FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

RajaMuhammadAwais/RISKX: RISKX - Research-first enterprise cyber-risk CLI: attack-surface discovery, vulnerability intelligence and risk prioritization. Evidence-backed, no guessing, offline-capable. · GitHub

Repository files navigation

+--------------------------------+
|   ____  ___ ____  _  ____  __ |
|  |  _ \|_ _/ ___|| |/ /\ \/ / |
|  | |_) || |\___ \| ' /  \  /  |
|  |  _ < | | ___) | . \  /  \  |
|  |_| \_\___|____/|_|\_\/_/\_\ |
+--------------------------------+

RISKX

Enterprise Cyber-Risk CLI — Research-First. Evidence-Backed. No Guessing.

Powered by RAJA MUHAMMAD AWAIS — Cyber Security Researcher


Purpose

RISKX is a command-line tool for continuous threat-exposure management (CTEM). It discovers your assets passively, enriches them with verified vulnerability intelligence, scores risk with a deterministic evidence-backed model, ranks attack paths, validates findings safely, and produces executive reports and machine-readable exports — all with mandatory evidence attached to every finding.

It follows the CISA CTEM lifecycle — Discover → Prioritize → Remediate → Validate — and is grounded exclusively in verified primary sources: CISA, NIST NVD, FIRST, MITRE, OWASP, and OSV.

Demo

Full end-to-end walkthrough of every RISKX feature (init → doctor → config → discover --delta → assets → vuln → prioritize → risk → delta → export (SARIF / CSV / JSONL) → report → graph → explain → attack-path → policy → validate → feed → cloud → serve → mcp → continuous → scan), captured live against a real build of v0.4.0.

Terminal recording — real RISKX v0.4.0 output, evidence-backed findings, no simulated data. Source: videos/RISKX_full_features_demo.mp4 in the repository.

3-Minute Live Session — Narrated End-to-End Demo

Narrated live terminal session — all 23 RISKX commands typed in real time with a synced voice-over, real v0.4.0 output, no simulated data. Source: videos/RISKX_live_session.mp4 in the repository.


THE NO-GUESSING RULE. Facts, inferences, and recommendations are separated in the data model. Detection without evidence is reported as insufficient confidence — never a fabricated finding. Inferred edges and findings are explicitly labeled and never presented as confirmed. Stale feeds are marked STALE, never silently dropped. Feed failures raise explicit errors, never "no data".

This is a non-commercial tool: see NON_COMMERCIAL.md and the LICENSE (CC BY-NC-ND 4.0). You are free to use, build, and share it for research, education, and personal defense — commercial use requires a separate license from the author.

Why RISKX

Most security tools present conclusions as facts. RISKX presents conclusions with their evidence: every finding carries what was observed, which source said so, when it was checked, and how confident the tool is. This makes the output audit-ready — an analyst can trace any line of a report back to the observation that produced it.

Principle How RISKX enforces it
No guessing Findings without evidence get insufficient confidence
Evidence provenance Every artifact carries source, URL, access time, version
Safe by default Discovery is passive/read-only; validation needs explicit authorization
Freshness discipline Feeds declare age; stale data is marked, never hidden
Determinism Risk model risk-v1 is fully deterministic and reproducible
Machine-readable Canonical versioned JSON on every command (--json)

What's New in v0.3.0

Feature Description
riskx serve Serves the evidence store as a read-only JSON API for agents, SIEM, and BI tooling (GET /v1/assets, /v1/findings, /v1/evidence, /v1/relationships, /v1/risk, /v1/health, /v1/metadata). Access is protected by a user-supplied API key (RISKX_API_KEY env or --key flag — no key, no access: 401). Defaults to loopback only (127.0.0.1:8890).
riskx discover --ct Certificate-transparency enumeration over public CT logs (verified SSLMate certspotter API). Pure observation — zero packets sent to the target. Wildcard SANs are reported as-is, never expanded into guessed hostnames. Results carry certificate_transparency provenance and persist to the evidence store with --data.
riskx explain Optional LLM explanation layer (OFF by default). The operator supplies their own LLM API key (RISKX_LLM_API_KEY — never embedded, never logged) and names their own model (llm.model). Supports any OpenAI-compatible endpoint, including self-hosted providers via llm.base_url. The LLM may only explain verified native content; it never sets severity, confidence, classification, or remediation. Provider failures degrade gracefully — the native output always prints.

