v0.1.0 β€” Public Release

Fast. Precise. Intelligent.

Autonomous security reconnaissance engine with decision chaining β€” SQLi β†’ users, LFI β†’ files, CMD β†’ shells, S3 β†’ buckets, Upload β†’ RCE

terminal β€” nice_scan hack example.com -R report.html
[0s] β–Έ Passive Reconnaissance OK (3 endpoints)
[2s] β–Έ Crawl Endpoints OK (47 paths)
[4s] β—ˆ SQL Injection !! CRITICAL β€” login.php
[5s] β”” SQLi Data Extract OK (142 users dumped)
[7s] β—ˆ LFI !! CRITICAL β€” /etc/passwd
[8s] β”” LFI File Read OK (12 files extracted)
[10s] β–Έ Risk Score 10.0 / 10 β€” report.html saved

Why NICE_SCAN?

Not just another scanner β€” an autonomous security agent that chains attacks, extracts real data, and generates professional reports.

Decision Engine

Forward-chaining AI scans for vulnerabilities and automatically spawns exploit modules β€” SQLi dumps user tables, LFI reads server files, CMD injection opens shells.

Attack Chaining

10 chain patterns — CORS+XSS, JWT→Admin, Secrets→Cloud, Upload→RCE. Each finding automatically triggers deeper exploitation across interconnected vectors.

Real Data Extraction

Goes beyond detection β€” extracts SQL databases, LFI files, S3 bucket contents, deploys web shells, and dumps everything to reports/ organized by target.

HTML Attack Reports

Professional dark-theme reports with risk scoring, findings timeline, capabilities graph, extracted data summary, and credential inventory. Shareable with -R report.html.

Trust Verification

All releases signed with GPG + Sigstore/cosign. SHA256 checksums verified. Supply-chain security with SLSA provenance and SPDX SBOM included every release.

14 Attack Modules

Passive recon, crawl, fuzz, JWT forge, login brute, XSS, SQLi, GraphQL, S3 enum, LFI, CMD injection, upload, OOB server, port scan β€” all with auto-spawning chains.

0 Exploit Modules
0 Chain Patterns
0 Attack Actions
0 Platforms

Get NICE_SCAN

Four ways to install, all with cryptographic verification.

🍺

Scoop

Windows package manager

πŸ“¦

Winget

Windows native package manager

⚑

Go Install

Cross-platform source build

πŸ“₯

Manual

Download from GitHub Releases

powershell
scoop bucket add nice-scan https://github.com/NICE-DEV226/nice-Scan
scoop install nice-scan/nice_scan

From Zero to Exploit

One command. Autonomous attack chaining. Real data extraction.

01

Quick Scan

Full autonomous attack against any target β€” detects vulnerabilities and automatically exploits them.

nice_scan hack example.com -R report.html
02

Interactive Shell

Persistent REPL reconnaissance shell with command history, session context, and live results.

nice_scan shell
03

Live Dashboard

Real-time TUI dashboard with progress bars, findings stream, and live severity updates.

nice_scan scan example.com -i
04

Time-Boxed Attack

Set a timeout to control engagement duration β€” ideal for bug bounties and CTFs.

nice_scan hack target.com --timeout 30s -R report.html

Professional HTML Reports

Dark-theme, risk-scored, evidence-backed β€” ready for client delivery or team collaboration.

β—ˆ Attack Report β€” example.com 10.0 / 10
v0.1.0 β€’ 14 actions β€’ 8 chained steps β€’ 25s elapsed
Findings
!!
SQL Injection
login.php β€” 142 users extracted
!!
Local File Inclusion
/etc/passwd, /etc/shadow, .env, config.php (12 files)
β–Έ
CORS Misconfiguration
api.example.com β€” allows all origins
β—ˆ
JWT Weak Secret
alg=none accepted, secret brute-forced
Extracted Data
Users 142 records
Files 12 LFI + 3 config
Credentials 8 found
Endpoints 47 discovered
Shells 1 deployed

Supply Chain Security

Every release is cryptographically signed. Every install script verifies before extraction.

πŸ”‘

GPG Signatures

Checksum files signed with NICE-DEV226's GPG key. Verify with:

gpg --verify checksums.txt.sig checksums.txt
πŸ›‘οΈ

Sigstore / cosign

Keyless signing via GitHub OIDC. SLSA provenance with cosign bundles.

cosign verify-blob --bundle checksums.sigstore.json checksums.txt
πŸ“‹

SPDX SBOM

Software Bill of Materials for every release β€” full dependency transparency.

syft scan nice_scan --from-release NICE-DEV226/nice-Scan:v0.1.0
βœ…

SLSA Level 2

Build integrity verified through Sigstore. Non-falsifiable provenance attestations.

gh attestation verify nice_scan_0.1.0_linux_amd64.tar.gz \
  --repo NICE-DEV226/nice-Scan

Download the latest release and verify for yourself.

Latest Release