A single, near-dependency-free C++17 binary for Red Team reconnaissance and external attack-surface mapping. In one shot it expands the targets, scans ports (TCP or UDP), fingerprints services, harvests TLS certificates, and brute-forces web content (HTTP and HTTPS, recursively, over pooled keep-alive connections) - all sharing one DNS cache and one rate governor. Only libc, pthreads, and an optional OpenSSL. Point it at a host and it hands back a unified JSON graph of what is exposed.
Author: d3xm0s. Licensed MIT (see LICENSE) - it is yours to ship.
- One binary, near-zero dependencies. libc and pthreads, plus optional OpenSSL. Drops onto a jump box or a stripped container without a package manager in sight.
- One pipeline, one cache. Host expansion, port scan, banner grab, and content discovery reuse the same cached DNS answers and the same connection-rate budget, so nothing re-resolves and nothing stampedes.
- Pooled keep-alive discovery. Each discovery worker keeps a single HTTP/1.1 connection (TLS session included) alive across many requests, amortizing the handshake instead of paying it per path.
- Fingerprint and cert harvest. Web ports surface their title, Server, and X-Powered-By; HTTPS ports also give up the certificate subject, issuer, expiry, and every SAN - a fast way to discover more hostnames.
- WAF detection and coverage profiling.
--wafsends a benign and a hostile request and names the WAF in front (Cloudflare, Akamai, Imperva, F5, Sucuri, ModSecurity, and more), or flags a generic block.--waf-bypassgoes further and maps which payload classes (XSS, SQLi, traversal, command injection) and encodings the filter actually stops - a coverage report for authorized assessment, not a delivered exploit. It self-throttles on 429/503 with an adaptive backoff so the WAF's own rate limiting can't skew the map. - Recursive, soft-404 aware, authenticated. Discovery recurses into found
directories, auto-calibrates against wildcard servers, fuzzes extensions, and
carries your cookies or tokens via
-H. - Composable. Reads targets from args, a file, or stdin; writes JSON, JSONL, or CSV; and prints a plain URL list for piping. Ctrl-C still reports what it found.
- Rate governor built in.
--ratecaps new connections per second across every worker so you stay inside a rules-of-engagement budget.
Requires a C++17 compiler and CMake. OpenSSL is optional and, when present, unlocks HTTPS.
cmake -B build
cmake --build build -j
ctest --test-dir build # run the unit testsThe binary lands at build/redscout. The configure step prints whether HTTPS
was enabled. On Debian/Kali, apt install libssl-dev gets you the OpenSSL
headers if they are missing.
redscout <target...> [options]
target host, IPv4, or IPv4/CIDR (10.0.0.0/24), or IPv6/CIDR;
repeatable, or '-' to read targets from stdin
-iL, --target-file <f> read targets from a file (one per line)
modes:
-A, --auto turn everything on: all ports + WAF detection + content
discovery with the built-in wordlist (this is the default)
-F, --fast top ports only, skip WAF and discovery
scan:
-p, --ports <spec> 22,80,443 | 1-1024 | top | all
(default: all; --fast uses top)
-w, --workers <n> concurrent connections (default: 512)
-t, --timeout <ms> connect timeout in ms (default: 1200)
-r, --retries <n> retries before a port is filtered (default: 1)
--rate <pps> cap new connections per second (default: off)
--udp probe UDP instead of TCP (reply=open, silence=filtered)
--waf detect a WAF in front of web ports and its vendor
--waf-bypass profile which payload classes the WAF blocks (implies --waf)
--no-probe skip banner grabbing
content discovery:
-d, --discover brute paths on discovered HTTP/HTTPS ports
-W, --wordlist <file> path list for discovery (optional; built-in list if omitted)
--depth <n> recurse into found directories n levels (default: 0)
-H, --header <line> extra request header, repeatable (cookies, auth)
-x, --extensions <csv> also try each word with these suffixes (.php,.bak)