These updates follow the research-backed roadmap (P0: agent data layer, CT-log attack-surface depth, agentic AI consumers): agents integrate over the canonical JSON evidence API instead of building their own scanners. Full flag tables are in the Flags Reference.

What's New in v0.4.0

Feature Description
riskx feed sync Pulls verified primary sources (CISA KEV catalog, FIRST EPSS scores) into a local, provenance-tagged offline cache (~/.riskx/feed.json by default). Every row records its source URL and fetch timestamp; entries older than 7 days are marked STALE, never silently trusted — a failed fetch keeps the last usable cache and reports the failure explicitly (spec §48: feed down → marked stale, never "no data").
riskx feed list Lists every cached feed entry — source, CVE, descriptor, fetch time, and staleness — with zero network requests. The cache is the authoritative offline copy, so researchers can inspect enrichment evidence without touching upstream catalogs. --stale filters to expired entries; --json emits canonical JSON.
riskx prioritize Ranks stored findings by documented public exploitation evidence only: CISA KEV membership (confirmed in-the-wild exploitation) and FIRST EPSS scores (published exploitation probability). Findings with no public exploit evidence are ranked last. Every rank line carries the exact evidence that produced it — source URL, CVE, and value — and the underlying rank-v1 model is fully deterministic (ties broken by severity, then finding ID). Requires a populated evidence store and a synced feed cache; purely local and offline.
Feed-aware vuln pipeline The vulnerability enricher now merges the offline KEV/EPSS cache with the evidence store using source-aware merging — a sync that fails partway never wipes rows from a healthy source.
Delta scanning (delta-v1) riskx delta diffs the two most recent scan snapshots stored in the evidence store and reports new, gone, and changed assets plus new, resolved, and changed findings. riskx discover --delta snapshots each run (content-addressed snapshot IDs — identical runs reproduce identical IDs) and prints the change summary versus the prior run. Every delta item is auditable: it carries the SHA-256 hashes of the compared content and the exact fingerprint fields that drifted (e.g. http_server), never guessed interpretations.

The v0.4.0 release implements the evidence-based prioritization layer of the research roadmap: enrichment data must be offline-verifiable, provenance-tagged, and stale-marked before any finding can be ranked on it — no live-only lookups, no inferred exploit claims. Full flag tables are in the Flags Reference.

v0.4.0 Quick Start Additions

# 0. Pull verified feeds into the local offline cache (the only network touch-point)
riskx feed sync                        # sync KEV catalog
riskx feed sync --epss CVE-2021-44228,CVE-2024-3094   # also pull EPSS for listed CVEs

# Inspect the cache offline (no network)
riskx feed list
riskx feed list --stale --json

# Rank findings by documented exploit evidence (offline, deterministic)
riskx prioritize                       # requires --data store + synced cache
riskx prioritize --data ./riskx.db --json

# Delta scanning: snapshot each run, report changes vs the prior run
riskx discover example.com --data ./riskx.db --delta
riskx discover example.com --data ./riskx.db --delta   # second run shows new/gone/changed assets vs the first

# Replay any earlier pair of stored snapshots
riskx delta --data ./riskx.db --json
riskx delta --data ./riskx.db --since snap-abcdef1234567890

Operating System Compatibility

RISKX is written in pure Go with a pure-Go SQLite driver (no CGo), so the same binary model builds and runs on every supported platform. Compatibility was verified on Ubuntu 24.04 (linux/amd64); other platforms use the identical code path.

Operating System Versions Method Status
Ubuntu 22.04, 24.04, 25.04 Build from source or Go install Verified on 24.04
Debian 12 (Bookworm), 13 (Trixie) Build from source or Go install Supported
Fedora 40, 41, 42 Build from source or Go install Supported
Arch Linux / Manjaro Rolling Build from source or Go install Supported
openSUSE Leap 15.6, Tumbleweed Build from source or Go install Supported
Kali Linux Rolling, 2024/2025 Build from source (preinstalled Go or go install) Supported
CentOS Stream / AlmaLinux / Rocky 9+ Build from source (requires recent Go) Supported
macOS 14 (Sonoma), 15 (Sequoia), 16+ Build from source or Go install Supported
Windows 10, 11 Build from source or Go install (riskx.exe) Supported

Installation

No Go toolchain required. The recommended installation pulls the pre-built binary for your OS and CPU architecture directly from the official GitHub Releases — the installer never clones the repository, downloads only one binary plus its checksums file, verifies the SHA-256 checksum before installing, and installs into a user-writable directory (~/.local/bin on Linux/macOS, %USERPROFILE%\.local\bin on Windows; created automatically if it does not exist). No sudo, no admin rights required.

