██╗ ██╗ █████╗ ███╗ ███╗██████╗ ███████╗███████╗ ██████╗██╗ ██╗██████╗ ███████╗
██║ ██║██╔══██╗████╗ ████║██╔══██╗██╔════╝██╔════╝██╔════╝██║ ██║██╔══██╗██╔════╝
██║ ██║███████║██╔████╔██║██████╔╝███████╗█████╗ ██║ ██║ ██║██████╔╝█████╗
╚██╗ ██╔╝██╔══██║██║╚██╔╝██║██╔═══╝ ╚════██║██╔══╝ ██║ ██║ ██║██╔══██╗██╔══╝
╚████╔╝ ██║ ██║██║ ╚═╝ ██║██║ ███████║███████╗╚██████╗╚██████╔╝██║ ██║███████╗
╚═══╝ ╚═╝ ╚═╝╚═╝ ╚═╝╚═╝ ╚══════╝╚══════╝ ╚═════╝ ╚═════╝ ╚═╝ ╚═╝╚══════╝
L A B S
Professional-grade security tooling for authorized penetration testing, vulnerability research and defensive operations.
Herramientas de seguridad profesionales para pruebas de intrusión autorizadas, investigación de vulnerabilidades y operaciones defensivas.
| Tool | Version | Description / Descripción |
|---|---|---|
| 🔍 RECONNAISSANCE & ATTACK SURFACE · RECONOCIMIENTO & SUPERFICIE DE ATAQUE | ||
| vamp-passive-recon | v1.3.0 |
Passive ASM — DNS, WHOIS, certificate transparency, GitHub dorks, Shodan OSINT, tech fingerprinting ASM pasivo — DNS, WHOIS, transparencia de certificados, dorks GitHub, OSINT Shodan, fingerprinting tecnológico |
| vamp-easm | v1.6 |
Continuous EASM — subdomain discovery, async port scan, TLS cert monitoring, Shodan+Censys enrichment, Shodan Monitor integration (monitor --setup/--check)EASM continuo — subdominios, puertos async, TLS, enriquecimiento Shodan+Censys, alertas Shodan Monitor persistentes |
| vamp-shodan-hunt | v1.2 |
Shodan OSINT exposure hunter — CVE-exposed hosts, product enumeration, org attack surface, raw query. No Shodan SDK required Cazador OSINT de exposición en Shodan — hosts con CVE, enumeración de productos, superficie de ataque de org. Sin SDK |
| vamp-subdomain-takeover | v1.3 |
Subdomain takeover detector — CNAME dangling, 40+ provider fingerprints, --monitor continuous DNS pollingDetector de subdomain takeover — CNAME colgantes, 40+ firmas de proveedores, --monitor polling DNS continuo |
| vamp-cloud-enum | v1.3 |
Async cloud storage & serverless scanner — S3/Azure/GCS buckets + GCP/AWS/Azure Cloud Functions exposure detection (--check-functions)Escáner async de almacenamiento cloud y serverless — buckets + Cloud Functions. No SDK requerido |
| vamp-ad-recon | v1.2 |
Active Directory security auditor — Kerberoasting, AS-REP Roasting, ACL abuse, BloodHound-compatible output, agentless LDAP Auditor de seguridad Active Directory — Kerberoasting, AS-REP, abuso de ACL, salida compatible con BloodHound |
| 🕵️ THREAT INTELLIGENCE · INTELIGENCIA DE AMENAZAS | ||
| vamp-darkweb-intel | v1.1.0 |
Darkweb & threat intelligence CLI — multi-source IOC lookup, automatic correlation, breach checks + --monitor persistent daemonCLI de inteligencia de amenazas y darkweb — IOC multi-fuente, correlación automática, filtraciones + daemon de vigilancia |
| 🔬 VULNERABILITY INTELLIGENCE · INTELIGENCIA DE VULNERABILIDADES | ||
| vamp-cve-oracle | v3.2 |
RBVM engine — NVD + CISA KEV + EPSS scoring + Shodan global exposure count per CVE, asset inventory, CVE-CPE correlation Motor RBVM — NVD + CISA KEV + EPSS + recuento de exposición global Shodan por CVE, inventario de activos |
| vamp-forticheck | v2.1 |
Multi-vendor edge device scanner — FortiOS, F5 BIG-IP, Palo Alto, Cisco ASA with live CVE probes + Shodan pre-scan discovery Escáner multi-vendor de dispositivos de borde — FortiOS, F5 BIG-IP, Palo Alto, Cisco ASA con sondas CVE en vivo |