--filter-size <n> drop discovery hits with these body sizes (csv)
--filter-status <n> drop discovery hits with these status codes (csv)
--no-autofilter do not auto-detect and drop soft-404 responses
output:
-o, --output <file> write a report to a file
--format <fmt> report format: json | jsonl | csv (default: json)
--print-urls print discovered URLs to stdout (for piping)
-q, --quiet quiet: no banner or progress counter
-v, --version print version and exit
-h, --help show this help
# Auto mode (default): all 65535 ports + WAF detection + content discovery with
# the built-in wordlist, flagging tcpwrapped / phantom ports - one command
redscout 192.168.56.101
# Quick look: top ports only, no WAF, no discovery
redscout 192.168.56.101 --fast
# Auto mode on a subnet, throttled, JSON report
redscout 10.10.10.0/24 -w 1024 --rate 500 -o scan.json
# Scan then brute web content (HTTP and HTTPS) with extension fuzzing, two deep
redscout target.internal -p 80,443,8080,8443 -d -W wordlists/common.txt \
-x php,bak,json --depth 2 -o out.json
# Authenticated discovery, targets from a file, URLs to stdout for the next tool
redscout -iL scope.txt -p 443 -d -W wordlists/common.txt \
-H "Cookie: session=abc123" --print-urls | tee urls.txt
# UDP sweep of common service ports
redscout 10.0.0.0/24 --udp -p 53,123,161,500
# Identify the WAF in front of a host before spending time on it
redscout target.internal -p 80,443 --waf
# Map which payload classes and encodings the WAF actually blocks
redscout target.internal -p 443 --waf-bypasstarget- expands host / IPv4 / IPv4-CIDR / IPv6-CIDR specs and parses the port spec (topis a curated ~110-port list;all/-is the full 1-65535 range).resolver- process-wide DNS cache; a host resolves once and later lookups just stamp in the port.net- the shared TCP core: non-blockingconnect()+poll(), timed reads, response flattening.scanner- fans host x port across a worker pool, classifies open / closed / filtered (TCP or UDP), grabs banners, fingerprints web ports, and flagstcpwrappedports (handshake completes but no service answers - a tcpwrapper or a path middlebox), both per connection and by cross-host correlation.probe- service labelling and plaintext banner logic.httpconn- pooled keep-alive HTTP/1.1 client (plain or TLS) with proper Content-Length / chunked framing, used for discovery and fingerprinting.tls- optional OpenSSL layer: TLS sessions, one-shot exchanges, and certificate extraction.buster- wordlist discovery with recursion, extensions, custom headers, and soft-404 / size / status filtering; ships a built-in path list so auto mode needs no wordlist file.waf- WAF fingerprinting via a benign/hostile request pair and a vendor signature table, plus payload-class coverage profiling with adaptive backoff on rate limiting.control- the Ctrl-C stop flag the worker loops cooperate with.report- console output plus JSON / JSONL / CSV and a URL list.
wordlists/common.txt is a starter list (~230 entries) covering admin panels,
config and secret files, VCS metadata, API surfaces, and framework tells. Point
-W at any newline-delimited list to go bigger.
redscout sends real connections and real HTTP requests to whatever you aim it
at. Run it only against hosts and networks you own or have explicit written
authorization to test. Unauthorized scanning is illegal in most jurisdictions
and will trip intrusion detection and abuse policies. Keep your rules of
engagement in reach and use --rate to stay inside them.
Инструмент Red Team для внешней разведки и картирования поверхности атаки - один самодостаточный бинарник на C++17 (почти без зависимостей). За один запуск он раскрывает цели, сканирует порты (TCP или UDP), определяет сервисы, собирает TLS-сертификаты и перебирает веб-контент (HTTP и HTTPS, рекурсивно, через пул keep-alive соединений) - всё через общий DNS-кэш и общий rate-губернатор. Только libc, pthreads и опциональный OpenSSL. Наводишь на хост - получаешь единый JSON-граф того, что открыто наружу.
