# Third-Party Licenses

RedAmon integrates, bundles, or dynamically invokes the following third-party open-source software. Each component is governed by its own license. **The authors of RedAmon do not own, maintain, or provide warranty for any of these tools.** This file documents all third-party components, their licenses, and where to obtain their source code.

> **AGPL-3.0 Notice**: Several tools bundled in RedAmon's Docker images are licensed under the GNU Affero General Public License v3.0. Under AGPL-3.0, the complete corresponding source code for these tools must be made available to any user who interacts with them. Source code for all AGPL-licensed components is available at their respective repositories listed below.

---

## ProjectDiscovery Tools

These tools are either installed in Docker images or pulled as Docker containers at runtime.

| Tool | Purpose | License | Source Repository | How Used |
|------|---------|---------|-------------------|----------|
| **Naabu** | Port scanning | AGPL-3.0 | https://github.com/projectdiscovery/naabu | Installed via `go install` in `mcp/kali-sandbox/Dockerfile`; also pulled as Docker image `projectdiscovery/naabu:latest` at runtime |
| **Nuclei** | Template-based vulnerability scanning (9,000+ templates) | AGPL-3.0 | https://github.com/projectdiscovery/nuclei | Installed via `go install` in `mcp/kali-sandbox/Dockerfile`; also pulled as Docker image `projectdiscovery/nuclei:latest` at runtime |
| **Nuclei Templates** | Community vulnerability detection templates | MIT | https://github.com/projectdiscovery/nuclei-templates | Downloaded via `nuclei -update-templates` in `mcp/kali-sandbox/entrypoint.sh` |
| **Katana** | Web crawling and endpoint discovery | AGPL-3.0 | https://github.com/projectdiscovery/katana | Pulled as Docker image `projectdiscovery/katana:latest` at runtime |
| **HTTPx** | HTTP probing and technology detection | AGPL-3.0 | https://github.com/projectdiscovery/httpx | Installed via `go install` in `mcp/kali-sandbox/Dockerfile`; also pulled as Docker image `projectdiscovery/httpx:latest` at runtime |
| **Subfinder** | Subdomain enumeration via passive sources | AGPL-3.0 | https://github.com/projectdiscovery/subfinder | Pulled as Docker image `projectdiscovery/subfinder:latest` at runtime |
| **DNSx** | Fast DNS toolkit (resolution, bruteforce, wildcard filtering) | AGPL-3.0 | https://github.com/projectdiscovery/dnsx | Pulled as Docker image `projectdiscovery/dnsx:latest` at runtime |
| **uncover** | Exposed-host discovery via search-engine APIs (Shodan, Censys, FOFA, Quake, Hunter, etc.) for target expansion | MIT | https://github.com/projectdiscovery/uncover | Pulled as Docker image `projectdiscovery/uncover:latest` at runtime (`recon/main_recon_modules/uncover_enrich.py`, `recon/entrypoint.sh`); provider API keys injected at call time |
| **Interactsh** | OOB (Out-of-Band) interaction gathering | MIT | https://github.com/projectdiscovery/interactsh | Installed via `go install` in `mcp/kali-sandbox/Dockerfile` |
| **vulnx** | CVE intelligence (NVD + CISA KEV + EPSS + HackerOne + GitHub PoCs + Nuclei template availability). Successor to cvemap. | MIT | https://github.com/projectdiscovery/vulnx | Installed via `go install` in `mcp/kali-sandbox/Dockerfile`. Invoked as a subprocess by the `cve_intel` agent tool ([mcp/servers/network_recon_server.py](mcp/servers/network_recon_server.py)). Optional PDCP API key (configured per-user in Global Settings) is injected at call time as `PDCP_API_KEY` env var; never logged or committed. |

