Built by Security Professionals,
for Security Professionals
Sirius Scan is shaped by the collective voice of its community. Every feature, integration, and workflow reflects the real needs of security teams working in the field. Join us and help build the future of open-source vulnerability management.
Get Involved
There are many ways to contribute — no matter your skill level or background.
Report Issues
Found a bug or have a feature idea? Open a GitHub issue with clear reproduction steps and help us improve Sirius Scan for everyone.
Open an IssueContribute Code
Pick up a good-first-issue, submit a PR, or propose a new feature. Our contributing guide walks you through the full workflow.
Contributing GuideImprove Documentation
Documentation is open source too. Fix a typo, add examples, or write a guide — every improvement helps the next person.
View Docs RepoShare & Discuss
Join conversations on Discord for real-time help, or use GitHub Discussions for longer-form topics, RFCs, and community showcases.
Start a ConversationThe Race to #KEV100
Not all vulnerabilities are created equal — most CVEs will never be exploited. By anyone. Ever.
How do we know what matters, and is there a free option to empower all security teams to find the most important vulnerabilities? Sirius Scan is proud to support the endeavor to create an open source option to discover every vulnerability on CISA's Known Exploited Vulnerabilities (KEV) list.
Join the Fight
Connect With Us
Find the right channel for every conversation.
Discord
Our primary community hub. Get real-time help, discuss features, share your security workflows, and connect with other operators and contributors.
Join ServerGitHub Discussions
The place for longer-form conversations, Q&A, feature proposals, RFCs, and community showcases. Great for topics that deserve more than a chat message.
Join DiscussionTwitter / X
Follow for project updates, security insights, release announcements, and community highlights. Tag @Sirius_Scan to share your experience.
Follow UsCommunity in Action
Real conversations and collaborations that shaped Sirius Scan.
Building Together
“Let's build an open-source vulnerability scanner together! 2 weeks ago hundreds of you all participated in a discussion on what features a vulnerability scanner needs.”
Hundreds of security practitioners shaped Sirius Scan's direction from day one through open community discussions.
Community-Requested Features
“I think I may do a poll on most request features based on this thread. It looks like API extensibility is coming in at the top — module coverage and risk adjustment based on asset tagging.”
From scan profiles to environment views, every major feature started as a community request.
Community Wish List
“Ok, wish list: 1) Import multiple vuln DBs... Not only the CVE one. 2) Adding more intelligence when fingerprinting. 3) Validation of vulns. 4) Graphic patterns...”
An open wish list lets everyone vote on priorities. The most-requested capabilities shape the roadmap.
CMDB Integration
“If you want to make it actionable at large scale, integration with an asset inventory is a must. And allow access to results based on that. Inventory data can be assigned through an API.”
Enterprise users requested CMDB integration to connect vulnerability data with asset management workflows.
Regular Discussions
“This week's topic will be on scanning agents! Agent AND scan-based, because I can't put agents on everything. Reasonable costs to deploy small and large. Remote engines. A solid API.”
Ongoing conversations about scanning strategies and security operations keep the community engaged.
Remediation Evaluation
“Tell me how effective I am at remediation. Ideally from the data the vulnerability was published but you could also take the data from the first scan.”
Collaborative assessment of remediation strategies helps teams move from discovery to action.
Agent-Based Scanning
“I'll second the backdooring cleverness. They're all terrible at that. Agent AND scan-based, because I can't put agents on everything.”
The agent architecture was designed with direct community input — lightweight, deployable agents that report host-level telemetry.
Project Roadmap
Where we've been and where we're headed — shaped by community input.
v1.0.0 Production Release
CompletedFull production-ready platform with installer-first setup, microservices architecture, and comprehensive scanning pipeline.
Agent-Based Scanning
CompletedCommunity RequestedLightweight host agents that report telemetry, software inventory, and vulnerability data back to the central engine.
KEV100 Coverage
In ProgressCommunity RequestedDetect every vulnerability on CISA's Known Exploited Vulnerabilities list with open-source tooling.
Sirius Pro & Enterprise Features
UpcomingAdvanced reporting, team collaboration, managed infrastructure, and priority support for enterprise security operations.
Plugin & Extension System
UpcomingCommunity RequestedA modular extension framework for custom assessors, integrations, and community-built scanning modules.
Contributors
The people behind Sirius Scan. Every contribution matters.
Proudly Sponsored By
Sirius Scan is sponsored by Open Security. Their support makes it possible to keep this project free, open, and growing.




