/langchain agentic/requirements.txt
LangGraph Multi-agent orchestration framework MIT https://github.com/langchain-ai/langgraph agentic/requirements.txt
LangChain-Anthropic Anthropic model integration for LangChain MIT https://github.com/langchain-ai/langchain agentic/requirements.txt
LangChain-OpenAI OpenAI model integration for LangChain MIT https://github.com/langchain-ai/langchain agentic/requirements.txt
LangChain-Google-GenAI Google Gemini model integration for LangChain MIT https://github.com/langchain-ai/langchain-google agentic/requirements.txt
LangChain-Community Community LangChain integrations MIT https://github.com/langchain-ai/langchain agentic/requirements.txt
LangChain-AWS AWS Bedrock integration for LangChain MIT https://github.com/langchain-ai/langchain-aws agentic/requirements.txt
LangChain-Neo4j Neo4j graph integration for LangChain MIT https://github.com/langchain-ai/langchain agentic/requirements.txt
LangChain-Tavily Tavily search integration for LangChain MIT https://github.com/langchain-ai/langchain agentic/requirements.txt
LangChain-MCP-Adapters MCP server integration for LangChain MIT https://github.com/langchain-ai/langchain-mcp-adapters agentic/requirements.txt
FastMCP Fast Model Context Protocol server framework MIT https://github.com/jlowin/fastmcp mcp/requirements.txt
MCP SDK Model Context Protocol Python SDK MIT https://github.com/modelcontextprotocol/python-sdk mcp/requirements.txt; also recon/requirements.txt (AI Surface Recon MCP handshake + tools/list)
LangGraph-Checkpoint-Postgres Persistent LangGraph checkpointer (Fireteam state) MIT https://github.com/langchain-ai/langgraph agentic/requirements.txt
FAISS (faiss-cpu) Vector similarity search for the knowledge base MIT https://github.com/facebookresearch/faiss agentic/requirements-kb.txt (optional --kbase install only)
sentence-transformers Text embedding models for the vector knowledge base Apache-2.0 https://github.com/UKPLab/sentence-transformers agentic/requirements-kb.txt (optional --kbase install only)
PyTorch (torch) Tensor / deep-learning backend (transitive dep of sentence-transformers) BSD-3-Clause https://github.com/pytorch/pytorch Pulled in transitively by sentence-transformers (optional --kbase install only)

