Open Source

Built by Security Professionals,
for Security Professionals

Sirius Scan is shaped by the collective voice of its community. Every feature, integration, and workflow reflects the real needs of security teams working in the field. Join us and help build the future of open-source vulnerability management.

1.2k+
GitHub Stars
30+
Contributors
200+
Discord Members
10+
Repositories

Get Involved

There are many ways to contribute — no matter your skill level or background.

Report Issues

Found a bug or have a feature idea? Open a GitHub issue with clear reproduction steps and help us improve Sirius Scan for everyone.

Open an Issue

Contribute Code

Pick up a good-first-issue, submit a PR, or propose a new feature. Our contributing guide walks you through the full workflow.

Contributing Guide

Improve Documentation

Documentation is open source too. Fix a typo, add examples, or write a guide — every improvement helps the next person.

View Docs Repo

Share & Discuss

Join conversations on Discord for real-time help, or use GitHub Discussions for longer-form topics, RFCs, and community showcases.

Start a Conversation
Community Initiative

The Race to #KEV100

Not all vulnerabilities are created equal — most CVEs will never be exploited. By anyone. Ever.

How do we know what matters, and is there a free option to empower all security teams to find the most important vulnerabilities? Sirius Scan is proud to support the endeavor to create an open source option to discover every vulnerability on CISA's Known Exploited Vulnerabilities (KEV) list.

Join the Fight
The Race to KEV100

Connect With Us

Find the right channel for every conversation.

Discord

Our primary community hub. Get real-time help, discuss features, share your security workflows, and connect with other operators and contributors.

Join Server

GitHub Discussions

The place for longer-form conversations, Q&A, feature proposals, RFCs, and community showcases. Great for topics that deserve more than a chat message.

Join Discussion

Twitter / X

Follow for project updates, security insights, release announcements, and community highlights. Tag @Sirius_Scan to share your experience.

Follow Us

Community in Action

Real conversations and collaborations that shaped Sirius Scan.

Building Together

Let's build an open-source vulnerability scanner together! 2 weeks ago hundreds of you all participated in a discussion on what features a vulnerability scanner needs.
@0sm0s1z·X / Twitter

Hundreds of security practitioners shaped Sirius Scan's direction from day one through open community discussions.

Community-Requested Features

I think I may do a poll on most request features based on this thread. It looks like API extensibility is coming in at the top — module coverage and risk adjustment based on asset tagging.
@0sm0s1z·X / Twitter

From scan profiles to environment views, every major feature started as a community request.

Community Wish List

Ok, wish list: 1) Import multiple vuln DBs... Not only the CVE one. 2) Adding more intelligence when fingerprinting. 3) Validation of vulns. 4) Graphic patterns...
@skywalkez·X / Twitter

An open wish list lets everyone vote on priorities. The most-requested capabilities shape the roadmap.

CMDB Integration

If you want to make it actionable at large scale, integration with an asset inventory is a must. And allow access to results based on that. Inventory data can be assigned through an API.
@goncalr·X / Twitter

Enterprise users requested CMDB integration to connect vulnerability data with asset management workflows.

Regular Discussions

This week's topic will be on scanning agents! Agent AND scan-based, because I can't put agents on everything. Reasonable costs to deploy small and large. Remote engines. A solid API.
@SecCurmDgn·X / Twitter

Ongoing conversations about scanning strategies and security operations keep the community engaged.

Remediation Evaluation

Tell me how effective I am at remediation. Ideally from the data the vulnerability was published but you could also take the data from the first scan.
@shakthack·X / Twitter

Collaborative assessment of remediation strategies helps teams move from discovery to action.

Agent-Based Scanning

I'll second the backdooring cleverness. They're all terrible at that. Agent AND scan-based, because I can't put agents on everything.
@SecCurmDgn·X / Twitter

The agent architecture was designed with direct community input — lightweight, deployable agents that report host-level telemetry.

Project Roadmap

Where we've been and where we're headed — shaped by community input.

v1.0.0 Production Release

Completed

Full production-ready platform with installer-first setup, microservices architecture, and comprehensive scanning pipeline.

Agent-Based Scanning

CompletedCommunity Requested

Lightweight host agents that report telemetry, software inventory, and vulnerability data back to the central engine.

KEV100 Coverage

In ProgressCommunity Requested

Detect every vulnerability on CISA's Known Exploited Vulnerabilities list with open-source tooling.

Sirius Pro & Enterprise Features

Upcoming

Advanced reporting, team collaboration, managed infrastructure, and priority support for enterprise security operations.

Plugin & Extension System

UpcomingCommunity Requested

A modular extension framework for custom assessors, integrations, and community-built scanning modules.

Proudly Sponsored By

Open Security

Sirius Scan is sponsored by Open Security. Their support makes it possible to keep this project free, open, and growing.

SIRIUS

SCAN

Empowering Cybersecurity, One Scan at a Time.

Quick Links
Contact
GitHub Repository
Sirius GitHub

Open Security