Method 1 — One-command installer (recommended)

Linux / macOS:

curl -fsSL https://raw.githubusercontent.com/RajaMuhammadAwais/RISKX/main/install.sh | sh

Windows (PowerShell):

irm https://raw.githubusercontent.com/RajaMuhammadAwais/RISKX/main/install.ps1 | iex

The installer detects your OS and CPU architecture, resolves the latest stable release (prereleases are never installed automatically), downloads the matching binary from the official GitHub Release, verifies its SHA-256 checksum against the release's checksums.txt (on failure the file is deleted and nothing is installed), and places it in your user bin directory. If that directory is not on your PATH, the installer prints the exact command to add it.

Install a specific release:

RISKX_VERSION=v0.4.0 curl -fsSL https://raw.githubusercontent.com/RajaMuhammadAwais/RISKX/main/install.sh | sh   # Linux / macOS
$env:RISKX_VERSION="v0.4.0"; irm https://raw.githubusercontent.com/RajaMuhammadAwais/RISKX/main/install.ps1 | iex   # Windows

Override the install directory (either platform):

RISKX_BIN_DIR=/opt/riskx/bin curl -fsSL https://raw.githubusercontent.com/RajaMuhammadAwais/RISKX/main/install.sh | sh   # Linux / macOS
$env:RISKX_BIN_DIR="C:\Tools\RISKX"; irm https://raw.githubusercontent.com/RajaMuhammadAwais/RISKX/main/install.ps1 | iex   # Windows

What the installer does — and does not do: it resolves a release, downloads exactly two files (the binary and checksums.txt) over HTTPS, verifies the SHA-256 checksum, copies the verified binary to the user bin directory, and prints the installed version. It never clones the repository, downloads unrelated files, modifies unrelated user files, installs persistence, creates services or scheduled tasks, touches firewall rules, or collects telemetry. A checksum failure deletes the downloaded file and exits with a clear error — an unverified binary is never silently installed.

Method 2 — Manual download from GitHub Releases

Download the binary that matches your platform from Releases alongside checksums.txt, verify it, then install:

# Linux example (adjust OS/arch to match your platform)
wget https://github.com/RajaMuhammadAwais/RISKX/releases/download/v0.4.0/riskx_linux_amd64
wget https://github.com/RajaMuhammadAwais/RISKX/releases/download/v0.4.0/checksums.txt
sha256sum -c <(grep riskx_linux_amd64 checksums.txt)
chmod +x riskx_linux_amd64 && mv riskx_linux_amd64 ~/.local/bin/riskx

Method 3 — Go install (source build)

Go 1.25 or newer is required. The binary is built from source and lands in $(go env GOPATH)/bin (default ~/go/bin):

go version

Install Go if not present (Ubuntu / Debian, latest versions):

# Install Go 1.25+ if not present
sudo apt update
sudo apt install -y golang-go   # or download latest from https://go.dev/dl/

# Verify
go version

Fedora:

sudo dnf install -y golang
go version

Arch Linux:

sudo pacman -S go
go version

macOS (Homebrew):

brew install go
go version

Windows (Scoop):

scoop install go
go version

Then build from source or use go install:

go install github.com/RajaMuhammadAwais/RISKX/cmd/riskx@latest

Method 4 — Build from source

git clone https://github.com/RajaMuhammadAwais/RISKX.git
cd RISKX
go build -o riskx ./cmd/riskx

# Move into your PATH
sudo mv riskx /usr/local/bin/    # Linux / macOS
# or on Windows, move riskx.exe anywhere on %PATH%

Cross-compiling for another OS works identically:

GOOS=windows GOARCH=amd64 go build -o riskx.exe ./cmd/riskx
GOOS=darwin  GOARCH=arm64 go build -o riskx ./cmd/riskx
GOOS=linux   GOARCH=arm64 go build -o riskx ./cmd/riskx

Supported platforms

Each release publishes these pre-built binaries:

Asset name Platform
riskx_linux_amd64 Linux amd64
riskx_linux_arm64 Linux arm64
riskx_darwin_amd64 macOS amd64 (Intel)
riskx_darwin_arm64 macOS arm64 (Apple Silicon)
riskx_windows_amd64.exe Windows amd64
riskx_windows_arm64.exe Windows arm64

Every release also ships checksums.txt with SHA-256 hashes for all assets. Release binaries inject version, commit, build date, and platform via Go linker flags — visible in the version output.