Key Python Libraries

Library Purpose License Source Repository How Used
Docker SDK for Python Docker API client Apache-2.0 https://github.com/docker/docker-py recon_orchestrator/requirements.txt
neo4j (Python driver) Neo4j database driver Apache-2.0 https://github.com/neo4j/neo4j-python-driver Multiple requirements.txt files
PyGithub GitHub API v3 client LGPL-3.0 https://github.com/PyGithub/PyGithub recon/requirements.txt, scanners/github_secret_hunt/requirements.txt, agentic/requirements.txt
GitPython Git repository interaction BSD-3-Clause https://github.com/gitpython-developers/GitPython agentic/requirements.txt
Paramiko SSH2 protocol library LGPL-2.1 https://github.com/paramiko/paramiko mcp/requirements.txt
Boto3 AWS SDK for Python Apache-2.0 https://github.com/boto/boto3 agentic/requirements.txt
BeautifulSoup4 HTML/XML parsing MIT https://www.crummy.com/software/BeautifulSoup/ mcp/requirements.txt
httpx Async HTTP client for Python BSD-3-Clause https://github.com/encode/httpx mcp/requirements.txt, agentic/requirements.txt
Requests HTTP library for Python Apache-2.0 https://github.com/psf/requests Multiple requirements.txt files
dnspython DNS toolkit for Python ISC https://github.com/rthalley/dnspython recon/requirements.txt
python-whois WHOIS lookup library MIT https://github.com/richardpenman/whois recon/requirements.txt
xmltodict XML to Python dict parser MIT https://github.com/martinblech/xmltodict scanners/gvm_scan/requirements.txt
SSE-Starlette Server-Sent Events for Starlette/FastAPI BSD-3-Clause https://github.com/sysid/sse-starlette recon_orchestrator/requirements.txt, mcp/requirements.txt
websockets WebSocket client and server library BSD-3-Clause https://github.com/python-websockets/websockets mcp/requirements.txt, agentic/requirements.txt
PyYAML YAML parser and emitter MIT https://github.com/yaml/pyyaml mcp/requirements.txt
PyCryptodome Cryptographic library BSD-2-Clause https://github.com/Legrandin/pycryptodome mcp/requirements.txt
PyJWT JSON Web Token implementation MIT https://github.com/jpadilla/pyjwt mcp/requirements.txt
NetworkX Graph/network analysis library BSD-3-Clause https://github.com/networkx/networkx agentic/requirements.txt
tree-sitter Incremental parsing system MIT https://github.com/tree-sitter/tree-sitter agentic/requirements.txt
tree-sitter-languages Pre-built Tree-sitter language grammars MIT https://github.com/grantjenks/py-tree-sitter-languages agentic/requirements.txt
mmh3 MurmurHash3 bindings (favicon hashing for AI-frontend product detection) MIT https://github.com/hajimes/mmh3 recon/requirements.txt (used by recon/helpers/ai_signal_catalog.py)
yara-python YARA bindings — static MCP tool-poisoning rules (deterministic, no LLM) in AI Surface Recon Apache-2.0 https://github.com/VirusTotal/yara-python recon/requirements.txt (lazy-imported by recon/main_recon_modules/ai_surface_recon.py)
prance OpenAPI/Swagger $ref-resolving parser for AI Surface Recon OpenAPI discovery MIT https://github.com/RonnyPfannschmidt/prance recon/requirements.txt (lazy-imported)
openapi-spec-validator OpenAPI 2.0/3.0/3.1 validation backend for prance Apache-2.0 https://github.com/python-openapi/openapi-spec-validator recon/requirements.txt
jq.py Python bindings for jq (Julius probe-pack models.extract expressions); bundles libjq BSD-2-Clause https://github.com/mwilliamson/jq.py recon/requirements.txt (lazy-imported)
markdownify HTML to Markdown converter (Tradecraft Lookup curated-resource crawl) MIT https://github.com/matthewwithanm/python-markdownify agentic/requirements.txt
pypdf Pure-Python PDF text extraction (Tradecraft Lookup) BSD-3-Clause https://github.com/py-pdf/pypdf agentic/requirements.txt
lxml C-backed XML/HTML parser BSD-3-Clause https://github.com/lxml/lxml agentic/requirements.txt
psycopg PostgreSQL adapter for Python (persistent LangGraph checkpointer) LGPL-3.0 https://github.com/psycopg/psycopg agentic/requirements.txt
OpenAI Python SDK OpenAI API client (vector knowledge base, provider-agnostic LLM calls) Apache-2.0 https://github.com/openai/openai-python agentic/requirements.txt