Автор: d3xm0s. Лицензия MIT (см. LICENSE) - инструмент ваш, публикуйте свободно.
- Один бинарник, почти без зависимостей. libc и pthreads, плюс опциональный OpenSSL. Кладётся на jump box или в урезанный контейнер без пакетного менеджера.
- Один конвейер, один кэш. Раскрытие хостов, скан портов, снятие баннеров и перебор используют одни закэшированные ответы DNS и один бюджет скорости соединений: ничего не резолвится повторно и не штурмует цель.
- Перебор на пуле keep-alive. Каждый воркер держит одно HTTP/1.1 соединение (включая TLS-сессию) на множество запросов, амортизируя handshake вместо оплаты его на каждый путь.
- Фингерпринт и сбор сертификатов. Веб-порты выдают title, Server и X-Powered-By; HTTPS-порты дополнительно отдают subject, издателя, срок и все SAN сертификата - быстрый способ найти новые хостнеймы.
- Детект WAF и профиль покрытия.
--wafшлёт безобидный и «атакующий» запрос и называет WAF перед целью (Cloudflare, Akamai, Imperva, F5, Sucuri, ModSecurity и др.) либо отмечает generic-блокировку.--waf-bypassидёт дальше и составляет карту того, какие классы payload'ов (XSS, SQLi, traversal, command injection) и кодировки фильтр реально останавливает - отчёт о покрытии для авторизованной оценки, а не готовый эксплойт. При 429/503 он сам сбавляет темп (адаптивный backoff), чтобы собственный rate-limit WAF не исказил карту. - Рекурсия, учёт мягких 404, аутентификация. Перебор уходит вглубь найденных
каталогов, калибруется против wildcard-серверов, фаззит расширения и несёт
ваши куки/токены через
-H. - Композиция. Читает цели из аргументов, файла или stdin; пишет JSON, JSONL или CSV; печатает список URL для пайпа. Ctrl-C всё равно выдаёт найденное.
- Встроенный rate-губернатор.
--rateограничивает число новых соединений в секунду по всем воркерам, чтобы держаться внутри рамок RoE.
Нужен компилятор C++17 и CMake. OpenSSL опционален и при наличии включает HTTPS.
cmake -B build
cmake --build build -j
ctest --test-dir build # прогнать юнит-тестыБинарник появится в build/redscout. На этапе конфигурации печатается, включён
ли HTTPS. На Debian/Kali заголовки OpenSSL ставятся через apt install libssl-dev.
redscout <target...> [options]
target хост, IPv4, IPv4/CIDR (10.0.0.0/24) или IPv6/CIDR;
повторяемый, или '-' для чтения целей из stdin
-iL, --target-file <f> читать цели из файла (по одной на строку)
режимы:
-A, --auto включить всё сразу: все порты + WAF-детект + перебор
контента встроенным словарём (поведение по умолчанию)
-F, --fast только top-порты, без WAF и перебора
скан:
-p, --ports <spec> 22,80,443 | 1-1024 | top | all
(по умолчанию: all; при --fast - top)
-w, --workers <n> число одновременных соединений (по умолчанию: 512)
-t, --timeout <ms> таймаут connect в мс (по умолчанию: 1200)
-r, --retries <n> повторы, прежде чем порт признан filtered (по умолчанию: 1)
--rate <pps> лимит новых соединений в секунду (по умолчанию: выкл.)
