| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Name | Name | Last commit date | ||
|---|---|---|---|---|
+--------------------------------+ | ____ ___ ____ _ ____ __ | | | _ \|_ _/ ___|| |/ /\ \/ / | | | |_) || |\___ \| ' / \ / | | | _ < | | ___) | . \ / \ | | |_| \_\___|____/|_|\_\/_/\_\ | +--------------------------------+
Powered by RAJA MUHAMMAD AWAIS — Cyber Security Researcher
RISKX is a command-line tool for continuous threat-exposure management (CTEM). It discovers your assets passively, enriches them with verified vulnerability intelligence, scores risk with a deterministic evidence-backed model, ranks attack paths, validates findings safely, and produces executive reports and machine-readable exports — all with mandatory evidence attached to every finding.
It follows the CISA CTEM lifecycle — Discover → Prioritize → Remediate → Validate — and is grounded exclusively in verified primary sources: CISA, NIST NVD, FIRST, MITRE, OWASP, and OSV.
Full end-to-end walkthrough of every RISKX feature (init → doctor → config → discover --delta → assets → vuln → prioritize → risk → delta → export (SARIF / CSV / JSONL) → report → graph → explain → attack-path → policy → validate → feed → cloud → serve → mcp → continuous → scan), captured live against a real build of v0.4.0.
Terminal recording — real RISKX v0.4.0 output, evidence-backed findings, no simulated data. Source: videos/RISKX_full_features_demo.mp4 in the repository.
Narrated live terminal session — all 23 RISKX commands typed in real time with a synced voice-over, real v0.4.0 output, no simulated data. Source: videos/RISKX_live_session.mp4 in the repository.
THE NO-GUESSING RULE. Facts, inferences, and recommendations are separated in the data model. Detection without evidence is reported as insufficient confidence — never a fabricated finding. Inferred edges and findings are explicitly labeled and never presented as confirmed. Stale feeds are marked STALE, never silently dropped. Feed failures raise explicit errors, never "no data".
This is a non-commercial tool: see NON_COMMERCIAL.md and the LICENSE (CC BY-NC-ND 4.0). You are free to use, build, and share it for research, education, and personal defense — commercial use requires a separate license from the author.
Most security tools present conclusions as facts. RISKX presents conclusions with their evidence: every finding carries what was observed, which source said so, when it was checked, and how confident the tool is. This makes the output audit-ready — an analyst can trace any line of a report back to the observation that produced it.
| Principle | How RISKX enforces it |
|---|---|
| No guessing | Findings without evidence get insufficient confidence |
| Evidence provenance | Every artifact carries source, URL, access time, version |
| Safe by default | Discovery is passive/read-only; validation needs explicit authorization |
| Freshness discipline | Feeds declare age; stale data is marked, never hidden |
| Determinism | Risk model risk-v1 is fully deterministic and reproducible |
| Machine-readable | Canonical versioned JSON on every command (--json) |
| Feature | Description |
|---|---|
| riskx serve | Serves the evidence store as a read-only JSON API for agents, SIEM, and BI tooling (GET /v1/assets, /v1/findings, /v1/evidence, /v1/relationships, /v1/risk, /v1/health, /v1/metadata). Access is protected by a user-supplied API key (RISKX_API_KEY env or --key flag — no key, no access: 401). Defaults to loopback only (127.0.0.1:8890). |
| riskx discover --ct | Certificate-transparency enumeration over public CT logs (verified SSLMate certspotter API). Pure observation — zero packets sent to the target. Wildcard SANs are reported as-is, never expanded into guessed hostnames. Results carry certificate_transparency provenance and persist to the evidence store with --data. |
| riskx explain | Optional LLM explanation layer (OFF by default). The operator supplies their own LLM API key (RISKX_LLM_API_KEY — never embedded, never logged) and names their own model (llm.model). Supports any OpenAI-compatible endpoint, including self-hosted providers via llm.base_url. The LLM may only explain verified native content; it never sets severity, confidence, classification, or remediation. Provider failures degrade gracefully — the native output always prints. |
These updates follow the research-backed roadmap (P0: agent data layer, CT-log attack-surface depth, agentic AI consumers): agents integrate over the canonical JSON evidence API instead of building their own scanners. Full flag tables are in the Flags Reference.