Key Node.js Libraries

Library Purpose License Source Repository How Used
neo4j-driver Neo4j database driver for Node.js Apache-2.0 https://github.com/neo4j/neo4j-javascript-driver webapp/package.json
@tanstack/react-query Async state management for React MIT https://github.com/TanStack/query webapp/package.json
@tanstack/react-table Headless table UI for React MIT https://github.com/TanStack/table webapp/package.json
XTerm.js Terminal emulator for the browser MIT https://github.com/xtermjs/xterm.js webapp/package.json (@xterm/xterm, @xterm/addon-fit, @xterm/addon-web-links)
Three.js 3D graphics library MIT https://github.com/mrdoob/three.js webapp/package.json
react-force-graph-2d/3d Force-directed graph visualization MIT https://github.com/vasturiano/react-force-graph webapp/package.json
Recharts Charting library for React MIT https://github.com/recharts/recharts webapp/package.json
react-markdown Markdown renderer for React MIT https://github.com/remarkjs/react-markdown webapp/package.json
react-syntax-highlighter Syntax highlighting for React MIT https://github.com/react-syntax-highlighter/react-syntax-highlighter webapp/package.json
remark-gfm GitHub Flavored Markdown plugin MIT https://github.com/remarkjs/remark-gfm webapp/package.json
Lucide React Icon library for React ISC https://github.com/lucide-icons/lucide webapp/package.json
React Flow (@xyflow/react) Node-based diagram UI (recon workflow / tool-node view) MIT https://github.com/xyflow/xyflow webapp/package.json
react-icons Popular icon packs as React components MIT https://github.com/react-icons/react-icons webapp/package.json
jose JavaScript JSON Web Token / JWE / JWS implementation MIT https://github.com/panva/jose webapp/package.json
bcryptjs Pure-JS bcrypt password hashing MIT https://github.com/dcodeIO/bcrypt.js webapp/package.json
Zod TypeScript-first schema validation MIT https://github.com/colinhacks/zod webapp/package.json
Archiver Streaming archive generation (ZIP) MIT https://github.com/archiverjs/node-archiver webapp/package.json
JSZip ZIP file creation and reading MIT (dual-licensed MIT/GPL-3.0; used by RedAmon under MIT) https://github.com/Stuk/jszip webapp/package.json
SheetJS (xlsx) Spreadsheet parser and writer Apache-2.0 https://github.com/SheetJS/sheetjs webapp/package.json
pdf-parse PDF text extraction MIT https://gitlab.com/nicola.zanon/pdf-parse webapp/package.json
Mammoth DOCX to HTML/Markdown converter BSD-2-Clause https://github.com/mwilliamson/mammoth.js webapp/package.json
d3-force Force-directed graph layout ISC https://github.com/d3/d3-force webapp/package.json
three-spritetext Text sprites for Three.js MIT https://github.com/vasturiano/three-spritetext webapp/package.json
TypeScript Typed JavaScript superset Apache-2.0 https://github.com/microsoft/TypeScript webapp/package.json (devDependency)
ESLint JavaScript/TypeScript linter MIT https://github.com/eslint/eslint webapp/package.json (devDependency)
Vitest Unit testing framework MIT https://github.com/vitest-dev/vitest webapp/package.json (devDependency)

Guinea Pig / Vulnerable Test Applications

These are intentionally vulnerable applications included for testing purposes only.

Application Purpose License Source Repository How Used
DVWS-Node Damn Vulnerable Web Services (Node.js) MIT https://github.com/snoopysecurity/dvws-node Cloned in testing/guinea_pigs/dvws-node/setup.sh
Log4Shell Vulnerable App Log4j RCE demonstration (CVE-2021-44228) Apache-2.0 https://github.com/christophetd/log4shell-vulnerable-app Docker image: ghcr.io/christophetd/log4shell-vulnerable-app:latest
vsftpd 2.3.4 Backdoored FTP server (CVE-2011-2523) GPL-2.0 N/A (pre-built image) Docker image: clintmint/vsftpd-2.3.4:1.0
Apache Tomcat 8.5.19 JSP upload RCE (CVE-2017-12617) Apache-2.0 https://github.com/vulhub/vulhub Docker image: vulhub/tomcat:8.5.19
Apache httpd 2.4.49 Path traversal RCE (CVE-2021-41773) Apache-2.0 https://github.com/apache/httpd Built from source in testing/guinea_pigs/apache_2.4.49/Dockerfile
Apache httpd 2.4.25 Auth bypass (CVE-2017-3167) Apache-2.0 https://github.com/apache/httpd Built from source in testing/guinea_pigs/apache_2.4.25/Dockerfile
node-serialize 0.0.4 Deserialization RCE demo MIT https://github.com/luin/serialize Built from testing/guinea_pigs/node_serialize_1.0.0/Dockerfile