Quick verification

riskx version
riskx doctor          # self-diagnoses your environment

Quick Start

The CTEM loop in five commands:

# 1. Discover assets (passive, read-only); --ct adds certificate-transparency enumeration
riskx discover example.com --ct --data ./riskx.db

# 2. Pull verified feeds into the offline cache (KEV / EPSS) — do this first
riskx feed sync
riskx feed sync --epss CVE-2021-44228,CVE-2024-3094

# 3. Enrich vulnerabilities (CISA KEV, NVD CVSS, FIRST EPSS, OSV aliases)
riskx vuln CVE-2021-44228 --data ./riskx.db

# 3b. Rank what to fix first by documented exploit evidence (offline, deterministic)
riskx prioritize --data ./riskx.db

# 4. Score risk deterministically
riskx risk --data ./riskx.db

# 5. Validate safely (read-only checks, no exploitation)
riskx validate tls example.com --data ./riskx.db

# 6. Report + export for your SOC / ticketing system
riskx report summary --data ./riskx.db
riskx export sarif  --data ./riskx.db > riskx.sarif   # GitHub/SonarQube compatible
riskx export csv    --data ./riskx.db > riskx.csv
riskx export jsonl  --data ./riskx.db > riskx.jsonl

# 7. Optional: serve the evidence store as a read-only JSON API (agents / BI / SIEM)
riskx serve --data ./riskx.db --listen 127.0.0.1:8890 --key "$RISKX_API_KEY"

# 8. Optional: LLM explanation of a verified finding (off by default)
riskx explain --finding <id> --data ./riskx.db   # needs llm.enabled + RISKX_LLM_API_KEY

Run everything at once:

riskx scan example.com --mode passive

Command Reference

Command What it does
discover Passive asset discovery: DNS, HTTP, TLS, RDAP, TCP reachability, CT-log enumeration (--ct)
feed Manage the offline intelligence cache: feed sync (pull KEV/EPSS into ~/.riskx/feed.json), feed list (offline inspection, --stale)
serve Read-only JSON API over the evidence store; user key via RISKX_API_KEY
vuln Vulnerability intelligence: CISA KEV, NVD CVSS, FIRST EPSS, OSV aliases
prioritize Rank stored findings by documented public exploit evidence (KEV + EPSS, model rank-v1); offline, deterministic
delta Delta scanning (model delta-v1): diff the two most recent stored scan snapshots — new/gone/changed assets, new/resolved/changed findings — with auditable SHA-256 hashes and field-level drift details
risk Deterministic risk scoring (risk-v1) with factor tables
attack-path Rank attack paths from internet entry to critical assets
graph Inspect the evidence-backed attack graph (centrality, edges)
validate Safe read-only validation: DNS, TLS, HTTP checks
cloud AWS read-only cloud discovery (STS, EC2, S3, IAM)
report Executive risk report over the evidence store
export Export findings: JSONL, CSV, SARIF 2.1.0
assets List the local asset inventory
scan Full flow: discover → enrich → risk-score
policy Policy evaluation with CI exit codes (0/1/2)
continuous Scheduled continuous exposure management
config Show / validate the configuration
init Initialize the configuration directory
doctor Diagnose the local environment
version Print versions (tool + all data models)
explain Optional LLM explanation of verified findings; user key via RISKX_LLM_API_KEY (off by default)

Commands marked future phase (identity, agent, mcp) are scaffolded and reserved; they print a clear status message and do nothing silently.

Flags Reference

Global flags (every command)

Flag Short Purpose Default
--help -h Show command help —
--json -j Emit canonical JSON output human-readable
--config — Path to config file ~/.config/riskx/config.yaml
--verbose -v Enable debug logging off
--quiet -q Suppress non-essential output off
--version — Print version (root only) —

discover

Flag Purpose Default
--file File of targets, one per line —
--mode Discovery mode: passive or safe passive
--records DNS record types, comma-separated A,AAAA,CNAME,MX,NS,TXT
--ports TCP ports to probe (connect-only), comma-separated —
--ct Add certificate-transparency enumeration (public CT logs; wildcards reported as-is) off
--data Evidence store path; off to disable; env RISKX_DATA ~/.riskx/riskx.db
--delta Snapshot this run and print changes versus the prior stored snapshot (new/gone/changed assets) off