| vamp-ssl-audit | v1.7.0 |
TLS/SSL auditor — SSLabs-style grading (A+…F), cipher suites, cert chain, HSTS, OCSP stapling, --delta diff scan, multi-format export (HTML/JSON/Markdown/CSV/PDF), importable packageAuditor TLS/SSL con calificación estilo SSLabs, --delta diff entre escaneos, paquete importable |
| 🌐 WEB & API SECURITY · SEGURIDAD WEB & API | ||
| vamp-http-audit | v1.3.0 |
HTTP security headers & CORS auditor — CSP, HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy Auditor de cabeceras de seguridad HTTP y CORS — CSP, HSTS, X-Frame-Options, Referrer-Policy |
| vamp-graphql-audit | v1.4.0 |
GraphQL DAST auditor — introspection, BOLA/IDOR, alias abuse, APQ persisted queries, nested DoS detection Auditor DAST GraphQL — introspección, BOLA/IDOR, alias abuse, APQ, DoS anidado |
| vamp-wp2shell-audit | v1.2 |
WordPress/Joomla/Drupal security auditor — 40+ CVEs, plugin enumeration, xmlrpc abuse, WPScan API integration Auditor de seguridad WordPress/Joomla/Drupal — 40+ CVEs, enumeración de plugins, xmlrpc, API WPScan |
| vamp-waf-bypass | v1.1.0 |
WAF evasion tester — WAF fingerprinting, 15 bypass techniques (SQLi/XSS/LFI encoded), --watch N daemon mode, 56 testsTester de evasión WAF — fingerprinting, 15 técnicas (SQLi/XSS/LFI codificados), daemon mode, 56 tests |
| vamp-oauth-audit | v1.1 |
OAuth 2.0 & OIDC security auditor — auth code injection, PKCE bypass (CVE-2025-4144), scope creep, .well-known misconfiguration Auditor de seguridad OAuth 2.0 y OIDC — inyección de código auth, bypass PKCE, scope creep, .well-known |
| vamp-jwt-audit | v1.4.0 |
JWT security auditor — alg=none, RS256→HS256 confusion, brute-force HMAC, kid injection, JWKS spoofing, OAuth flow audit. Importable package Auditor JWT — alg=none, confusión RS256/HS256, brute-force HMAC, kid injection, JWKS spoofing. Paquete importable |
| vamp-api-probe | v1.0 |
REST API DAST scanner — BOLA, BFLA, mass assignment, rate-limiting bypass, OWASP API Top 10, OpenAPI spec ingestion Escáner DAST REST — BOLA, BFLA, mass assignment, bypass de rate-limiting, OWASP API Top 10 |
| ☁️ CLOUD, IaC & CONTAINERS · CLOUD, IaC & CONTENEDORES | ||
| vamp-aws-audit | v1.0.0 |
AWS security auditor — 71 CIS AWS Level 1 controls across 8 modules (IAM/S3/EC2/CloudTrail/RDS/KMS/GuardDuty/Config), SigV4 without boto3 Auditor AWS — 71 controles CIS Level 1, 8 módulos (IAM/S3/EC2/CloudTrail/RDS/KMS/GuardDuty/Config), sin boto3 |
| vamp-azure-audit | v1.1 |
Microsoft Azure security auditor — RBAC, Storage ACL, Key Vault, App Service, NSG, AKS, Entra ID, Defender for Cloud Auditor Azure — RBAC, Storage ACL, Key Vault, App Service, NSG, AKS, Entra ID, Defender for Cloud |
| vamp-gcp-audit | v1.3 |
Google Cloud Platform security auditor — Service Accounts, GCS ACL, GKE, Cloud Run, BigQuery, Artifact Registry, Workload Identity Auditor GCP — Service Accounts, GCS ACL, GKE, Cloud Run, BigQuery, Artifact Registry, Workload Identity |
| vamp-iac-audit | v2.5.0 |
IaC static security auditor — 264 checks across 6 formats: Terraform, CloudFormation, Helm, Ansible, Pulumi, AWS SAM/CDK. YAML-driven extensible rules engine (9 rule files). CIS + MITRE ATT&CK mappings. AWS, Azure, GCP Auditor estático IaC — 264 checks, 6 formatos, motor YAML extensible. Brecha vs Checkov ~3.8x |