--udp зондировать UDP вместо TCP (ответ=open, тишина=filtered)
--waf определить WAF перед веб-портами и его вендора
--waf-bypass профилировать, какие классы payload'ов блокирует WAF (влечёт --waf)
--no-probe не снимать баннеры
перебор контента:
-d, --discover перебор путей на найденных HTTP/HTTPS портах
-W, --wordlist <file> словарь путей (необязателен; без него - встроенный)
--depth <n> рекурсия в найденные каталоги на n уровней (по умолчанию: 0)
-H, --header <line> дополнительный заголовок запроса, повторяемый (куки, авторизация)
-x, --extensions <csv> также пробовать каждое слово с этими суффиксами (.php,.bak)
--filter-size <n> отбрасывать находки с этими размерами тела (через запятую)
--filter-status <n> отбрасывать находки с этими кодами ответа (через запятую)
--no-autofilter не определять и не отсеивать мягкие 404 автоматически
вывод:
-o, --output <file> записать отчёт в файл
--format <fmt> формат отчёта: json | jsonl | csv (по умолчанию: json)
--print-urls печатать найденные URL в stdout (для пайпа)
-q, --quiet тихий режим: без баннера и счётчика прогресса
-v, --version вывести версию и выйти
-h, --help показать эту справку
# Частые порты на одном хосте (title, Server и сертификат берутся автоматически)
redscout 192.168.56.101
# Весь диапазон на лабораторной подсети, с троттлингом, JSON-отчёт
redscout 10.10.10.0/24 -p 1-65535 -w 1024 --rate 500 -o scan.json
# Скан, затем перебор веб-контента (HTTP и HTTPS) с фаззингом расширений, вглубь на 2
redscout target.internal -p 80,443,8080,8443 -d -W wordlists/common.txt \
-x php,bak,json --depth 2 -o out.json
# Авторизованный перебор, цели из файла, URL в stdout для следующего инструмента
redscout -iL scope.txt -p 443 -d -W wordlists/common.txt \
-H "Cookie: session=abc123" --print-urls | tee urls.txt
# UDP-обход частых сервисных портов
redscout 10.0.0.0/24 --udp -p 53,123,161,500
# Определить WAF перед хостом, прежде чем тратить на него время
redscout target.internal -p 80,443 --waf
# Карта того, какие классы payload'ов и кодировки WAF реально блокирует
redscout target.internal -p 443 --waf-bypasstarget- раскрывает host / IPv4 / IPv4-CIDR / IPv6-CIDR и разбирает спецификацию портов (top- список ~110 частых портов;all/-- полный диапазон 1-65535).resolver- общий на процесс DNS-кэш: хост резолвится один раз, дальше только подставляется порт.net- общее TCP-ядро: неблокирующийconnect()+poll(), чтения с таймаутом, схлопывание ответа.scanner- раскидывает «хост x порт» по пулу воркеров, различает open / closed / filtered (TCP или UDP), снимает баннеры, фингерпринтит веб-порты и помечаетtcpwrapped-порты (handshake прошёл, но сервис молчит - tcpwrapper или middlebox на пути): по одному соединению и по кросс-хостовой корреляции.probe- маркировка сервисов и логика баннеров открытым текстом.httpconn- пул keep-alive HTTP/1.1 клиента (обычного и TLS) с корректным разбором Content-Length / chunked, используется для перебора и фингерпринта.tls- опциональный слой OpenSSL: TLS-сессии, одноразовые обмены и извлечение сертификата.buster- перебор по словарю с рекурсией, расширениями, своими заголовками и отсевом мягких 404 / по размеру / по статусу.waf- фингерпринт WAF парой запросов (безобидный/атакующий) и таблицей сигнатур вендоров, плюс профилирование покрытия по классам payload'ов с адаптивным backoff при rate-limit.control- флаг остановки по Ctrl-C, с которым кооперируют воркеры.report- консольный вывод плюс JSON / JSONL / CSV и список URL.
wordlists/common.txt - стартовый список (~230 записей): админ-панели, файлы
конфигов и секретов, метаданные VCS, поверхности API и признаки фреймворков.
Укажите -W на любой список с одним путём на строку, чтобы взять шире.
redscout шлёт реальные соединения и реальные HTTP-запросы туда, куда вы его
наводите. Запускайте его только против хостов и сетей, которыми владеете или на
тестирование которых есть письменное разрешение. Несанкционированное
сканирование незаконно в большинстве юрисдикций и поднимет системы обнаружения и
жалобы. Держите rules of engagement под рукой и используйте --rate, чтобы не
выходить за их пределы.
