Autonomous security reconnaissance engine with decision chaining β SQLi β users, LFI β files, CMD β shells, S3 β buckets, Upload β RCE
Not just another scanner β an autonomous security agent that chains attacks, extracts real data, and generates professional reports.
Forward-chaining AI scans for vulnerabilities and automatically spawns exploit modules β SQLi dumps user tables, LFI reads server files, CMD injection opens shells.
10 chain patterns β CORS+XSS, JWTβAdmin, SecretsβCloud, UploadβRCE. Each finding automatically triggers deeper exploitation across interconnected vectors.
Goes beyond detection β extracts SQL databases, LFI files, S3 bucket contents, deploys web shells, and dumps everything to reports/ organized by target.
Professional dark-theme reports with risk scoring, findings timeline, capabilities graph, extracted data summary, and credential inventory. Shareable with -R report.html.
All releases signed with GPG + Sigstore/cosign. SHA256 checksums verified. Supply-chain security with SLSA provenance and SPDX SBOM included every release.
Passive recon, crawl, fuzz, JWT forge, login brute, XSS, SQLi, GraphQL, S3 enum, LFI, CMD injection, upload, OOB server, port scan β all with auto-spawning chains.
Four ways to install, all with cryptographic verification.
Windows package manager
Windows native package manager
Cross-platform source build
Download from GitHub Releases
scoop bucket add nice-scan https://github.com/NICE-DEV226/nice-Scan
scoop install nice-scan/nice_scan
One command. Autonomous attack chaining. Real data extraction.
Full autonomous attack against any target β detects vulnerabilities and automatically exploits them.
nice_scan hack example.com -R report.html
Persistent REPL reconnaissance shell with command history, session context, and live results.
nice_scan shell
Real-time TUI dashboard with progress bars, findings stream, and live severity updates.
nice_scan scan example.com -i
Set a timeout to control engagement duration β ideal for bug bounties and CTFs.
nice_scan hack target.com --timeout 30s -R report.html
Dark-theme, risk-scored, evidence-backed β ready for client delivery or team collaboration.
Every release is cryptographically signed. Every install script verifies before extraction.
Checksum files signed with NICE-DEV226's GPG key. Verify with:
gpg --verify checksums.txt.sig checksums.txt
Keyless signing via GitHub OIDC. SLSA provenance with cosign bundles.
cosign verify-blob --bundle checksums.sigstore.json checksums.txt
Software Bill of Materials for every release β full dependency transparency.
syft scan nice_scan --from-release NICE-DEV226/nice-Scan:v0.1.0
Build integrity verified through Sigstore. Non-falsifiable provenance attestations.
gh attestation verify nice_scan_0.1.0_linux_amd64.tar.gz \
--repo NICE-DEV226/nice-Scan
Download the latest release and verify for yourself.
Latest Release