{"repo":"rivalsec/autobb","free":true,"listed":false,"github":"https://github.com/rivalsec/autobb","clone":"git clone https://github.com/rivalsec/autobb.git","description":"External attack surface monitoring & vulnerability automation","language":"Python","stars":25,"topics":["automation","bugbounty","docker","reconnaissance","scanner","subdomain-enumeration","easm","easm-core"],"license":null,"category":"workflow-automation","readme_excerpt":"AutoBB Continuous external attack surface monitoring & vulnerability automation — self-hosted, runs continuously in Docker. AutoBB discovers your internet-facing assets, tracks how they change over time, scores findings by risk, scans them for vulnerabilities, and alerts you on anything new. It keeps a persistent asset inventory in MongoDB and re-checks it on a schedule, so it's a continuous monitor — not a one-shot recon script. Built for bug bounty hunters (be first to a new or changed asset on a large program) and security teams / companies (know your external attack surface and get alerted the moment it shifts). Core loop: discover assets → track changes → score risk → scan for vulns → alert. What it does - Continuous asset discovery — passive OSINT (subfinder), DNS brute-force (puredns), permutations (dnsgen), and resolution (dnsx) to find subdomains and live hosts. - Persistent asset inventory — every domain, HTTP service, open port, and finding is stored in MongoDB ( domains , http probes , ports , nuclei hits , nuclei passive hits , http paths , secret hits ). - Change detection — diffs each scan against the last and records a per-field diff history, so you're alerted on real changes and not re-alerted on oscillating values (e.g. rotating CDN CNAMEs). - Risk scoring (\"juicy\") — surfaces the interesting findings first: out-of-scope CNAMEs/certs, services on non-80/443 ports, external redirects, fuzzed paths that flipped 4xx → 200 , and more. - Vulnerability scanning — ","default_branch":null,"files":null,"tree":[],"storefront":"/r/rivalsec","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/rivalsec/autobb/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}