#139 · Primary category: Cybersecurity & Decryption Tools

FofaMap

ai-agent asset-discovery asset-mapping attack-surface-management cybersecurity fastapi fofa fofa-api mcp model-context-protocol nuclei osint python red-team security-tools

An evidence-driven FOFA asset mapping agent: supports natural language reconnaissance, AI reflection, CLI/MCP/Skill/REST API, and human-approved Nuclei scanning.

Project last updated:08/16/26

GitHub Stars

708

Forks

94

Contributors

1

License

Apache-2.0

Why we included this project

FofaMap is for security teams that want FOFA's asset search to produce something they can trace back to evidence. You can run classic FOFA queries from a plain CLI with no model involved, or hand a natural-language reconnaissance request to an agent that plans several queries and refines its approach based on real hit counts before writing an asset brief that separates high-confidence findings from candidates and noise. The same interface is available over MCP and as a Skill, so AI coding tools can drive it, and there is a REST API for custom integrations. When a scan is needed, FofaMap only proposes a plan; the targets, templates, and severity levels need a one-time human approval before the scan is handed to Nuclei. That approval gate keeps automated scanning under control, and because the deterministic code handles the querying and export while the agent only plans and summarizes, failures show up as real errors instead of being hidden as empty results.

Articles for this project

No articles for this project yet.

To suggest a topic or contribute an article, contact us.

Related projects in this category