| Feature | Description |
|---|---|
| riskx feed sync | Pulls verified primary sources (CISA KEV catalog, FIRST EPSS scores) into a local, provenance-tagged offline cache (~/.riskx/feed.json by default). Every row records its source URL and fetch timestamp; entries older than 7 days are marked STALE, never silently trusted — a failed fetch keeps the last usable cache and reports the failure explicitly (spec §48: feed down → marked stale, never "no data"). |
| riskx feed list | Lists every cached feed entry — source, CVE, descriptor, fetch time, and staleness — with zero network requests. The cache is the authoritative offline copy, so researchers can inspect enrichment evidence without touching upstream catalogs. --stale filters to expired entries; --json emits canonical JSON. |
| riskx prioritize | Ranks stored findings by documented public exploitation evidence only: CISA KEV membership (confirmed in-the-wild exploitation) and FIRST EPSS scores (published exploitation probability). Findings with no public exploit evidence are ranked last. Every rank line carries the exact evidence that produced it — source URL, CVE, and value — and the underlying rank-v1 model is fully deterministic (ties broken by severity, then finding ID). Requires a populated evidence store and a synced feed cache; purely local and offline. |
| Feed-aware vuln pipeline | The vulnerability enricher now merges the offline KEV/EPSS cache with the evidence store using source-aware merging — a sync that fails partway never wipes rows from a healthy source. |
| Delta scanning (delta-v1) | riskx delta diffs the two most recent scan snapshots stored in the evidence store and reports new, gone, and changed assets plus new, resolved, and changed findings. riskx discover --delta snapshots each run (content-addressed snapshot IDs — identical runs reproduce identical IDs) and prints the change summary versus the prior run. Every delta item is auditable: it carries the SHA-256 hashes of the compared content and the exact fingerprint fields that drifted (e.g. http_server), never guessed interpretations. |
The v0.4.0 release implements the evidence-based prioritization layer of the research roadmap: enrichment data must be offline-verifiable, provenance-tagged, and stale-marked before any finding can be ranked on it — no live-only lookups, no inferred exploit claims. Full flag tables are in the Flags Reference.
# 0. Pull verified feeds into the local offline cache (the only network touch-point)
riskx feed sync # sync KEV catalog
riskx feed sync --epss CVE-2021-44228,CVE-2024-3094 # also pull EPSS for listed CVEs
# Inspect the cache offline (no network)
riskx feed list
riskx feed list --stale --json
# Rank findings by documented exploit evidence (offline, deterministic)
riskx prioritize # requires --data store + synced cache
riskx prioritize --data ./riskx.db --json
# Delta scanning: snapshot each run, report changes vs the prior run
riskx discover example.com --data ./riskx.db --delta
riskx discover example.com --data ./riskx.db --delta # second run shows new/gone/changed assets vs the first
# Replay any earlier pair of stored snapshots
riskx delta --data ./riskx.db --json
riskx delta --data ./riskx.db --since snap-abcdef1234567890RISKX is written in pure Go with a pure-Go SQLite driver (no CGo), so the same binary model builds and runs on every supported platform. Compatibility was verified on Ubuntu 24.04 (linux/amd64); other platforms use the identical code path.
| Operating System | Versions | Method | Status |
|---|---|---|---|
| Ubuntu | 22.04, 24.04, 25.04 | Build from source or Go install | Verified on 24.04 |
| Debian | 12 (Bookworm), 13 (Trixie) | Build from source or Go install | Supported |
| Fedora | 40, 41, 42 | Build from source or Go install | Supported |
| Arch Linux / Manjaro | Rolling | Build from source or Go install | Supported |
| openSUSE | Leap 15.6, Tumbleweed | Build from source or Go install | Supported |
| Kali Linux | Rolling, 2024/2025 | Build from source (preinstalled Go or go install) | Supported |
| CentOS Stream / AlmaLinux / Rocky | 9+ | Build from source (requires recent Go) | Supported |
| macOS | 14 (Sonoma), 15 (Sequoia), 16+ | Build from source or Go install | Supported |
| Windows | 10, 11 | Build from source or Go install (riskx.exe) | Supported |
No Go toolchain required. The recommended installation pulls the pre-built binary for your OS and CPU architecture directly from the official GitHub Releases — the installer never clones the repository, downloads only one binary plus its checksums file, verifies the SHA-256 checksum before installing, and installs into a user-writable directory (~/.local/bin on Linux/macOS, %USERPROFILE%\.local\bin on Windows; created automatically if it does not exist). No sudo, no admin rights required.
