afrog is a high-performance security scanning toolkit built for bug bounty, pentest, and red team workflows. It combines fast target probing, built-in vulnerability checks, custom PoC authoring, and SDK-driven automation in a single Go-based workflow.
Download the latest release from:
git clone https://github.com/zan8in/afrog.git
cd afrog
go mod tidy
go build -o afrog cmd/afrog/main.go
./afrog -h
go install -v github.com/zan8in/afrog/v3/cmd/afrog@latest
Scan a single target:
afrog -t https://example.com
Scan multiple targets from a file:
afrog -T targets.txt
Run only high and critical checks:
afrog -T targets.txt -S high,critical
The documentation is organized into four handbooks:
| Handbook | Start here |
|---|---|
| User Guide | What afrog is and how to use it |
| PoC Authoring Guide | Write your first PoC |
| SDK Usage Guide | Embed afrog in your Go program |
| Curated PoC | Enable licensed curated PoCs |
To join the afrog WeChat discussion group, add the afrog account and mark it as afrog.
afrog is part of 404Starlink.
This tool is intended only for legally authorized security work. Do not scan unauthorized targets. The user is solely responsible for any misuse or illegal activity.