| vamp-k8s-audit | v3.0.0 |
Kubernetes security auditor — RBAC, pods, network, CIS Benchmark YAML engine (44 checks), kube-bench wrapper, --control-plane flags check, --delta diff scan, importable packageAuditor Kubernetes — motor YAML CIS, kube-bench, control plane, diff scan, paquete importable |
| vamp-docker-audit | v1.5.0 |
Docker security auditor — CIS Docker Benchmark, CycloneDX SBOM generation, secrets in env vars, layer secrets, --delta diff scan, importable packageAuditor Docker — CIS Benchmark, SBOM CycloneDX, secretos en capas/env, diff scan, paquete importable |
| vamp-mobile-audit | v1.0.0 |
Mobile security static auditor — OWASP MASVS 2.0 checks for APK and IPA files, hardcoded secrets, SSL pinning, exported components Auditor estático mobile — OWASP MASVS 2.0, APK e IPA, secretos hardcodeados, SSL pinning, componentes exportados |
| 🔒 DevSec & SUPPLY CHAIN · SEGURIDAD DEL DESARROLLO | ||
| vamp-secrets-scanner | v3.0.0 |
Static secrets & credentials scanner — 271 patterns across 9 YAML rule files (cloud, AI APIs, CI/CD, SaaS, auth, payments, hardware/web3/gaming/enterprise), git history, Docker, K8s, SARIF, --delta, --watch N daemon, importable packageEscáner de secretos — 271 patrones, 9 ficheros YAML, historial git, Docker, K8s, SARIF, diff, daemon. Paquete importable |
| vamp-supply-chain | v1.1 |
Supply chain security scanner — SBOM CycloneDX/SPDX, CVE checks via OSV.dev, typosquatting detection, SAST↔CVE cross-reference Escáner de cadena de suministro — SBOM CycloneDX/SPDX, CVE OSV.dev, typosquatting, cruce SAST↔CVE |
| vamp-ci-audit | v1.0 |
CI/CD pipeline security auditor — GitHub Actions, GitLab CI, Forgejo Actions: expression injection, SHA pinning, GITHUB_TOKEN permissions, fork access Auditor de pipelines CI/CD — expresion injection, SHA pin, permisos GITHUB_TOKEN, acceso desde forks |
| vamp-compliance-check | v1.1 |
Static multi-framework compliance auditor — ENS RD 311/2022, NIS2, ISO 27001, DORA, GDPR. Spanish/European focus, gap analysis report Auditor de cumplimiento multi-marco — ENS, NIS2, ISO 27001, DORA, GDPR. Enfoque español/europeo |
| vamp-entropy-watch | v2.2 |
Entropy-based ransomware & exfil detector — file system monitoring, Shannon entropy analysis, 80+ known ransomware extensions Detector de ransomware y exfiltración por entropía — monitorización FS, entropía Shannon, 80+ extensiones |
| 🖥️ ENDPOINT & HOST SECURITY · SEGURIDAD DE ENDPOINTS | ||
| vamp-host-audit | v1.15.0 |
Multiplatform host hardening auditor — 272 checks: Linux, macOS, Windows. ENS RD 311/2022 + CCN-STIC 808, NIS2, ISO 27001, DORA. SSH remote audit, YAML profiles, --delta diffAuditor de hardening multiplataforma — 272 checks Linux/macOS/Windows, ENS+CCN-STIC 808, NIS2, DORA, auditoría SSH remota |
| vamp-windows-audit | v1.1.0 |
Windows post-compromise security auditor — 15 CIS checks, agentless (WinRM/PowerShell), --baseline delta scan with NEW/RECURRING/RESOLVED badges, HTML report, 74 testsAuditor Windows sin agente — 15 checks CIS, delta scan NEW/RECURRING/RESOLVED, informe HTML |
| ⚡ EMERGING THREAT COVERAGE · COBERTURA DE AMENAZAS EMERGENTES | ||
| vamp-llm-probe | v1.8.0 |