Linux / macOS:
curl -fsSL https://raw.githubusercontent.com/RajaMuhammadAwais/RISKX/main/install.sh | shWindows (PowerShell):
irm https://raw.githubusercontent.com/RajaMuhammadAwais/RISKX/main/install.ps1 | iexThe installer detects your OS and CPU architecture, resolves the latest stable release (prereleases are never installed automatically), downloads the matching binary from the official GitHub Release, verifies its SHA-256 checksum against the release's checksums.txt (on failure the file is deleted and nothing is installed), and places it in your user bin directory. If that directory is not on your PATH, the installer prints the exact command to add it.
Install a specific release:
RISKX_VERSION=v0.4.0 curl -fsSL https://raw.githubusercontent.com/RajaMuhammadAwais/RISKX/main/install.sh | sh # Linux / macOS
$env:RISKX_VERSION="v0.4.0"; irm https://raw.githubusercontent.com/RajaMuhammadAwais/RISKX/main/install.ps1 | iex # WindowsOverride the install directory (either platform):
RISKX_BIN_DIR=/opt/riskx/bin curl -fsSL https://raw.githubusercontent.com/RajaMuhammadAwais/RISKX/main/install.sh | sh # Linux / macOS
$env:RISKX_BIN_DIR="C:\Tools\RISKX"; irm https://raw.githubusercontent.com/RajaMuhammadAwais/RISKX/main/install.ps1 | iex # WindowsWhat the installer does — and does not do: it resolves a release, downloads exactly two files (the binary and checksums.txt) over HTTPS, verifies the SHA-256 checksum, copies the verified binary to the user bin directory, and prints the installed version. It never clones the repository, downloads unrelated files, modifies unrelated user files, installs persistence, creates services or scheduled tasks, touches firewall rules, or collects telemetry. A checksum failure deletes the downloaded file and exits with a clear error — an unverified binary is never silently installed.
Download the binary that matches your platform from Releases alongside checksums.txt, verify it, then install:
# Linux example (adjust OS/arch to match your platform)
wget https://github.com/RajaMuhammadAwais/RISKX/releases/download/v0.4.0/riskx_linux_amd64
wget https://github.com/RajaMuhammadAwais/RISKX/releases/download/v0.4.0/checksums.txt
sha256sum -c <(grep riskx_linux_amd64 checksums.txt)
chmod +x riskx_linux_amd64 && mv riskx_linux_amd64 ~/.local/bin/riskxGo 1.25 or newer is required. The binary is built from source and lands in $(go env GOPATH)/bin (default ~/go/bin):
go versionInstall Go if not present (Ubuntu / Debian, latest versions):
# Install Go 1.25+ if not present
sudo apt update
sudo apt install -y golang-go # or download latest from https://go.dev/dl/
# Verify
go versionFedora:
sudo dnf install -y golang
go versionArch Linux:
sudo pacman -S go
go versionmacOS (Homebrew):
brew install go
go versionWindows (Scoop):
scoop install go
go versionThen build from source or use go install:
go install github.com/RajaMuhammadAwais/RISKX/cmd/riskx@latestgit clone https://github.com/RajaMuhammadAwais/RISKX.git
cd RISKX
go build -o riskx ./cmd/riskx
# Move into your PATH
sudo mv riskx /usr/local/bin/ # Linux / macOS
# or on Windows, move riskx.exe anywhere on %PATH%Cross-compiling for another OS works identically:
GOOS=windows GOARCH=amd64 go build -o riskx.exe ./cmd/riskx
GOOS=darwin GOARCH=arm64 go build -o riskx ./cmd/riskx
GOOS=linux GOARCH=arm64 go build -o riskx ./cmd/riskxEach release publishes these pre-built binaries:
| Asset name | Platform |
|---|---|
| riskx_linux_amd64 | Linux amd64 |
| riskx_linux_arm64 | Linux arm64 |
| riskx_darwin_amd64 | macOS amd64 (Intel) |
| riskx_darwin_arm64 | macOS arm64 (Apple Silicon) |
| riskx_windows_amd64.exe | Windows amd64 |
| riskx_windows_arm64.exe | Windows arm64 |
Every release also ships checksums.txt with SHA-256 hashes for all assets. Release binaries inject version, commit, build date, and platform via Go linker flags — visible in the version output.
