// FREE · LOCAL · NO ACCOUNT · AI OPTIONAL

One local scanner for the whole pen test — and it verifies every finding.

Point NewScan at a target you're authorized to test. It sweeps the engagement — APIs, web apps, network & infrastructure, Wi-Fi, and segmentation — then re-runs every hit to confirm it's real before it reports it. A live console explains every step; SARIF / Markdown / interactive HTML output with a CI gate. Pen testers cover more in less time; internal teams verify their coverage or run their own pen test — without anyone ever losing the call.

  • One tool, five surfaces — API, web, network, Wi-Fi, and segmentation, results shared across modes.
  • Validated findings — reproduced and cross-referenced, with the evidence attached, so you can trust what's reported.
  • No account to run — a quick sign-in gets you the download, then it runs on your box; your traffic and keys never leave it.
  • AI optional, BYOK — runs fully deterministic with no key, or add OpenAI / Anthropic / Gemini / Ollama for deeper reach.

// GET NEWSCAN — FREE

STATUS: sign in to download…

Sign in once to get the download — it keeps bots and spam out. That's all the sign-in does: NewScan still runs locally on your own box with no account, and your traffic and keys never leave it.

The source is private — there's no public repo. A quick SSO sign-in gets you the download; that's still not an account to run it — there's nothing to log into to use NewScan. Only scan systems you own or are authorized to test; NewScan is scope-locked to the target you give it.

Overview

// free · local · verifies every finding

NewScan is a free, self-hosted scanner that sweeps your whole engagement — APIs, web apps, network & infrastructure, Wi-Fi, and segmentation — and re-runs every hit to confirm it's real before reporting it. A deterministic floor runs with no key; an optional AI layer (BYOK) goes deeper. Everything runs on your box.

  • Completely free to self-host — no license, seat fees, or demo call.
  • Local-first — target traffic, findings, and AI keys never leave your machine.
  • Evidence-backed findings — every finding is reproduced and cross-referenced before it's recorded, with the evidence attached and severity never inflated.
  • AI optional, BYOK — fully deterministic with no key; add OpenAI / Anthropic / Gemini / Ollama for deeper reach.
  • CI-ready — SARIF 2.1.0 plus a severity exit-code gate for any pipeline.
  • Compliance-calibrated — one score mapped to PCI DSS, SOC 2, ISO 27001, HITRUST, HIPAA, and NIST 800-53.
NewScan findings view

FINDINGS

Confirmed findings ranked by severity, each with reproduced evidence and remediation attached.

NewScan web-app scan console

WEB SCAN

The live web-app scan — crawl, probe, and verify in a real browser, streamed step by step.

NewScan detected technology stack

TECH STACK

The detected technology stack and infrastructure, fingerprinted from responses and cross-referenced to known CVEs.

AI where it makes the scan better

// deterministic proof · agentic reach · your choice

NewScan starts with a complete deterministic scan, then uses AI for the work where judgement and iteration add reach. Every AI-led signal is still checked against real evidence before it becomes a finding. Run without AI, bring your own model, use NewScan AI, or let your own agent drive the loop.

MCP / YOUR AGENT

Give your agent the controls

The local MCP server lets any MCP-capable agent start scoped scans, run checks, read evidence and reports, fix your code, then rescan until the gate passes. Your agent chooses the workflow; NewScan supplies the scanning control plane.

BUILT-IN AGENTS

Go beyond the fixed sweep

Built-in ReACT and campaign agents use the deterministic results, near-misses and shared scan knowledge to plan high-yield follow-ups, craft target-specific probes and investigate attack paths. An adversarial pass tries to refute the result before it is recorded.

AI ON YOUR TERMS

Choose how it runs

Quick and baseline profiles need no model or key. For AI-assisted depth, bring an OpenAI, Anthropic, Gemini, Ollama or compatible-provider key and keep it local, or use integrated NewScan AI with pay-as-you-go billing. The scan engine and evidence bar stay the same.

Want the full agent loop? Connect NewScan to your MCP client →

Scan types

// five surfaces, one tool

API

REST · GraphQL · gRPC · SOAP · MCP · WebSocket

WEB

SPA crawl (Playwright) · XSS · SSTI · CSRF

NETWORK

hosts · ports · TLS · DNS · SMB/SNMP · CVE

WI-FI

rogue APs, device ID & client posture

SEGMENTATION

cross-VLAN reachability · PCI CDE

Findings are shared across modes — a network scan hands discovered web services straight to the API scanner, so nothing falls between tools.