vuln / risk

Flag Purpose Default
--data Evidence store path; off to disable; env RISKX_DATA ~/.riskx/riskx.db

validate

Flag Purpose Default
--kind Check kind: dns, tls, or http dns
--dns-type DNS record type for DNS checks A
--dns-want Expected DNS record values (optional) —
--mode Validation mode: safe, validation, or active validation
--ci CI mode (deterministic output) off
--preapprove Pre-approve the printed plan (CI only) off
--data Evidence store path; env RISKX_DATA ~/.riskx/riskx.db

cloud discover

Flag Purpose Default
--action whoami, instances, buckets, identities, or all all
--mode safe or validation validation
--ci CI mode off
--preapprove Pre-approve the printed plan (CI only) off
--data Evidence store path; env RISKX_DATA ~/.riskx/riskx.db

feed sync / feed list

Flag Purpose Default
--cache Feed cache file path ~/.riskx/feed.json
--epss Comma-separated CVEs to also pull FIRST EPSS scores for (sync only) —
--stale Show only STALE (7+ day old) entries (list only) off

The feed cache is the only point where RISKX touches upstream catalogs; every other command reads the cached, provenance-tagged copy. Failed fetches keep the last usable cache and report the failure explicitly — data is marked STALE, never silently removed.

prioritize

Flag Purpose Default
--data Evidence store path; env RISKX_DATA ~/.riskx/riskx.db
--cache Feed cache file path ~/.riskx/feed.json

Requires both a populated evidence store (findings with CVE references) and a synced feed cache (riskx feed sync). Ranking uses documented public exploitation evidence only (rank-v1): KEV membership beats EPSS≥0.5, both beat no-evidence; ties are broken by severity then finding ID. Offline and deterministic.

delta

Flag Purpose Default
--data Evidence store path; env RISKX_DATA ~/.riskx/riskx.db
--since Pin the older snapshot ID; compared against the next chronologically stored snapshot latest stored

Snapshots are content-addressed — identical runs reproduce identical snapshot IDs — so delta reports stay reproducible and audit-grade: every change carries the SHA-256 hashes of both compared contents and the exact fingerprint fields that drifted. With only one stored snapshot the first run prints a confirmation message and stores the snapshot; subsequent runs compare against it.

serve

Flag Purpose Default
--data Evidence store path; env RISKX_DATA ~/.riskx/riskx.db
--listen Bind address 127.0.0.1:8890
--key API key for /v1 access; env RISKX_API_KEY (recommended) —

Without a key the API refuses all authenticated endpoints (401). Serves: GET /v1/assets, /v1/findings, /v1/evidence, /v1/relationships, /v1/risk, /v1/health, /v1/metadata.

explain

Flag Purpose Default
--finding Finding id from the evidence store —
--text Verified text to explain —
--prompt Override the explanation prompt research-based default
--data Evidence store path (with --finding); env RISKX_DATA ~/.riskx/riskx.db

Requires llm.enabled: true in config plus RISKX_LLM_API_KEY and llm.model. The LLM only explains verified native content — it never sets severity, confidence, or classification.

report, export, scan, attack-path, policy, continuous

Command Notable flags
report summary --data
export sarif --data, --output (file; default stdout)
export csv / jsonl --data, --output
scan --mode (default passive), --ci, --preapprove
attack-path top <n> --mode edge-status gate: observed_only, evidence_backed, exploratory (default evidence_backed)
policy check --file (policy file)
continuous --every cycle interval (default 24h)

Examples

Passive discovery with JSON output:

riskx discover example.com --json

Bulk targets from a file:

riskx discover --file targets.txt --records A,MX,TXT --ports 80,443,8080

Validate a TLS configuration safely:

riskx validate tls example.com --json

Verify DNS against expected values (useful in CI):

riskx validate dns example.com --dns-want 93.184.216.34 --ci --preapprove

AWS cloud discovery (read-only; requires AWS_ACCESS_KEY_ID + AWS_SECRET_ACCESS_KEY):

riskx cloud discover all
riskx cloud discover --action buckets

Policy check for CI pipelines (exit code 0/1/2):

riskx policy check --file policy.yaml
echo $?