---

## Exploitation & Post-Exploitation Tools

| Tool | Purpose | License | Source Repository | How Used |
|------|---------|---------|-------------------|----------|
| **Metasploit Framework** | Exploitation, post-exploitation, and payload generation | BSD-3-Clause (Rapid7) | https://github.com/rapid7/metasploit-framework | Installed via `apt-get` in `mcp/kali-sandbox/Dockerfile` |
| **Hydra** | Network login brute-force (50+ protocols) | AGPL-3.0 | https://github.com/vanhauser-thc/thc-hydra | Installed via `apt-get` in `mcp/kali-sandbox/Dockerfile` |
| **SQLMap** | Automated SQL injection detection and exploitation | GPL-2.0 | https://github.com/sqlmapproject/sqlmap | Installed via `apt-get` in `mcp/kali-sandbox/Dockerfile` |
| **John the Ripper** | Password cracking | GPL-2.0 | https://github.com/openwall/john | Installed via `apt-get` in `mcp/kali-sandbox/Dockerfile` |
| **ExploitDB** | Public exploit archive and search | GPL-2.0 | https://gitlab.com/exploit-database/exploitdb | Installed via `apt-get` in `mcp/kali-sandbox/Dockerfile` |
| **Impacket** | Python classes for working with network protocols | Apache-1.1 (modified) | https://github.com/fortra/impacket | Installed via `pip` in `mcp/requirements.txt` |
| **Pwntools** | CTF framework and exploit development library | MIT | https://github.com/Gallopsled/pwntools | Installed via `pip` in `mcp/requirements.txt` |
| **Dalfox** | XSS vulnerability scanner and parameter analysis | MIT | https://github.com/hahwul/dalfox | Installed via `go install` in `mcp/kali-sandbox/Dockerfile` |
| **kxss** | Per-character XSS reflection probe | Apache-2.0 | https://github.com/Emoe/kxss | Installed via `go install` in `mcp/kali-sandbox/Dockerfile` |
| **commix** | Automated command injection detection and exploitation | GPL-3.0 | https://github.com/commixproject/commix | Installed via `apt-get` in `mcp/kali-sandbox/Dockerfile` |
| **ysoserial** | Java deserialization gadget chain generator | MIT | https://github.com/frohoff/ysoserial | JAR downloaded from upstream releases in `mcp/kali-sandbox/Dockerfile` |
| **phpggc** | PHP gadget chain generator (unserialize / PHAR exploitation) | Apache-2.0 | https://github.com/ambionics/phpggc | Cloned from upstream in `mcp/kali-sandbox/Dockerfile` |
| **netexec** | Multi-protocol network exploitation (CrackMapExec successor) | BSD-2-Clause | https://github.com/Pennyw0rth/NetExec | Installed via `apt-get` in `mcp/kali-sandbox/Dockerfile` |
| **hashcat** | GPU-accelerated password cracking | MIT | https://github.com/hashcat/hashcat | Installed via `apt-get` in `mcp/kali-sandbox/Dockerfile` |
| **sshpass** | Non-interactive SSH password authentication | GPL-2.0 | https://sourceforge.net/projects/sshpass/ | Installed via `apt-get` in `mcp/kali-sandbox/Dockerfile` |
| **hashID** | Hash type identification (MD5, NTLM, bcrypt, etc.) | GPL-3.0 | https://github.com/psypanda/hashID | Installed via `pip` in `mcp/kali-sandbox/Dockerfile` |
| **WPScan** | WordPress vulnerability scanner | WPScan Public Source License | https://github.com/wpscanteam/wpscan | Installed via `apt-get` in `mcp/kali-sandbox/Dockerfile`. **Free for pentesting assessments and personal use; commercial use may require a separate license from https://wpscan.com.** |

---

## Active Directory & Post-Exploitation (Python)

These are AD reconnaissance and abuse primitives installed in the Kali sandbox container, used by the AD kill-chain and Windows-priv-esc Chat Skills.