Detections categories

// high level · OWASP API / Web / LLM Top 10

ACCESS CONTROL

BOLA / IDOR · function-level · business-flow abuse

AUTHENTICATION

JWT inspection · weak-secret cracking

INJECTION

SQLi · cmdi · SSTI · XSS · NoSQL · XXE · Prompts

SSRF

server-side request forgery

DATA EXPOSURE

secrets / PII · mass assignment (BOPLA)

DATA EXFILTRATION

out-of-band egress · blind SSRF/XXE callbacks · DNS/webhook exfil

NETWORK & INFRA

TLS / cert · DNS & email · SMB/SNMP · CVE cross-ref

AI / LLM

LLM01 prompt injection · MCP tool poisoning

BROWSER & SESSION TRUST

CSRF · clickjacking · CORS · cookie flags · open redirect · tabnabbing · XS-Leak

BUSINESS LOGIC

race conditions · value tampering · workflow limits

DENIAL OF SERVICE

open resolvers · UDP amplification · resource exhaustion

Plus CRLF injection, file-upload and cloud-storage exposure, deserialization, SAML/OAuth misconfiguration, dependency & CVE cross-referencing, and cross-finding attack-chain correlation. Out-of-band classes (blind SSRF, OOB SQLi/XXE, blind XSS) unlock with NewScan Pro.

Want the exact payloads and checks for your stack? The technology breakdowns go detector-by-detector on GraphQL, gRPC, SOAP, Spring Boot, Kubernetes, JWT/OAuth, MongoDB, Redis, Supabase, Firebase, WordPress, Next.js and AI-backed APIs.

Protocols

// tested natively, not just REST

REST

HTTP / HTTPS APIs

OpenAPI / Postman / HAR import · full injection & auth testing

GRAPHQL

Dedicated GraphQL pack

engine fingerprinting · introspection abuse · batching / DoS · CSRF & injection

gRPC

HTTP/2 + protobuf

reflection discovery · mTLS transport audit · per-field fuzzing

WEBSOCKET

Live channel testing

CSWSH · origin validation · authenticated message-level fuzzing

MCP

AI tool servers

tool poisoning · unauthenticated exposure · indirect prompt injection

SOAP

Auto-detected

classified by content-type / WSDL, tested through the injection engine

Authentication schemes

// scan authenticated, as a real user

BEARER / JWT

bare tokens auto-prefixed; JWTs inspected for weak signing

API KEY

custom header (default X-API-Key) on every request

HTTP BASIC

username : password, Base64 Authorization header

OAUTH2

client-credentials & password grants, token auto-installed

FORM / SPA LOGIN

API login or browser-driven (Playwright) session capture

HMAC SIGNING

per-request HMAC-SHA256/512 with a shared secret

On the roadmap: session cookie · mTLS client certificates · OAuth2 authorization-code + PKCE.

Reports & exports

// one scan, every format your workflow needs

SARIF

SARIF 2.1.0

Machine-readable results for CI code-scanning — GitHub, Azure DevOps, and any SARIF-aware pipeline, with a severity exit-code gate.

MARKDOWN

Markdown report

A human-readable write-up to review or hand to stakeholders — prints or converts to PDF cleanly.

INTERACTIVE TRIAGE

Self-contained HTML

Per-finding status & notes, severity filtering, and one-click Jira / GitHub tickets — triage in the report itself.

HAR

HAR traffic capture

The scan's raw HTTP requests and responses — replay and inspect every exchange in Burp or browser DevTools.

Run it in CI/CD — or from your agent

// scan a release before you ship

AS AN MCP SERVER

The running app serves an MCP server on the same port, so any MCP-capable agent can scan, read the findings, fix the code and rescan until the gate passes. Two commands and you're driving it from Claude Code:

$ docker compose up            # the app, console and /mcp on http://localhost:9700
$ claude mcp add --transport http newscan http://127.0.0.1:9700/mcp

> Using the newscan MCP server, scan http://localhost:3000, then fix each
  real finding in this repo and rescan until nothing high or above is left.

Any other client: add an HTTP / streamable-HTTP server at the same URL. Full tool reference and the scan → fix → rescan loop in the MCP docs.

AS A SCRIPT

NewScan runs headless with a single command and exits with a severity gate code, so any pipeline can scan a build and fail it before deploy — no server, no browser. The keyless quick profile needs no API key.

$ python -m newscan https://staging.example.com \
    --scan-mode api --profile quick \
    --fail-on high --sarif out.sarif

Exit 0 clean · 1 a finding met the threshold · 2 the scan couldn't run. SARIF uploads straight to GitHub/GitLab code scanning.

GITHUB ACTIONS

Or use the NewScan Action — one step, no install, SARIF into the Security tab. Point it at a preview deploy or an app you start as a job service; make it a required check and a PR can't merge until it passes.