riskx version
riskx doctor # self-diagnoses your environmentThe CTEM loop in five commands:
# 1. Discover assets (passive, read-only); --ct adds certificate-transparency enumeration
riskx discover example.com --ct --data ./riskx.db
# 2. Pull verified feeds into the offline cache (KEV / EPSS) — do this first
riskx feed sync
riskx feed sync --epss CVE-2021-44228,CVE-2024-3094
# 3. Enrich vulnerabilities (CISA KEV, NVD CVSS, FIRST EPSS, OSV aliases)
riskx vuln CVE-2021-44228 --data ./riskx.db
# 3b. Rank what to fix first by documented exploit evidence (offline, deterministic)
riskx prioritize --data ./riskx.db
# 4. Score risk deterministically
riskx risk --data ./riskx.db
# 5. Validate safely (read-only checks, no exploitation)
riskx validate tls example.com --data ./riskx.db
# 6. Report + export for your SOC / ticketing system
riskx report summary --data ./riskx.db
riskx export sarif --data ./riskx.db > riskx.sarif # GitHub/SonarQube compatible
riskx export csv --data ./riskx.db > riskx.csv
riskx export jsonl --data ./riskx.db > riskx.jsonl
# 7. Optional: serve the evidence store as a read-only JSON API (agents / BI / SIEM)
riskx serve --data ./riskx.db --listen 127.0.0.1:8890 --key "$RISKX_API_KEY"
# 8. Optional: LLM explanation of a verified finding (off by default)
riskx explain --finding <id> --data ./riskx.db # needs llm.enabled + RISKX_LLM_API_KEYRun everything at once:
riskx scan example.com --mode passive| Command | What it does |
|---|---|
| discover | Passive asset discovery: DNS, HTTP, TLS, RDAP, TCP reachability, CT-log enumeration (--ct) |
| feed | Manage the offline intelligence cache: feed sync (pull KEV/EPSS into ~/.riskx/feed.json), feed list (offline inspection, --stale) |
| serve | Read-only JSON API over the evidence store; user key via RISKX_API_KEY |
| vuln | Vulnerability intelligence: CISA KEV, NVD CVSS, FIRST EPSS, OSV aliases |
| prioritize | Rank stored findings by documented public exploit evidence (KEV + EPSS, model rank-v1); offline, deterministic |
| delta | Delta scanning (model delta-v1): diff the two most recent stored scan snapshots — new/gone/changed assets, new/resolved/changed findings — with auditable SHA-256 hashes and field-level drift details |
| risk | Deterministic risk scoring (risk-v1) with factor tables |
| attack-path | Rank attack paths from internet entry to critical assets |
| graph | Inspect the evidence-backed attack graph (centrality, edges) |
| validate | Safe read-only validation: DNS, TLS, HTTP checks |
| cloud | AWS read-only cloud discovery (STS, EC2, S3, IAM) |
| report | Executive risk report over the evidence store |
| export | Export findings: JSONL, CSV, SARIF 2.1.0 |
| assets | List the local asset inventory |
| scan | Full flow: discover → enrich → risk-score |
| policy | Policy evaluation with CI exit codes (0/1/2) |
| continuous | Scheduled continuous exposure management |
| config | Show / validate the configuration |
| init | Initialize the configuration directory |
| doctor | Diagnose the local environment |
| version | Print versions (tool + all data models) |
| explain | Optional LLM explanation of verified findings; user key via RISKX_LLM_API_KEY (off by default) |
Commands marked future phase (identity, agent, mcp) are scaffolded and reserved; they print a clear status message and do nothing silently.
