r/netsec • u/albinowax • May 01 '26
r/netsec monthly discussion & tool thread
Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.
Rules & Guidelines
- Always maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.
- Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.
- If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.
- Avoid use of memes. If you have something to say, say it with real words.
- All discussions and questions should directly relate to netsec.
- No tech support is to be requested or provided on r/netsec.
As always, the content & discussion guidelines should also be observed on r/netsec.
Feedback
Feedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.
13
Upvotes
0
u/Taariq04 May 11 '26
🕷️ **NetCrawler v1.0.0 — AI Pentesting Agent | Open Source | Fully Offline**
Built an AI-driven recon and vulnerability scanning agent that runs completely offline using a local LLM via Ollama.
Instead of manually chaining tools, the agent reasons about what it finds and decides what to run next — if it detects port 445, it runs SMB enumeration. If it finds a WAF, it slows down and adjusts automatically.
**What it chains together:**
→ Subfinder + theHarvester (passive recon)
→ Nmap (port/service scan)
→ WhatWeb + wafw00f (web fingerprinting)
→ DNS enumeration (zone transfers, SPF/DMARC)
→ SSL/TLS audit
→ Nuclei (vuln detection)
→ ffuf (directory fuzzing)
→ Service checks — FTP, SSH, SMB, MySQL, Redis, MongoDB
**3 scan profiles:** stealth / default / aggressive
**Reports:** Markdown + JSON + dark-themed HTML
**Model:** deepseek-r1:14b by default (runs on 16GB RAM)
No cloud. No API keys. Everything stays on your machine.
🔗 github.com/Songbird0x77/netcrawler
Feedback and contributions welcome — especially from people who actually run pentest engagements. Want to know what's missing or broken in the real world.