Skip to content

Latest commit

 

History

History
247 lines (194 loc) · 13.7 KB

File metadata and controls

247 lines (194 loc) · 13.7 KB
title Vigolium
description High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision
mode wide

Vigolium Workbench showing scan overview with severity breakdown and individual finding details

Vigolium is a high-fidelity web vulnerability scanner that fuses agentic AI with native speed, modularity, and precision. It combines deterministic multi-phase scanning with AI-driven autonomous analysis to deliver comprehensive security coverage, from injection flaws and access control issues to framework-specific vulnerabilities and blind out-of-band attacks.

The platform is built around three key components that work together to provide a complete vulnerability scanning solution.

Key Components

The core scanning engine. Handles all scanning logic, module execution, and heavy lifting, from content discovery and browser-based spidering to active fuzzing and agentic AI scanning. A self-hosted dashboard for visualizing scan results, managing projects, and tracking findings across your infrastructure. Deploy it on your own servers for full control over your data. A cloud-based solution that provides managed scanning, team collaboration, and centralized reporting without the overhead of self-hosting.

Installation

```bash curl -fsSL https://vigolium.com/install.sh | bash ``` Installs `~/.local/bin/vigolium` and adds it to your shell profile. The installer verifies the SHA-256 checksum before installing. ```bash npm install -g @vigolium/vigolium ``` Thin launcher that pulls the prebuilt binary for your platform as an optional dependency (Node 16+). ```bash bun add -g @vigolium/vigolium ``` Installs the Vigolium launcher globally with Bun. Same prebuilt-binary launcher as the npm install path; Bun is just a faster package manager. ```bash brew install vigolium/tap/vigolium ``` Installs the latest release from the Vigolium tap on macOS and Linux. Upgrade with `brew upgrade vigolium`. ```bash docker pull j3ssie/vigolium:latest docker run --rm j3ssie/vigolium:latest scan -h ``` The container entrypoint is the `vigolium` binary, pass any subcommand directly. ```bash git clone https://github.com/vigolium/vigolium.git cd vigolium make build ``` Requires Go 1.27+, Bun 1.3.11+, `git`, and `make`. Always use `make build` (not `go build`), it injects version metadata. ```powershell npm install -g @vigolium/vigolium ``` Vigolium ships a native **windows/amd64** build since v0.4.3. The npm launcher is the easiest path; alternatively download `vigolium__windows_amd64.zip` from the [releases page](https://github.com/vigolium/vigolium/releases) and put `vigolium.exe` on your `PATH`. `curl | bash` and Homebrew are POSIX-only, and `vigolium update` cannot self-update on Windows — it prints the zip to download instead. Windows on ARM installs the x64 build and runs it under emulation.

For a guided walkthrough including validation and your first scan, see the Quickstart.


Scanning Mode

Agentic Scan

Agentic scanning uses AI agents to drive or augment the scanning process. Invoked via vigolium agent <mode>. All AI dispatch is routed through the in-process olium engine, which supports eleven providers: openai-codex-oauth, anthropic-api-key, anthropic-oauth, openai-api-key, openai-responses, anthropic-cli, anthropic-claude-sdk-bridge, anthropic-compatible, anthropic-vertex, google-vertex, and openai-compatible (Ollama / OpenRouter / LM Studio / vLLM).

Mode Command Description
Query vigolium agent query Single-shot prompt execution. Good for code review, endpoint discovery, secret detection. No network scanning.
Autopilot vigolium agent autopilot Autonomous AI-driven pentest. The olium engine discovers endpoints, runs scans, and triages findings on its own, driving Bash, file ops, and first-class Vigolium tools until it calls halt_scan. Supports diff-focused runs (--diff), prior/knowledge-base context, intensity presets, and durable-mode resume.
Swarm vigolium agent swarm AI-guided pipeline for targeted single-request or full-scope (--discover) scanning. The master agent selects modules, generates custom JS scanner extensions, runs code audit and SAST, executes scans, and triages results, with native Go handling the heavy lifting while AI intervenes at checkpoints.
Audit vigolium agent audit Unified whitebox security audit driver (lite / balanced / deep). Runs the embedded vigolium-audit harness, the standalone piolium harness, or both side-by-side under one parent scan.
Piolium vigolium agent audit --driver=piolium Pi-native whitebox audit driver (separate install). Up to 17 phases at deep, the most thorough audit available.
Olium vigolium olium / vigolium ol Interactive TUI chat or one-shot non-interactive prompt, the underlying agent runtime.

All scan-oriented modes support --source for source-aware analysis and store session artifacts (plans, extensions, output) under ~/.vigolium/agent-sessions/.

Native Scan

Deterministic, multi-phase vulnerability scanning via vigolium scan. Fast, modular, and repeatable, runs content discovery, browser spidering, SPA crawling, and active/passive dynamic-assessment phases with 323 scanner modules (207 active, 116 passive).

