GitHub
The full console, core API and Go scanning engine live in the open. Releases and issue tracker are one click away.
AI-powered, open-source attack surface management. Continuously discover, monitor and secure your internet-facing assets, with AI agents that analyze every finding and guide remediation.
Powered by open-source scanners · deploy with Docker in minutes
Platform
OASM turns scattered scan output into one operational picture: every asset, service and exposure tracked over time.
Auto-discover internet-facing IPs, ports, services and technologies as a continuously updated inventory.
Discovery docs →IPs · ports · services · technologies
Detect vulnerabilities and misconfigurations, then track them with risk analysis and remediation guidance.
Assessment docs →severity · AI analysis · remediation
Fingerprint the frameworks, platforms and services running on every discovered asset.
Detection docs →frameworks · platforms · services
Organize assets into groups with their own tool configs and execution schedules.
Groups docs →groups · tool configs · schedules
A horizontally scalable worker fleet with fault-tolerant job distribution and a high-performance engine.
Workers docs →horizontally scalable worker fleet
Live notifications and a statistics dashboard fed by a streaming event channel.
Monitoring docs →live events · statistics dashboard
Your stack stays in sync: assets flow in automatically, findings push straight to your channels, with Jira ticketing on the way.
Integrations docs →cloud · code · notifications · ticketing
Install scanning tools platform-wide or per workspace, add third-party providers and manage their API keys from the console.
Tools docs →tool categories · providers · API keys
Capabilities
AI-powered security
Scans keep your attack surface current, AI analysis explains each critical risk, and the in-platform assistant helps your team remediate it.
// Ask OASM's assistant anything about your assets >
Community
Auditable code, a coordinated disclosure process and a place to ask questions.
The full console, core API and Go scanning engine live in the open. Releases and issue tracker are one click away.
Ask about deployment, connector authoring or scanning strategy. The maintainers are in the same channels as the operators.
Pricing
Self-host the full platform at no cost. Managed and on-premise support is on the way.
Open-source · GPL-3.0
Managed or on-premise
Self-hosted · GPL-3.0
Deploy with Docker in minutes. Your data never leaves your infrastructure.
Start free