Sn1per - free, open-source attack surface management and automated penetration testing platform. Continuous asset discovery, OSINT, vulnerability scanning, and red team automation for pentesters, bug bounty hunters, and SOC teams.
Sn1per Community Edition is a free, open-source attack surface management (ASM) and automated penetration testing platform built by working pentesters since 2014. Trusted by 500+ security teams worldwide, with 10,000+ stars and 2,000+ forks on GitHub.
Sn1per Community Edition discovers your organization's external attack surface, automates reconnaissance and OSINT collection, scans for vulnerabilities and CVEs, and verifies exploitability - all from a single command-line tool. Deploy on Kali Linux, Ubuntu, Debian, or Docker in minutes.
For the full web UI, multi-user workspaces, active exploitation modules, PDF reporting, and distributed scanning at enterprise scale, see Sn1per Professional 2026 and Sn1per Enterprise at https://sn1persecurity.com.
Use cases
External Attack Surface Management (EASM) - Continuous discovery, monitoring, and risk prioritization of every internet-facing asset, including assets that don't appear in a CMDB.
Combines DNS enumeration, certificate transparency, port scanning, web fingerprinting, and OSINT.
Automated Penetration Testing - Orchestrate 600+ exploits and 10,000+ detections in a single workflow. Active verification eliminates the false positives that version-only vulnerability
scanners ship as "critical."
Bug Bounty Automation - Manage large attack surfaces and stay ahead of the competition with continuous scanning, change detection, and integrated reporting.
Red Team Automation - Simulate real-world attackers and stress-test blue team detection and response.
Vulnerability Scanning - Aggregate findings from open-source and commercial scanners into one centralized risk view. Integrates natively with Nessus, OpenVAS / GVM, Nuclei, OWASP ZAP, Burp Suite Pro, WPScan, and Metasploit.
Dynamic Application Security Testing (DAST) - Scan web applications for OWASP Top 10 vulnerabilities, injection flaws, authentication weaknesses, and misconfigurations.
Threat Intelligence and OSINT - Stay current with emerging CVEs, data breaches, and exploit releases. Native integrations with Shodan, Censys, Hunter.io, and VirusTotal.
Continuous Attack Surface Monitoring - Schedule daily, weekly, or monthly rescans to detect new domains, subdomains, open ports, HTTP header changes, and exposed services.
Core features
One-line installation script - running in under five minutes on Kali Linux, Ubuntu, Debian, or Docker
90+ native integrations with leading security tools, APIs, and threat intelligence services
600+ exploit modules and 10,000+ detection signatures
Full attack surface coverage across on-prem, cloud, and hybrid environments
Scope and configuration controls for safe execution in production environments
Centralized IT asset inventory - searchable, sortable, and filterable
Notifications for new domains, new URLs, open-port changes, and surface drift
Export attack-surface inventory and vulnerability reports to CSV, XLS, or PDF
Daily, weekly, or monthly scheduled scans with diff alerting
On-premises deployment - scan data never leaves your environment
Keywords: attack surface management, ASM, EASM, external attack surface management, automated penetration testing, automated pentest, vulnerability scanner, OSINT framework, reconnaissance scanner, bug bounty automation, red team automation, DAST, dynamic application security testing, continuous penetration testing, open source pentest tool, free penetration testing tool, Kali Linux pentest, security automation, Sn1per, Sn1perSecurity.
Highlights
External Attack Surface Management (EASM) without blind spots. Sn1per continuously discovers and monitors every internet-facing asset your organization owns, including shadow IT, forgotten subdomains, and cloud sprawl that never make it into the CMDB. Combines DNS enumeration, certificate transparency, port scanning, web fingerprinting, and OSINT collection into one unified attack surface management workflow. Trusted by 500+ security teams worldwide with 10,000+ GitHub stars.
Automated penetration testing with active verification - no more false positives. Sn1per orchestrates 600+ exploits and 10,000+ detection signatures in a single workflow, then verifies exploitability so your team triages real risk instead of version-only critical findings. Native integrations with Nessus, Nuclei, OpenVAS, OWASP ZAP, Burp Suite Pro, Metasploit, and Shodan. Run from the CLI on Kali Linux, Ubuntu, Debian, or Docker.
Free, open-source, and 100% on-premises - scan data never leaves your perimeter. Sn1per Community Edition is the attack surface management and automated pentest tool of choice for pentesters, bug bounty hunters, red teams, and SOC analysts who need full control over their tooling. One-line install on Kali Linux, Ubuntu, Debian, or Docker.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
This product is available free of charge. Free subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
Sn1per Community Edition is free software with no license charge. You pay only for the AWS EC2 instance you run it on, billed hourly. The many dimensions listed are AWS instance types, not product tiers. They span general-purpose (m-series) and burstable (t-series) families in sizes from nano and micro up through metal. Larger instances carry more CPU and memory, so their hourly rate rises with size. Pick the instance that matches your scanning workload. The Community Edition capability itself is the same regardless of which instance you choose.
Top-of-mind questions for buyers
Am I charged when I stop or pause the EC2 instance running Community Edition?
The software carries no license charge, so stopping the instance halts hourly instance-hour billing. A fully stopped instance does not accrue compute charges. Attached storage may still incur underlying AWS fees while the instance is stopped. Only running time meters compute cost.
What does one hourly unit cover, and what determines the rate?
Each unit is one hour of running one EC2 instance of the chosen type. The rate reflects that instance's CPU and memory. Metal and larger sizes cost more per hour; nano and micro sizes cost less. You pick the type at launch and can change it later.
Which instance size should I match to my scanning workload?
The Community Edition engine is the same on every instance. Larger m-series and metal sizes give more CPU and memory for heavier scans across many targets. Burstable t-series sizes suit lighter, occasional scans. Match the instance to your target volume and expected scan concurrency.
sn1persecurity.com+1
Helpful?
Vendor refund policy
This is a free software product, so no refunds will be accepted.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This particular software helped (and continues to help me) in the automatic execution of several tasks. Inside this software are a lot of open-source tools that are helpful.
What do you dislike about the product?
Possibly the purchase cost of the software is overestimated. The website that is provided and the product is presented I would call it unprofessional and maybe needs improvement.
What problems is the product solving and how is that benefiting you?
Due to the many tools available through the software, the time to complete the work is reduced while the quality is increase. All tools embeded to Sn1per are known.