Category Coverage
Injection XSS (reflected, DOM-based, SSR hydration), SQL injection (error-based, boolean/time-blind), NoSQL injection, SSTI/CSTI, CRLF injection, command injection, XXE/SAML, prototype pollution
Access Control CSRF, IDOR, authorization bypass, mass assignment, forbidden bypass, HTTP method tampering
File & Path LFI, path traversal, file upload flaws, directory listing, backup/sensitive file discovery, path normalization bypass
API & Protocol GraphQL security suite (introspection, SQLi, IDOR/BOLA, DoS, batching), MCP server security (tool/resource/prompt fuzzing, session & origin checks), SSRF (direct & blind), open redirect, HTTP request smuggling, JWT vulnerabilities, JSONP callback, WebSocket security, race conditions
Framework-Specific Spring Boot, Django, Laravel, Rails, Express, Next.js, Nuxt, Remix, ASP.NET/Blazor, IIS, Flask, FastAPI
Enterprise & SaaS Platforms Adobe Experience Manager (dispatcher bypass, sensitive servlets, RCE-surface exposure, CVE probes), Salesforce Experience Cloud (Aura object/record exposure, guest Apex execution, Lightning debug mode), ServiceNow (widget & KB data exposure), Microsoft Power Pages (Dataverse Web API exposure)
CMS WordPress (XML-RPC, user enum, AJAX exposure), Drupal, Joomla, CMS installer exposure
Cloud & Infra Firebase (RTDB, storage, auth, functions), cloud storage listing/takeover, default credentials, web cache poisoning, CORS misconfiguration
Out-of-Band Blind vulnerabilities via OAST callbacks (blind SSRF, blind SSTI, OAST probes)

Vigolium CLI

The CLI is the heart of Vigolium, powering all scanning operations with two complementary modes:

CLI Highlights

  • Value-aware mutation: classify parameter values by semantic type and generate intelligent mutations
  • Multi-phase pipeline: external harvesting, content discovery, SPA crawling, and audit controlled by strategy presets
  • Scanning profiles: bundle strategy, pace, scope, and module config into a single YAML file
  • Multiple input formats: URLs, OpenAPI/Swagger, WSDL/SOAP, Postman, Burp Suite, cURL, Nuclei JSONL
  • Browser-based spider: Chromium-driven crawler with SPA support, form filling, and JS analysis
  • Multi-session authentication: inline sessions, session files, or full auth configs with login flows and token extraction
  • JavaScript extensions: custom modules and hooks via embedded JS engine
  • Source-aware agentic scan: pair --source with swarm, autopilot, or audit for code-context-aware AI scanning and audit
  • Concurrent architecture: configurable worker pool with per-host rate limiting and hybrid queue
  • HTML reports: self-contained HTML reports with sortable/filterable tables
  • API server mode: REST API with Swagger UI, multi-format ingestion, transparent HTTP proxy

Vigolium Workbench

A self-hosted web dashboard that provides a visual interface for managing and analyzing your scan data. Deploy Workbench on your own infrastructure to maintain complete control over your vulnerability data while giving your team an intuitive way to:

  • Browse and filter scan findings with severity breakdown per project
  • Track vulnerability trends across repositories and scan history
  • Manage multiple projects with multi-tenancy support
  • View detailed request/response evidence for each finding

Workbench project overview showing scan summary and severity counts

Workbench findings list with severity filters and search

Workbench detailed finding view showing HTTP request and response evidence

Workbench scan history view with vulnerability trend tracking

CLI Native Scan

CLI Native Scan 2

Self-contained HTML report showing vulnerability summary with severity chart

Self-contained HTML report with sortable and filterable findings table


Vigolium Cloud Console

A cloud-based solution for teams that want the power of Vigolium without managing infrastructure. Console is the upgraded, fully-featured version of Vigolium, managed scanning, centralized reporting, team collaboration, and extra features layered on top of the open-source core, so you can focus on fixing vulnerabilities instead of maintaining tooling.

Check out the Cloud Console at [console.vigolium.com](https://console.vigolium.com/).

Vigolium Console native scan view

Vigolium Console agentic scan view

Open-source audit project list

Open-source audit findings detail


Where to Go Next

I want to... Start here
Get up and running quickly Quickstart
Understand how native scanning works How It Works
Pick the right scanning strategy Strategies
Dive into individual scan phases Phases, discovery, spidering, audit, extension, SPA
Try agentic scanning Agent Mode
Let AI drive scans autonomously Autopilot
Run multi-phase AI + native pipelines Swarm
Audit source code in depth Agentic Security Audit
Chat with the agent runtime Olium
Run Vigolium as an API server Server Mode
Tweak scan settings Configuration
Export and format results Output & Reporting
Write custom JS extensions Writing Extensions
Browse the REST API API References

For any inquiries, feel free to contact us at contact@vigolium.com.