Evidence Model

Every security artifact in RISKX carries provenance. Findings separate FACT (observation + evidence items), INFERENCE (confidence and status), and RECOMMENDATION (remediation, never presented as fact). Attack-graph edges carry one of four statuses:

  • observed — directly measured in the current scan
  • inferred — plausible from evidence, explicitly never confirmed
  • potential — theoretically possible, no evidence yet
  • validated — confirmed via an approved validation step

Feeds declare freshness; data older than its allowed age is marked stale.

Data Sources

Source Use Attribution
CISA KEV Known-exploited-vulnerability membership CISA
NVD API 2.0 CVSS vectors and scores "Products incorporate NVD, a product of NIST. This information is not guaranteed to be accurate."
FIRST EPSS Exploit probability scores FIRST
OSV Aliases and ecosystem packages Google / OSV
MITRE ATT&CK Technique classification (STIX v19.2) MITRE
CWE Weakness classification MITRE
OWASP Top 10:2025 Application-risk classification OWASP
OWASP MCP Top 10 AI-agent/MCP-risk classification OWASP
SSLMate certspotter Certificate-transparency subdomain enumeration (--ct) SSLMate

Environment Variables

Variable Purpose Used by
RISKX_DATA Default evidence store path (--data override) all analysis commands
RISKX_API_KEY API key for riskx serve (--key override) serve
RISKX_LLM_API_KEY Operator's own LLM API key (never embedded, never logged) explain (LLM layer, off by default)

Versioned Data Models

Model Version Used by
asset asset-v1 discover, assets
finding finding-v1 vuln, report, export
evidence evidence-v1 all commands
risk risk-v1 risk
graph graph-v1 attack-path, graph
storage storage-v1 --data / RISKX_DATA
report report-v1 report

Print all versions at once with riskx version.

Exit Codes

Code Meaning
0 No policy violation / clean
1 Policy violation detected
2 Execution error

Repository Layout

cmd/riskx/                 CLI entry point and command tree
internal/core/             config, log, errs, mode, output, idgen, runner
internal/discovery/        dns, http, tls, rdap passive-discovery engines
internal/vulnerability/    ingest (KEV/NVD/EPSS/OSV), normalize, findings
internal/risk/             risk-v1 deterministic scoring engine
internal/graph/            graph-v1 attack graph (BFS, Dijkstra, centrality)
internal/policy/           YAML policy evaluation
internal/reporting/        report-v1 summary + SARIF 2.1.0 / CSV / JSONL export
internal/validate/         safe read-only DNS/TLS/HTTP validation
internal/cloud/            cloud-v1 AWS read-only discovery (SigV4)
internal/storage/          storage-v1 SQLite persistence
internal/evidence/         source-metadata and confidence typing
pkg/models/                canonical versioned data model
pkg/plugins/               plugin interfaces and registry
.github/workflows/         CI: test/build, lint, staticcheck, govulncheck

Development

go build ./...          # compile everything
go vet ./...            # static analysis
go test ./... -short    # unit + fixture tests (live feeds skipped)
go test ./...           # includes live feed integration tests
go test ./... -race     # race detector (pure-Go SQLite driver; no gcc needed)
go test -bench=. -run=^$ ./internal/risk ./internal/vulnerability/ingest

Benchmarks

Measured on live hardware (Ubuntu 24.04, linux/amd64):

Benchmark Result
Risk scoring (risk-v1, 7 factors) ~2.2 µs/op, 21 allocs
CISA KEV ingestion (1,666 verified rows) ~1.8–2.0 ms, schema-validated
Test suite 15/15 packages pass with race detector; vet + staticcheck clean

License

RISKX is non-commercial open-source software authored by Raja Muhammad Awais.

  • Code, documentation, and research artifacts: CC BY-NC-ND 4.0 — free to use, build, and share for non-commercial purposes with attribution; no commercial use and no derivative works without permission.
  • Commercial licensing: contact the author (see NON_COMMERCIAL.md).
  • Third-party data: CISA, NIST NVD, FIRST EPSS, MITRE, OWASP, and OSV data carry their own licenses and attribution requirements, which RISKX reproduces verbatim in its outputs.

Author

RAJA MUHAMMAD AWAIS — Cyber Security Researcher Built with a research-first methodology: every capability grounded in verified primary sources, every output evidence-backed.


If this project helps you, star it on GitHub — and remember: scan only what you own or are authorized to test.

About

RISKX - Research-first enterprise cyber-risk CLI: attack-surface discovery, vulnerability intelligence and risk prioritization. Evidence-backed, no guessing, offline-capable.

Topics

Resources

Security policy

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages


Back | FazBrowse Home | New Git URL