asaotomo/FofaMap

一款证据驱动的 FOFA 资产测绘智能体:支持自然语言侦察、AI 反思、CLI / MCP / Skill / REST API,以及经人工审批的 Nuclei 扫描。

What it solves

FofaMap is a tool for asset discovery and attack surface analysis using the FOFA search engine. It bridges the gap between raw search queries and actionable security intelligence by allowing users to find assets using natural language, verify them with evidence-based summaries, and perform controlled vulnerability scanning.

How it works

FofaMap operates through three primary interfaces: a traditional CLI for direct FOFA queries, an AI-powered Agent for natural language reconnaissance, and an MCP (Model Context Protocol) server for integration with AI IDEs like Cursor or Claude.

When using the AI Agent, the system decomposes a natural language request into multiple FOFA queries, reflects on the results to refine the search, and categorizes assets by confidence levels (corroborated, observed, or candidate). For active scanning, it integrates with Nuclei, but enforces a strict human-approval gate where the user must review the target list, templates, and severity levels before any scan is executed.

Who it’s for

It is designed for security researchers, penetration testers, and asset managers who need to map an organization's public-facing infrastructure while maintaining a traceable and approved workflow.

Highlights

  • Natural Language Reconnaissance: Converts plain-text requirements into optimized FOFA queries with self-reflection loops to improve result quality.
  • Curation-Based Reporting: Generates Markdown reports that distinguish between high-confidence assets and noise, rather than treating all search hits as confirmed assets.
  • Controlled Scanning: Integrates Nuclei with a mandatory approval mechanism to prevent unauthorized or accidental scanning.
  • AI Ecosystem Integration: Provides one-click installation for MCP-compatible hosts including Cursor, Claude Code, and LM Studio.
  • Flexible Output: Supports exporting results to XLSX, CSV, and JSONL formats for further analysis.

Related

  • Project
  • Project
  • Project
  • Project
  • Project