LLM security auditor — prompt injection, jailbreak, ASCII smuggling, RAG injection, model extraction. Bilingual EN+ES (666+210+390 payload dataset). --watch N daemon, importable packageAuditor de seguridad LLM — inyección, jailbreak, smuggling ASCII, RAG, extracción de modelos. Bilingüe EN+ES |
| vamp-llm-payloads | dataset | Adversarial datasets for LLM red teaming — 666 jailbreaks EN, 210 injection vectors, 390 forbidden questions (companion to vamp-llm-probe) Datasets adversariales para red team LLM — jailbreaks, inyección, preguntas prohibidas (complemento de vamp-llm-probe) |
| vamp-mcp-audit | v2.3 |
MCP server security auditor — tool poisoning, 17 injection regexes + 50 payload dataset, OWASP Agentic Top 10, --monitor continuous polling, VS Code config audit. First OSS MCP security toolAuditor de seguridad MCP — envenenamiento de herramientas, OWASP Agentic Top 10, polling continuo. Primera herramienta OSS para MCP |
| vamp-rag-audit | v1.0 |
RAG & agentic AI security auditor — indirect prompt injection, context poisoning, Unicode Tags smuggling, query injection, OWASP LLM Top 10 Auditor de seguridad RAG y IA agéntica — inyección indirecta, context poisoning, Unicode Tags, OWASP LLM Top 10 |
| 📧 EMAIL SECURITY · SEGURIDAD DE EMAIL | ||
| vamp-mail-audit | v1.2.0 |
Email security auditor — SPF, DKIM (RSA key length), DMARC policy, BIMI, MTA-STS, SMTP open relay detection. Importable package Auditor de seguridad email — SPF, DKIM, DMARC, BIMI, MTA-STS, relay abierto. Paquete importable |
| 📊 LOGS & FORENSICS · LOGS & ANÁLISIS FORENSE | ||
| vamp-log-analyzer | v2.4.0 |
Forensic log analyzer — 25 MITRE ATT&CK detectors, cross-source correlation, STIX 2.1 export, Sigma rules YAML, chain-of-custody ZIP, --watch-wazuh-api. Importable packageAnalizador forense de logs — 25 detectores MITRE ATT&CK, correlación multi-fuente, STIX 2.1, Sigma, cadena de custodia |
| vamp-log-hunter | v1.3 |
IoC detector for server logs — --fast-mode triage (<5s), SQLi/XSS/webshells/brute force detection. Distinct from vamp-log-analyzer (forensic)Detector de IoC en logs — triage --fast-mode <5s, SQLi/XSS/webshells/fuerza bruta. Diferente de vamp-log-analyzer |
| vamp-forensic-query | v1.3 |
Forensic SQL/log query engine — CSV/XLSX ingestion, DNI/email/IP pattern search, evidence ZIP signed, streaming SQLite >500MB Motor de consulta forense — ingestión CSV/XLSX, búsqueda DNI/email/IP, ZIP de evidencia firmado, SQLite streaming >500MB |
| 🎯 REPORTING & ORCHESTRATION · INFORMES & ORQUESTACIÓN | ||
| vamp-penreport | v2.7.0 |
Professional pentest report aggregator — all VSL JSON → client HTML/PDF, CVSS 3.1, Jira/DefectDojo export, GPG-signed PDF, ENS RD 311/2022 checklist. Importable package Agregador de informes pentest — JSON VSL → HTML/PDF, CVSS 3.1, Jira/DefectDojo, PDF firmado GPG, checklist ENS |
| vamp-orchestrator | v2.5 |
Meta-tool chaining 22 VSL scanners — parallel execution, YAML pipelines, unified risk score, MITRE ATT&CK mapping, Telegram notifications. Playbooks: devops_audit / cloud_posture / endpoint_hardeningMeta-herramienta que encadena 22 escáneres VSL — ejecución paralela, pipelines YAML, puntuación unificada, Telegram |
| 🔬 RESEARCH LAB · LABORATORIO DE INVESTIGACIÓN | ||
| vamp-arp-sentinel | v2.2 |