| Tool | Purpose | License | Source Repository | How Used |
|------|---------|---------|-------------------|----------|
| **BloodHound (Python collector)** | Active Directory relationship collector | MIT | https://github.com/dirkjanm/BloodHound.py | Installed via `pip` in `mcp/kali-sandbox/Dockerfile` (CLI use only; no Python imports in RedAmon source) |
| **certipy-ad** | AD Certificate Services exploitation (ESC1-ESC13) | MIT | https://github.com/ly4k/Certipy | Installed via `pip` in `mcp/kali-sandbox/Dockerfile` |
| **ldapdomaindump** | LDAP enumeration (users, groups, password policies) | MIT | https://github.com/dirkjanm/ldapdomaindump | Installed via `pip` in `mcp/kali-sandbox/Dockerfile` |
| **bloodyAD** | Live AD abuse primitives (password reset, group add, SPN set) | MIT | https://github.com/CravateRouge/bloodyAD | Installed via `pip` in `mcp/kali-sandbox/Dockerfile` |
| **gMSADumper** | Read gMSA passwords (BloodHound ReadGMSAPassword edge) | GPL-3.0 | https://github.com/micahvandeusen/gMSADumper | Cloned from upstream in `mcp/kali-sandbox/Dockerfile` (separate-process invocation, mere aggregation) |
| **kerbrute** | Kerberos pre-auth user enumeration + password spraying | Apache-2.0 | https://github.com/ropnop/kerbrute | Installed via `go install` in `mcp/kali-sandbox/Dockerfile` |
| **enum4linux-ng** | SMB / Windows / AD enumeration | GPL-3.0 | https://github.com/cddmp/enum4linux-ng | Installed via `apt-get` in `mcp/kali-sandbox/Dockerfile` |
| **dnsrecon** | DNS enumeration (zone transfers, SRV, DNSSEC walk) | GPL-2.0 | https://github.com/darkoperator/dnsrecon | Installed via `apt-get` in `mcp/kali-sandbox/Dockerfile` |
| **smbclient (Samba)** | SMB client for share enumeration and access | GPL-3.0 | https://gitlab.com/samba-team/samba | Installed via `apt-get` (`samba-common-bin`) in `mcp/kali-sandbox/Dockerfile` |
| **ldap3** | Pure-Python LDAP client library | LGPL-3.0 | https://github.com/cannatag/ldap3 | Installed via `pip` in `mcp/kali-sandbox/Dockerfile` |

---

## Cloud Provider SDKs (Cloud-Attack Chat Skills)

These SDKs are installed in the Kali sandbox container and used by cloud-enumeration / cloud-attack Chat Skills for Entra ID / Azure / GCP probing.

| Library | Purpose | License | Source Repository | How Used |
|---------|---------|---------|-------------------|----------|
| **MSAL (msal)** | Microsoft Authentication Library (Entra ID token acquisition) | MIT | https://github.com/AzureAD/microsoft-authentication-library-for-python | Installed via `pip` in `mcp/kali-sandbox/Dockerfile` |
| **azure-identity** | Azure credential / token provider | MIT | https://github.com/Azure/azure-sdk-for-python | Installed via `pip` in `mcp/kali-sandbox/Dockerfile` |
| **azure-mgmt-resource** | Azure Resource Manager client | MIT | https://github.com/Azure/azure-sdk-for-python | Installed via `pip` in `mcp/kali-sandbox/Dockerfile` |
| **google-auth** | Google authentication library | Apache-2.0 | https://github.com/googleapis/google-auth-library-python | Installed via `pip` in `mcp/kali-sandbox/Dockerfile` |
| **google-api-python-client** | Google APIs client library | Apache-2.0 | https://github.com/googleapis/google-api-python-client | Installed via `pip` in `mcp/kali-sandbox/Dockerfile` |
| **google-cloud-storage** | Google Cloud Storage client | Apache-2.0 | https://github.com/googleapis/python-storage | Installed via `pip` in `mcp/kali-sandbox/Dockerfile` |

---

## Privilege Escalation Helpers (Staged Binaries)

These scripts and binaries are downloaded into `/opt/tools/{linux,windows}/` and served by the agent to a foothold host (HTTP, SMB, or upload primitive). They are **not** linked against RedAmon code; they are unmodified upstream artifacts staged for delivery.

