
Multi-protocol port scanner with fingerprint recognition, service detection, and brute-force authentication testing. Supports 1200+ protocols, 10000+ fingerprints, and automated network reconnaissance.
[[Chinese Readme]][url-doczh] | [[English Readme]][url-docen]
This tool is intended only for legally authorized enterprise security construction activities and personal learning. If you need to test the usability of this tool, please set up your own target environment.
When using this tool for testing, you must ensure that the behavior complies with local laws and regulations, and that sufficient authorization has been obtained. Do not scan unauthorized targets.
If the above prohibited actions are discovered, we reserve the right to pursue legal liability.
If you engage in any illegal behavior while using this tool, you shall bear the corresponding consequences yourself, and we will not assume any legal or joint liability.
Before installing and using this tool, please be sure to read carefully and fully understand all terms.
Unless you have fully read, completely understood, and accepted all terms of this agreement, please do not install or use this tool. Your use of the tool or any other express or implied acceptance of this agreement will be deemed as your agreement to be bound by this agreement.
_ __
/#| /#/ Lightweight comprehensive scanning tool by: kv2
|#|/#/ _____ _____ * _ _
|#.#/ /Edge/ /Forum\ /#\ /#\ /#\
|##| |#|____ |#| /Kv2\ |##\|#|
|#.#\ \r0cky\|#| /#/_\#\ |#.#.#|
|#|\#\/\___|#||#|____/#/Rui\#\|#|\##|
\#| \#\lcvvvv/ \aels/#/ v1.87#\#/ \#/
Kscan is a full-featured scanner developed purely in Go, capable of port scanning, protocol detection, fingerprint recognition, and brute-force cracking. It supports over 1200 protocols, 10,000+ protocol fingerprints, 20,000+ application fingerprints, and more than 10 brute-force protocols.
There are already many tools for asset scanning, fingerprint recognition, and vulnerability detection on the market, including some excellent ones. However, Kscan has many different ideas.
Kscan aims to accept a variety of input formats without requiring users to classify scan targets beforehand (e.g., distinguishing between IPs and URLs). This eliminates extra work for users. All entries can be input and recognized normally—if it's a URL, the path is preserved for detection; if it's simply IP:PORT, protocol identification is prioritized. Currently, Kscan supports three input methods (-t, --target | -f, --fofa | --spy).
Kscan does not sacrifice accuracy by matching port numbers to common protocols for efficiency, nor does it only detect web assets. Instead, it places greater emphasis on accuracy and comprehensiveness. Only highly accurate protocol identification can provide a good foundation for subsequent application-layer detection.
Kscan does not adopt a modular approach of simply stacking functions (e.g., one module fetching titles, another fetching SMB info, etc.) and running them independently with separate outputs. Instead, it outputs asset information on a per-port basis. For example, if the port protocol is HTTP, it automatically performs subsequent fingerprint recognition and title retrieval; if the port protocol is RPC, it attempts to obtain the hostname, etc.

Kscan currently supports three methods of specifying scan targets:
IP address: 114.114.114.114
IP address range: 114.114.114.114-115.115.115.115
URL address: https://www.baidu.com
File path: /tmp/target.txt
[empty]: Detect the local IP and probe the B-segment of the local IP.
[all]: Probe all private IP ranges (192.168, 172.32, 10, etc.).
[IP address]: Probe the B-segment of the specified IP address.
Fofa search keyword: directly returns fofa search results.
usage: kscan [-h,--help,--fofa-syntax] (-t,--target,-f,--fofa,--spy) [-p,--port|--top] [-o,--output] [-oJ] [--proxy] [--threads] [--path] [--host] [--timeout] [-Pn] [-Cn] [-sV] [--check] [--encoding] [--hydra] [hydra options] [fofa options]