ARP/IPv6 NDP spoofing detector + active PoC — Scapy-based passive+active detection for Blue Team / Red Team training Detector de ARP spoofing + PoC activo — Scapy, detección pasiva+activa para Blue Team / Red Team |
| vamp-icmp-shadow | v1.3 |
ICMP covert channel lab for Blue Team / Red Team training — educational PoC, authorized use only Laboratorio de canal encubierto ICMP para formación Blue/Red Team — PoC educativo, solo uso autorizado |
| vamp-shellcode-lab | v1.0.0 |
ARM64 shellcode research lab — macOS/Linux shellcode generation, encoding, analysis. Authorized use only Lab de investigación de shellcode ARM64 — generación, codificación y análisis. Solo uso autorizado |
# Install via PyPI / Instalar vía PyPI
pip install vamp-ssl-audit vamp-secrets-scanner vamp-iac-audit vamp-k8s-audit
# Install via Homebrew / Instalar vía Homebrew
brew tap vampsecure-labs/labs
brew install vamp-ssl-audit vamp-iac-audit vamp-secrets-scanner
# Scan IaC for misconfigurations / Escanear IaC
vamp-iac-audit scan --path ./infra --json results.json
# Scan for secrets in git history / Escanear secretos en historial git
vamp-secrets-scanner . --git-history --sarif findings.sarif
# TLS audit / Auditoría TLS
vamp-ssl-audit example.com --html report.html
# Kubernetes security audit / Auditoría de seguridad Kubernetes
vamp-k8s-audit --all --delta last_scan.json
# Orchestrate multiple tools / Orquestar múltiples herramientas
python3 vamp_orchestrator.py --targets example.com --playbook devops_audit --report-html audit.htmlEvery tool exits with standardized exit codes for pipeline automation.
Todas las herramientas usan códigos de salida estandarizados para automatización de pipelines.
| Exit Code | Meaning / Significado |
|---|---|
0 |
No findings above LOW severity / Sin hallazgos por encima de severidad BAJA |
1 |
HIGH severity findings detected / Hallazgos de severidad ALTA detectados |
2 |
CRITICAL severity findings — pipeline should fail / Hallazgos CRÍTICOS — el pipeline debe fallar |
# GitHub Actions / Forgejo CI
- name: IaC security scan
run: vamp-iac-audit scan --path ./infra --json iac.json
continue-on-error: false # exit 2 = CRITICAL = pipeline fails
- name: Secrets scan
run: vamp-secrets-scanner . --git-history --sarif secrets.sarifAll tools produce a consistent JSON schema for interoperability.
Todas las herramientas generan un esquema JSON consistente para interoperabilidad.
{
"tool": "vamp-iac-audit",
"version": "2.5.0",
"target": "./infra",
"timestamp": "2026-10-08T12:00:00Z",
"findings": [
{
"id": "IAC-CDK-Y-001",
"severity": "CRITICAL",
"title": "Lambda Function URL without authentication (AuthType: NONE)",
"description": "...",
"remediation": "...",
"mitre_attack": "T1190"
}
],
"summary": { "total": 1, "critical": 1, "high": 0, "medium": 0, "low": 0 }
}Use vamp-penreport to aggregate outputs from multiple tools into a single client-ready report.
Usa vamp-penreport para agregar los resultados de múltiples herramientas en un único informe listo para el cliente.
© VampSecure Studios — VampSecure Labs Security Research Division
All tools are released for authorized security testing only.
Todas las herramientas se publican exclusivamente para pruebas de seguridad autorizadas.
Usage against systems without explicit written permission is prohibited.
El uso contra sistemas sin permiso escrito explícito está prohibido.