| Tool | Purpose | License | Source Repository | How Used |
|------|---------|---------|-------------------|----------|
| **PEASS-ng (linpeas / winPEAS)** | Linux + Windows privesc auditors | GPL-2.0 | https://github.com/peass-ng/PEASS-ng | Binaries downloaded in `mcp/kali-sandbox/Dockerfile`, staged in `/opt/tools/{linux,windows}/` (unmodified upstream artifact, served to foothold hosts; not linked against RedAmon) |
| **LinEnum** | Linux enumeration helper script | MIT | https://github.com/rebootuser/LinEnum | Script downloaded in `mcp/kali-sandbox/Dockerfile`, staged in `/opt/tools/linux/` |
| **pspy** | Real-time process snooper (no root needed) | GPL-3.0 | https://github.com/DominicBreuker/pspy | Binary downloaded in `mcp/kali-sandbox/Dockerfile`, staged in `/opt/tools/linux/` (unmodified upstream artifact, served to foothold hosts; not linked against RedAmon) |
| **deepce** | Docker container escape primitive scanner | Apache-2.0 | https://github.com/stealthcopter/deepce | Script downloaded in `mcp/kali-sandbox/Dockerfile`, staged in `/opt/tools/linux/` |
| **PowerUp.ps1 (PowerSploit)** | Windows local privilege escalation toolkit | BSD-3-Clause | https://github.com/PowerShellMafia/PowerSploit | Script downloaded in `mcp/kali-sandbox/Dockerfile`, staged in `/opt/tools/windows/` |
| **PrivescCheck.ps1** | Windows privilege escalation audit script | BSD-3-Clause | https://github.com/itm4n/PrivescCheck | Script downloaded in `mcp/kali-sandbox/Dockerfile`, staged in `/opt/tools/windows/` |

---

## Network Scanning & Reconnaissance Tools

| Tool | Purpose | License | Source Repository | How Used |
|------|---------|---------|-------------------|----------|
| **Nmap** | Network scanning and service detection | NPSL (Nmap Public Source License) | https://github.com/nmap/nmap | Installed via `apt-get` in `mcp/kali-sandbox/Dockerfile` |
| **Masscan** | Asynchronous TCP port scanner | AGPL-3.0 | https://github.com/robertdavidgraham/masscan | Built from source in `recon/Dockerfile`; also installed via `apt-get` in `mcp/kali-sandbox/Dockerfile` |
| **Amass** | In-depth subdomain enumeration | Apache-2.0 | https://github.com/owasp-amass/amass | Pulled as Docker image `caffix/amass:latest` at runtime |
| **Knockpy** | Subdomain enumeration via wordlist | GPL-3.0 | https://github.com/guelfoweb/knock | Installed via `pip` in `recon/Dockerfile`. **Invoked as a CLI subprocess only** (`knockpy -d ...` in `recon/main_recon_modules/domain_recon.py`); never imported into RedAmon source, so its GPL scope does not extend to RedAmon's code (mere aggregation). |
| **puredns** | DNS wildcard filtering and resolution | GPL-3.0 | https://github.com/d3mondev/puredns | Pulled as Docker image `frost19k/puredns:latest` at runtime |
| **Hakrawler** | Web crawling and link discovery | MIT | https://github.com/hakluke/hakrawler | Pulled as Docker image `jauderho/hakrawler:latest` at runtime |
| **GAU (GetAllUrls)** | Passive URL discovery from web archives | MIT | https://github.com/lc/gau | Pulled as Docker image `sxcurity/gau:latest` at runtime |
| **Kiterunner** | API endpoint discovery | AGPL-3.0 | https://github.com/assetnote/kiterunner | Binary downloaded from GitHub releases at runtime |
