GitHub repositories

XSISEC Framework 2K

End-to-end workflow for scope, recon, testing, findings, and reporting in one place. The framework combines a curated security toolbox, a deep test-case library, structured evidence handling, PDF export, and a reproducible Docker-based recon environment.

10
Repositories
5
Languages
5
Stars
2
Forks

Capabilities

Target & Scope Control

Capture program rules, in-scope assets, SLAs, and constraints. Prevent scope-creep with visible guardrails and tags for priority/risk.

Recon Automation

Opinionated sequences for subdomains, ASN/WHOIS, live host discovery, JS asset surfacing, content discovery, and dorking — mapped to concrete tools and commands.

Toolbox with Recipes

Curated commands for assetfinder, subfinder, httpx, naabu, nuclei, ffuf, dnsx, gau/gauplus, hakrawler, gospider, httprobe, asnmap and more. Docker image optional.

Test-Case Library (~548 notes)

Reusable inspiration across XSS, CSRF, SSRF, SQLi, GraphQL, MFA/session, and SSO/OIDC/SAML — balanced for real-world surfaces.

Findings Management

Track vulnerabilities with severity, CWE/CVE references, CVSS placeholders, asset links, reproduction steps, and remediation status.

Evidence Capture & Media

Attach PoC screenshots and artifacts straight into Markdown notes and reports through the optional Supabase flow.

Templates & Reuse

Nuclei-style checks, saved queries, and reusable snippets keep tests consistent while staying agile.

Privacy & Safety

Run tools only against authorized targets with clear audit trails and opt-in persistence mounts.

Architecture & tech

Frontend: React, Next.js, TypeScript and Tailwind with modular components.

Editing: Markdown editors with preview and Mermaid rendering for fast drafting.

Authentication: Firebase Auth with server-verified session cookies.

Firestore: Session state, lightweight content, timeline entries and admin profiles.

Supabase + PostgreSQL: Targets, assets, templates, notes, findings and reports.

PDF Export: Structured templates for professional reporting workflows.

Reporting: Structured Markdown content and reusable evidence workflows.

Workflow

1. Target Setup & Scope

Document rules of engagement, in-scope assets, and constraints. Avoid surprises and keep priorities explicit.

2. Recon & Enumeration

Subdomains, ASN/WHOIS, alive hosts, JS scraping, GitHub dorks, wordlists, and directory brute force mapped to concrete commands.

3. Template-Based Testing

Reusable checks across common bug classes without losing the flexibility needed for manual testing.

4. Findings & Reporting

Track evidence and export professional PDFs with CWE/CVE references and CVSS placeholders.

Source code

Repositories

10 public repositories, ordered by latest GitHub update.