OASM logoOASM
Open source · Self-hosted · GPL-3.0

The attack surface platform security teams build on

AI-powered, open-source attack surface management. Continuously discover, monitor and secure your internet-facing assets, with AI agents that analyze every finding and guide remediation.

OASM console overview dashboard showing asset, service and technology totals, findings by severity and a geographic map of the scanned attack surface

Powered by open-source scanners · deploy with Docker in minutes

Subdomain discoveryPort scanningHTTP probingVulnerability checksEnterprise scans

Platform

One platform for your entire attack surface.

OASM turns scattered scan output into one operational picture: every asset, service and exposure tracked over time.

Asset discovery & management

Auto-discover internet-facing IPs, ports, services and technologies as a continuously updated inventory.

Discovery docs →

IPs · ports · services · technologies

Vulnerability assessment

Detect vulnerabilities and misconfigurations, then track them with risk analysis and remediation guidance.

Assessment docs →
CVE-XXXX-XXXXCritical
TLS 1.0 exposedHigh
Missing HSTSMedium

severity · AI analysis · remediation

Technology detection

Fingerprint the frameworks, platforms and services running on every discovered asset.

Detection docs →
CloudflareNginxApacheNext.jsReactWordPressNode.jsPHPLaravelPostgreSQLMySQLRedisGoKubernetesDockerGoogle Analytics

frameworks · platforms · services

Groups & targeted scanning

Organize assets into groups with their own tool configs and execution schedules.

Groups docs →
ProductionDaily · 02:00
api.acme.ioapp.acme.io
StagingWeekly · Sun
stg.acme.io

groups · tool configs · schedules

Distributed scanning engine

A horizontally scalable worker fleet with fault-tolerant job distribution and a high-performance engine.

Workers docs →
core enginew1w2w3w4w5

horizontally scalable worker fleet

Real-time monitoring

Live notifications and a statistics dashboard fed by a streaming event channel.

Monitoring docs →
DashboardLive
Targets0
Assets0
Services0
Technologies0
Vulnerabilities0
Critical0
High0
Open issues0
TLS expired0
New asset discovered

live events · statistics dashboard

Integrations & alerting

Your stack stays in sync: assets flow in automatically, findings push straight to your channels, with Jira ticketing on the way.

Integrations docs →
Slack
Telegram
AWS
GCP
Cloudflare
Vercel
Jira
GitHub
GitLab
OASM

cloud · code · notifications · ticketing

Extensible security tools

Install scanning tools platform-wide or per workspace, add third-party providers and manage their API keys from the console.

Tools docs →
Subdomain discoveryPort scanningHTTP probingVulnerability scanningScreenshots
OASMOASM

tool categories · providers · API keys

Capabilities

Subdomain discovery
Port scanning
HTTP probing
Vulnerability checks
Visual capture
Enterprise scans
URL discovery
CMS checks

AI-powered security

AI analysis on every finding, before attackers act.

Scans keep your attack surface current, AI analysis explains each critical risk, and the in-platform assistant helps your team remediate it.

  • Agent mode plans and runs multi-step analysis on live workspace data
  • Just ask — answers in natural language, streamed tool call by tool call
  • Bring your own model: OpenAI, Anthropic or any compatible provider
AI agent docs →
// Ask OASM's assistant anything about your assets
> 

ASK ANYTHING · AI AGENTS · CONTINUOUS TESTING · REMEDIATION GUIDANCE

Community

Built in the open.

Auditable code, a coordinated disclosure process and a place to ask questions.

SOURCE, ISSUES, DISCUSSIONS

GitHub

The full console, core API and Go scanning engine live in the open. Releases and issue tracker are one click away.

OASM-PLATFORM / OPEN-ASMOpen the repository →
MAINTAINERS AND OPERATORS

Discord

Ask about deployment, connector authoring or scanning strategy. The maintainers are in the same channels as the operators.

DISCORD.GG / FWQBNHXR8HJoin the community →

Pricing

Free and open source, forever.

Self-host the full platform at no cost. Managed and on-premise support is on the way.

SELF-HOSTED

Free

Open-source · GPL-3.0

  • Unlimited targets, assets and scans
  • Domain, IP and CIDR discovery with internal/external scope
  • Subdomain, port, HTTP and screenshot scanning tools
  • Extensible tool & provider framework for modern security scanners
  • Technology, service and TLS certificate monitoring
  • Vulnerability assessment with AI analysis and remediation
  • Issue tracking with open/closed states and comments
  • Asset inventory with pivot views, filters and CSV export
  • Scheduled workflows, asset groups and job registry
  • Statistics dashboard, global search and PDF reports
  • Alerts, distributed workers, RBAC and full API access
ENTERPRISE

Custom

Managed or on-premise

Coming soon

Self-hosted · GPL-3.0

See your attack surface clearly.

Deploy with Docker in minutes. Your data never leaves your infrastructure.

Start free