ENNAENNA

Tsunami

Apache-2.0

๐ŸŒ Network Recon ยท Java

Tsunami is a network security scanner developed by Google designed for detecting high-severity vulnerabilities with high confidence at scale. It operates in two phases: first scanning for open ports and services using nmap/ncrack integration, then running vulnerability detection plugins against discovered services. Tsunami focuses on minimizing false positives and only reports vulnerabilities it can verify. Its plugin system allows community contributions for new vulnerability checks. Designed for enterprise-scale networks where manual verification of every finding is impractical.

8.6kstars
921forks
8issues
Updated 11d ago
+I use this

Installation

$ git clone https://github.com/google/tsunami-security-scanner.git && cd tsunami-security-scanner && ./gradlew shadowJar

Use Cases

  • Large-scale network vulnerability detection
  • Automated verification of high-severity vulnerabilities
  • Continuous security scanning of enterprise infrastructure
  • Service discovery and fingerprinting at scale

Tags

vulnerability-scannernetwork-scanninggoogleplugin-systementerprise-scale

Community Reviews

More in Network Recon