| Flag | Short | Purpose | Default |
|---|---|---|---|
| --help | -h | Show command help | — |
| --json | -j | Emit canonical JSON output | human-readable |
| --config | — | Path to config file | ~/.config/riskx/config.yaml |
| --verbose | -v | Enable debug logging | off |
| --quiet | -q | Suppress non-essential output | off |
| --version | — | Print version (root only) | — |
| Flag | Purpose | Default |
|---|---|---|
| --file | File of targets, one per line | — |
| --mode | Discovery mode: passive or safe | passive |
| --records | DNS record types, comma-separated | A,AAAA,CNAME,MX,NS,TXT |
| --ports | TCP ports to probe (connect-only), comma-separated | — |
| --ct | Add certificate-transparency enumeration (public CT logs; wildcards reported as-is) | off |
| --data | Evidence store path; off to disable; env RISKX_DATA | ~/.riskx/riskx.db |
| --delta | Snapshot this run and print changes versus the prior stored snapshot (new/gone/changed assets) | off |
| Flag | Purpose | Default |
|---|---|---|
| --data | Evidence store path; off to disable; env RISKX_DATA | ~/.riskx/riskx.db |
| Flag | Purpose | Default |
|---|---|---|
| --kind | Check kind: dns, tls, or http | dns |
| --dns-type | DNS record type for DNS checks | A |
| --dns-want | Expected DNS record values (optional) | — |
| --mode | Validation mode: safe, validation, or active | validation |
| --ci | CI mode (deterministic output) | off |
| --preapprove | Pre-approve the printed plan (CI only) | off |
| --data | Evidence store path; env RISKX_DATA | ~/.riskx/riskx.db |
| Flag | Purpose | Default |
|---|---|---|
| --action | whoami, instances, buckets, identities, or all | all |
| --mode | safe or validation | validation |
| --ci | CI mode | off |
| --preapprove | Pre-approve the printed plan (CI only) | off |
| --data | Evidence store path; env RISKX_DATA | ~/.riskx/riskx.db |
| Flag | Purpose | Default |
|---|---|---|
| --cache | Feed cache file path | ~/.riskx/feed.json |
| --epss | Comma-separated CVEs to also pull FIRST EPSS scores for (sync only) | — |
| --stale | Show only STALE (7+ day old) entries (list only) | off |
The feed cache is the only point where RISKX touches upstream catalogs; every other command reads the cached, provenance-tagged copy. Failed fetches keep the last usable cache and report the failure explicitly — data is marked STALE, never silently removed.
| Flag | Purpose | Default |
|---|---|---|
| --data | Evidence store path; env RISKX_DATA | ~/.riskx/riskx.db |
| --cache | Feed cache file path | ~/.riskx/feed.json |
Requires both a populated evidence store (findings with CVE references) and a synced feed cache (riskx feed sync). Ranking uses documented public exploitation evidence only (rank-v1): KEV membership beats EPSS≥0.5, both beat no-evidence; ties are broken by severity then finding ID. Offline and deterministic.
| Flag | Purpose | Default |
|---|---|---|
| --data | Evidence store path; env RISKX_DATA | ~/.riskx/riskx.db |
| --since | Pin the older snapshot ID; compared against the next chronologically stored snapshot | latest stored |
Snapshots are content-addressed — identical runs reproduce identical snapshot IDs — so delta reports stay reproducible and audit-grade: every change carries the SHA-256 hashes of both compared contents and the exact fingerprint fields that drifted. With only one stored snapshot the first run prints a confirmation message and stores the snapshot; subsequent runs compare against it.
| Flag | Purpose | Default |
|---|---|---|
| --data | Evidence store path; env RISKX_DATA | ~/.riskx/riskx.db |
| --listen | Bind address | 127.0.0.1:8890 |
| --key | API key for /v1 access; env RISKX_API_KEY (recommended) | — |
Without a key the API refuses all authenticated endpoints (401). Serves: GET /v1/assets, /v1/findings, /v1/evidence, /v1/relationships, /v1/risk, /v1/health, /v1/metadata.
| Flag | Purpose | Default |
|---|---|---|
| --finding | Finding id from the evidence store | — |
| --text | Verified text to explain | — |
| --prompt | Override the explanation prompt | research-based default |
| --data | Evidence store path (with --finding); env RISKX_DATA | ~/.riskx/riskx.db |
Requires llm.enabled: true in config plus RISKX_LLM_API_KEY and llm.model. The LLM only explains verified native content — it never sets severity, confidence, or classification.
| Command | Notable flags |
|---|---|
| report summary | --data |
| export sarif | --data, --output (file; default stdout) |
| export csv / jsonl | --data, --output |
| scan | --mode (default passive), --ci, --preapprove |
| attack-path top <n> | --mode edge-status gate: observed_only, evidence_backed, exploratory (default evidence_backed) |
| policy check | --file (policy file) |
| continuous | --every cycle interval (default 24h) |
Passive discovery with JSON output:
riskx discover example.com --jsonBulk targets from a file:
riskx discover --file targets.txt --records A,MX,TXT --ports 80,443,8080Validate a TLS configuration safely:
riskx validate tls example.com --jsonVerify DNS against expected values (useful in CI):
riskx validate dns example.com --dns-want 93.184.216.34 --ci --preapproveAWS cloud discovery (read-only; requires AWS_ACCESS_KEY_ID + AWS_SECRET_ACCESS_KEY):
riskx cloud discover all
riskx cloud discover --action bucketsPolicy check for CI pipelines (exit code 0/1/2):
riskx policy check --file policy.yaml
echo $?Every security artifact in RISKX carries provenance. Findings separate FACT (observation + evidence items), INFERENCE (confidence and status), and RECOMMENDATION (remediation, never presented as fact). Attack-graph edges carry one of four statuses:
Feeds declare freshness; data older than its allowed age is marked stale.