Runtime Languages & Build Tools (in Agent Container)

The agent container (agentic/Dockerfile) bundles multiple language runtimes for code analysis:

Tool Version License How Used
Node.js 20 LTS MIT Installed in agentic/Dockerfile
Go 1.22.10 BSD-3-Clause Installed in agentic/Dockerfile
Ruby + Bundler System BSD-2-Clause / MIT Installed via apt-get in agentic/Dockerfile
OpenJDK + Maven Headless GPL-2.0 (w/ Classpath Exception) / Apache-2.0 Installed via apt-get in agentic/Dockerfile
PHP + Composer CLI PHP-3.01 / MIT Installed via apt-get in agentic/Dockerfile
.NET SDK 8 MIT Installed in agentic/Dockerfile
ripgrep System MIT / Unlicense (dual) Installed via apt-get in agentic/Dockerfile
Yarn Classic BSD-2-Clause JS package manager, npm install -g yarn in agentic/Dockerfile
pnpm Latest MIT JS package manager, npm install -g pnpm in agentic/Dockerfile
uv Latest Apache-2.0 / MIT (dual) Python package installer for uvx MCP servers, pip install uv in agentic/Dockerfile

AGPL-3.0 Source Code Availability

In compliance with the AGPL-3.0 license, the complete corresponding source code for all AGPL-licensed components is available at the repositories listed above. If you have received a RedAmon Docker image containing any of these tools and cannot access their source code at the listed repositories, please contact the maintainers at samuele@redamon.org and we will provide the source code.

License Compatibility Note

RedAmon's own source code is released under the MIT License.

Separate-process tools (CLI / Docker containers)

The majority of third-party tools are invoked as separate processes via CLI commands, Docker containers, or network APIs. Under the GPL, AGPL, and related copyleft licenses this constitutes "mere aggregation" (GPL v3 sec. 5, AGPL v3 sec. 5) and does not require RedAmon's own source code to adopt a copyleft license. Any modifications made to those tools themselves must still comply with their respective licenses.

GPL-3.0 libraries linked at the Python import level

The following GPL-3.0-licensed Python libraries are imported directly into RedAmon source code. Under the GPL-3.0, the resulting combined work in each container must be distributed under GPL-3.0-compatible terms:

Library License Container Source files affected
python-gvm GPL-3.0 gvm_scan All .py files in scanners/gvm_scan/
python-Wappalyzer GPL-3.0 recon Files in recon/ that import Wappalyzer

Accordingly, the Python source files listed above are dual-licensed MIT AND GPL-3.0. You may use, copy, and distribute them under either license. When they are combined with the GPL-3.0 libraries they import, the combined executable is governed by the GPL-3.0.

All other RedAmon source code (the webapp, the agent, the recon orchestrator, MCP servers, shell scripts, Dockerfiles, and configuration) remains under the MIT License only.

LGPL libraries

Several LGPL-licensed libraries (PyGithub, Paramiko, psycopg, ldap3) are used via standard Python imports or dynamic linking. The LGPL explicitly permits this without requiring the calling code to adopt LGPL or GPL terms, provided the libraries can be replaced or re-linked by the end user. Since RedAmon installs these via standard pip (user-replaceable), this condition is satisfied.

AGPL network-interaction obligation

AGPL-3.0 extends the GPL-3.0 copyleft to users who interact with the software over a network. Several tools in RedAmon (GVM/OpenVAS, Nuclei, Naabu, Katana, HTTPx, Subfinder, DNSx, Masscan, TruffleHog, Hydra, Kiterunner, Arjun) are AGPL-3.0. RedAmon does not modify any of these tools. Their unmodified source code is available at the repositories listed in this document. If you modify any AGPL-3.0 component and make it available over a network, you must offer the corresponding source code to users of that network service.


Last updated: September 2026