| **jsluice** | JavaScript file analysis for endpoints and secrets | MIT | https://github.com/BishopFox/jsluice | Built from source via `go install` in `recon/Dockerfile` (multi-stage) |
| **ffuf** | Web fuzzer (directories, parameters, vhosts) | MIT | https://github.com/ffuf/ffuf | Built from source in `recon/Dockerfile`; also installed via `go install` in `mcp/kali-sandbox/Dockerfile` |
| **Arjun** | HTTP hidden parameter discovery | AGPL-3.0 | https://github.com/s0md3v/Arjun | Installed via `pip` in `recon/requirements.txt`. **Invoked as a CLI subprocess only** (`shutil.which('arjun')` + `subprocess(['arjun', ...])` in `recon/helpers/resource_enum/arjun_helpers.py`); never imported into RedAmon source, so its AGPL scope does not extend to RedAmon's code (mere aggregation). |
| **ParamSpider** | URL parameter mining from web archives | MIT | https://github.com/devanshbatham/ParamSpider | Installed via `pip` (git) in `recon/requirements.txt` |
| **TruffleHog** | Credential and secret scanning | AGPL-3.0 | https://github.com/trufflesecurity/trufflehog | Pulled as Docker image `trufflesecurity/trufflehog:latest` at runtime; also installed as binary in `scanners/trufflehog_scan/Dockerfile` |
| **betterleaks** | Git repository secret scanner (API keys, passwords, tokens); gitleaks successor from the same author | MIT | https://github.com/betterleaks/betterleaks | Installed via `go install` in `mcp/kali-sandbox/Dockerfile` |
| **subzy** | Subdomain takeover fingerprint scanner (90+ providers) | GPL-2.0 | https://github.com/PentestPad/subzy | Installed via `go install` in `mcp/kali-sandbox/Dockerfile` (separate-process invocation, mere aggregation) |
| **Nikto** | Web server vulnerability scanner | GPL-3.0 (database files non-GPL, distributable only with Nikto) | https://github.com/sullo/nikto | Installed via `apt-get` in `mcp/kali-sandbox/Dockerfile` |
| **WhatWeb** | Web technology fingerprinting | GPL-2.0 | https://github.com/urbanadventurer/WhatWeb | Installed via `apt-get` in `mcp/kali-sandbox/Dockerfile` |
| **testssl.sh** | SSL/TLS configuration auditing | GPL-2.0 | https://github.com/drwetter/testssl.sh | Installed via `apt-get` in `mcp/kali-sandbox/Dockerfile` |
| **CeWL** | Custom wordlist generator from target websites | CC-BY-SA-2.0 UK (with GPL-3.0+ alternative offered by upstream) | https://github.com/digininja/CeWL | Installed via `apt-get` in `mcp/kali-sandbox/Dockerfile` |
| **Subjack** | Subdomain takeover detection (CNAME/NS/MX/SPF + stale A records) | Apache-2.0 | https://github.com/haccer/subjack | Built from source via `go install` in `recon/Dockerfile` (multi-stage); invoked as native binary inside the recon container |
| **BadDNS** | Deep DNS takeover detection (CNAME/NS/MX/TXT/SPF/DMARC/MTA-STS/wildcard/NSEC/references/zonetransfer modules) | **AGPL-3.0** | https://github.com/blacklanternsecurity/baddns | **Isolated in its own Docker image `redamon-baddns:latest`** (built from `scanners/baddns_scan/Dockerfile` via `pip install baddns`). RedAmon never imports from this package. The recon container spawns the sidecar via `docker run --rm` and receives results as NDJSON on stdout. The process + filesystem boundary preserves the AGPL-3.0 license scope. Upstream source code is available at the linked repository. |