- uses: NewNormal-Security/newscan-action@v1
  with:
    target: https://staging.example.com
    license: ${{ secrets.NEWSCAN_LICENSE }}
    fail-on: high
- if: always()
  uses: github/codeql-action/upload-sarif@v4
  with: { sarif_file: newscan.sarif }

Inputs, outputs and three ready workflows (deploy gate, ephemeral service, per-PR preview) are in the action's README. The action is a Pro feature; the script above stays free.

NewScan Pro

// optional upgrade · everything local stays free

A whole class of bugs — blind and reflection vulnerabilities — never show up in any response the scanner can see. Confirming them means making the target call back to a listener you control. Everything NewScan verifies in-band stays fully local and free; NewScan Pro adds the NewNormal-hosted listener that triggers and verifies the rest end to end.

Only the callback interactions touch the hosted service — your target traffic, findings, and AI keys still never leave your machine. This is the one capability that needs an account; the scanner itself never does. Without Pro, every out-of-band check still runs its in-band arm — you get the vulnerability class, minus the blind confirmation.

01

Open a session

The licensed scanner gets a unique canary host; payloads carry it so any callback is yours alone.

02

Target calls back

A vulnerable target reaches the hosted HTTP/DNS endpoint; the interaction is matched to your session.

03

Verify & record

NewScan ties the callback to the request that caused it and records a confirmed finding.

// OUT-OF-BAND DETECTIONS PRO UNLOCKS

Detection How the callback confirms it
Blind SSRFThe target fetches the canary over HTTP or DNS — proof the server made the request. Separate arms prove an allow-list bypass too (redirect-follow, DNS rebinding, credential and encoding tricks), each with the remediation for how it got through.
SSRF where scanners don’t lookGraphQL arguments found by introspection, image/URL proxies that carry the origin in the path (/unsafe/http://… — Thumbor, imgproxy, /_next/image), and webhook/upstream fetches (OWASP API10). Same canary, surfaces a parameter sweep never reaches.
OAuth / OIDC URI SSRFThe URI params an authorization server is supposed to dereference — request_uri, jwks_uri, sector_identifier_uri, logo_uri — pointed at the listener. A callback proves the server fetches attacker URLs pre-auth.
Prompt-injection SSRF (LLM & MCP)A canary URL planted in the prompt instructs the model’s browsing/fetch tool to retrieve it; the callback proves the injection actually drove a server-side request. Same arm confirms a poisoned MCP tool reaching out.
Blind XSSA stored payload fires later — when an admin views it — and loads its script from the listener. Nothing in the response you got ever showed it.
OOB XXEAn external entity resolves against the listener — in a JSON/XML API, a SOAP operation, or an uploaded SVG — confirming the parser is vulnerable when no file content reflects.
Insecure deserialization → RCEA language gadget (Python pickle, Java URLDNS — JDK-only, no extra library needed) makes the target call out as it deserializes — proving execution before any response is rendered.
CVE RCE callbacksLog4Shell (CVE-2021-44228), Text4Shell (CVE-2022-42889), Fastjson autotype and Langflow’s unauthenticated /api/v1/validate/code — a lookup reaching the listener proves the version present actually executes, instead of guessing from a version string.
JWT jku / x5uA forged token points at a JWKS on the listener; the fetch proves the verifier trusts attacker-supplied keys — token forgery and SSRF at once.
Reset poisoning & email header injectionThe app’s own mail lands in the hosted SMTP sink — proving it sent mail out, and revealing a host-header-poisoned reset link (account takeover) or an attacker-injected recipient.
Remote include & XSLT fetchAn include/template parameter (RFI) or an XSLT document() pulls the listener’s URL server-side — the recorded pull is the confirmation when nothing renders.
Open DNS resolver & SMTP relayNetwork mode: a recursive query for a canary host, and one external→external test message. A DNS callback or a delivery into the sink is the only way to prove the abuse actually works from outside.

These are the highest-impact ones — the hosted listener arms every out-of-band check in NewScan, and new ones land with the daily detection releases. Each callback is correlated to the request that triggered it and recorded as a verified, reproduced finding.

// ALSO IN PRO

Shipped

Daily detection signature updates ✓

new detections every day, delivered over the air as signed signature packs — a Pro install picks them up at startup, no new image

Jira integration ✓

push findings straight to Jira tickets — re-filing updates instead of duplicating

GitHub Issues integration ✓

open GitHub Issues from findings; connect the repo on your account page

Security-framework reports ✓

reports scoped to PCI DSS, SOC 2, ISO 27001, HITRUST, HIPAA & NIST 800-53

See NewScan Pro pricing →

Enterprise licenses available — contact sales for volume, multi-seat, and custom terms.

Already ran it? Tell us what to sharpen → · Want a say in what's next? Vote on the roadmap →