| Source | Use | Attribution |
|---|---|---|
| CISA KEV | Known-exploited-vulnerability membership | CISA |
| NVD API 2.0 | CVSS vectors and scores | "Products incorporate NVD, a product of NIST. This information is not guaranteed to be accurate." |
| FIRST EPSS | Exploit probability scores | FIRST |
| OSV | Aliases and ecosystem packages | Google / OSV |
| MITRE ATT&CK | Technique classification (STIX v19.2) | MITRE |
| CWE | Weakness classification | MITRE |
| OWASP Top 10:2025 | Application-risk classification | OWASP |
| OWASP MCP Top 10 | AI-agent/MCP-risk classification | OWASP |
| SSLMate certspotter | Certificate-transparency subdomain enumeration (--ct) | SSLMate |
| Variable | Purpose | Used by |
|---|---|---|
| RISKX_DATA | Default evidence store path (--data override) | all analysis commands |
| RISKX_API_KEY | API key for riskx serve (--key override) | serve |
| RISKX_LLM_API_KEY | Operator's own LLM API key (never embedded, never logged) | explain (LLM layer, off by default) |
| Model | Version | Used by |
|---|---|---|
| asset | asset-v1 | discover, assets |
| finding | finding-v1 | vuln, report, export |
| evidence | evidence-v1 | all commands |
| risk | risk-v1 | risk |
| graph | graph-v1 | attack-path, graph |
| storage | storage-v1 | --data / RISKX_DATA |
| report | report-v1 | report |
Print all versions at once with riskx version.
| Code | Meaning |
|---|---|
| 0 | No policy violation / clean |
| 1 | Policy violation detected |
| 2 | Execution error |
cmd/riskx/ CLI entry point and command tree internal/core/ config, log, errs, mode, output, idgen, runner internal/discovery/ dns, http, tls, rdap passive-discovery engines internal/vulnerability/ ingest (KEV/NVD/EPSS/OSV), normalize, findings internal/risk/ risk-v1 deterministic scoring engine internal/graph/ graph-v1 attack graph (BFS, Dijkstra, centrality) internal/policy/ YAML policy evaluation internal/reporting/ report-v1 summary + SARIF 2.1.0 / CSV / JSONL export internal/validate/ safe read-only DNS/TLS/HTTP validation internal/cloud/ cloud-v1 AWS read-only discovery (SigV4) internal/storage/ storage-v1 SQLite persistence internal/evidence/ source-metadata and confidence typing pkg/models/ canonical versioned data model pkg/plugins/ plugin interfaces and registry .github/workflows/ CI: test/build, lint, staticcheck, govulncheck
go build ./... # compile everything
go vet ./... # static analysis
go test ./... -short # unit + fixture tests (live feeds skipped)
go test ./... # includes live feed integration tests
go test ./... -race # race detector (pure-Go SQLite driver; no gcc needed)
go test -bench=. -run=^$ ./internal/risk ./internal/vulnerability/ingestMeasured on live hardware (Ubuntu 24.04, linux/amd64):
| Benchmark | Result |
|---|---|
| Risk scoring (risk-v1, 7 factors) | ~2.2 µs/op, 21 allocs |
| CISA KEV ingestion (1,666 verified rows) | ~1.8–2.0 ms, schema-validated |
| Test suite | 15/15 packages pass with race detector; vet + staticcheck clean |
RISKX is non-commercial open-source software authored by Raja Muhammad Awais.
RAJA MUHAMMAD AWAIS — Cyber Security Researcher Built with a research-first methodology: every capability grounded in verified primary sources, every output evidence-backed.
If this project helps you, star it on GitHub — and remember: scan only what you own or are authorized to test.
| Back | FazBrowse Home | New Git URL |