---

## Web Application & API Security Tools

| Tool | Purpose | License | Source Repository | How Used |
|------|---------|---------|-------------------|----------|
| **jwt_tool** | JWT token testing and exploitation | GPL-3.0 | https://github.com/ticarpi/jwt_tool | Installed via `pip` (git) in `mcp/kali-sandbox/Dockerfile` |
| **graphql-cop** | GraphQL security auditing | BSD-3-Clause | https://github.com/dolevf/graphql-cop | Installed via `pip` (git) in `mcp/kali-sandbox/Dockerfile` |
| **GraphQLmap** | GraphQL endpoint exploitation | MIT | https://github.com/swisskyrepo/GraphQLmap | Installed via `pip` (git) in `mcp/kali-sandbox/Dockerfile` |
| **SSTImap** | Server-Side Template Injection detection & exploitation | GPL-3.0 | https://github.com/vladko312/SSTImap | Cloned from upstream in `mcp/kali-sandbox/Dockerfile` (separate-process invocation, mere aggregation) |
| **tplmap** | SSTI scanner (Smarty / Velocity coverage) | GPL-3.0 | https://github.com/epinna/tplmap | Cloned from upstream in `mcp/kali-sandbox/Dockerfile` (isolated venv) |
| **semgrep** | Source-aware static analysis (SAST) | LGPL-2.1 | https://github.com/semgrep/semgrep | Installed via `pip` in `mcp/kali-sandbox/Dockerfile`. Used by the source-aware-sast Chat Skill on operator-provided repos. |
| **Playwright** | Browser automation (Chromium) for web recon | Apache-2.0 | https://github.com/microsoft/playwright-python | Installed via `pip` in `mcp/kali-sandbox/Dockerfile` |
| **zeep** | Python SOAP client (WS-Security / XSW probing in the SOAP Chat Skill) | MIT | https://github.com/mvantellingen/python-zeep | Installed via `pip` in `mcp/kali-sandbox/Dockerfile` |
| **python3-saml** | SAML toolkit (XSW / Comment Injection / Golden SAML construction in the SAML Chat Skill) | MIT | https://github.com/SAML-Toolkits/python3-saml | Installed via `pip` in `mcp/kali-sandbox/Dockerfile` |
| **OWASP ZAP (Zed Attack Proxy)** | Browser-driven (headless Firefox) Ajax Spider for resource enumeration of JS-heavy SPAs | Apache-2.0 | https://github.com/zaproxy/zaproxy | Pulled as Docker image `ghcr.io/zaproxy/zaproxy:stable` at runtime by the recon container (`recon/helpers/resource_enum/zap_ajax_spider_helpers.py`); run with `--net=host` via the ZAP Automation Framework. RedAmon never imports from ZAP; results are parsed from an exported artifact (process + filesystem boundary). |
| **Web Cache Vulnerability Scanner (WCVS)** | Web cache poisoning & deception scanning (header/parameter cache-key probing) for the cache-poisoning recon module | Apache-2.0 | https://github.com/Hackmanit/Web-Cache-Vulnerability-Scanner | Go binary built from source into the local image `redamon-wcvs:latest` (`scanners/wcvs/Dockerfile`); run as a separate `docker run` subprocess from the recon container (`recon/cache_scan/wcvs_runner.py`). RedAmon never links WCVS code; output is parsed from JSON (process boundary, mere aggregation). |

---

## HTTP Traffic Capture (TrafficMind)

These libraries power **TrafficMind**, RedAmon's engagement-scoped HTTP capture layer (the credential-free man-in-the-middle capture proxy and its trusted ingest worker). Both are installed into the `redamon-capture-proxy` image (`scanners/capture_proxy/Dockerfile`).

| Library | Purpose | License | Source Repository | How Used |
|---------|---------|---------|-------------------|----------|
| **mitmproxy** | Interactive TLS-capable HTTP/HTTPS intercepting proxy | MIT | https://github.com/mitmproxy/mitmproxy | Installed via `pip` (`mitmproxy~=11.1`) in `scanners/capture_proxy/Dockerfile`; run as `mitmdump -s capture_addon.py` on the target-facing network to intercept and record HTTP transactions |
| **psycopg (psycopg[binary])** | PostgreSQL adapter for Python | LGPL-3.0 | https://github.com/psycopg/psycopg | Installed via `pip` (`psycopg[binary]~=3.2`) in `scanners/capture_proxy/Dockerfile`; used only by the trusted ingest worker (`scanners/capture_proxy/ingest_worker.py`) to INSERT captured transactions via a scoped, insert-only database role |

---

## Supply-Chain / Malicious-Package Detection

These tools power RedAmon's **Supply-Chain Discovery** module (malicious / vulnerable dependency detection across the three layers: L1 SBOM scan, L2 recon harvest, L3 agent tools). All are invoked as **separate processes** via `run_argv` (`shell=False` subprocess), never imported into RedAmon source, so their scope does not extend to RedAmon's MIT code (mere aggregation). All are permissively licensed and MIT-compatible.

| Tool | Purpose | License | Source Repository | How Used |
|------|---------|---------|-------------------|----------|
| **OSV-Scanner** | Offline verdict engine — flags packages as malicious (`MAL-`) or known-vulnerable (`CVE`/`GHSA`) against a local OSV database | Apache-2.0 | https://github.com/google/osv-scanner | Go binary built from source (`@v2.4.0`) in `scanners/supply_chain_analyzer/Dockerfile`, `scanners/supply_chain_scan/Dockerfile`, `recon/Dockerfile`, and `mcp/kali-sandbox/Dockerfile`; invoked as a CLI subprocess via `scanners/supply_chain_common/osv_runner.py` with `--offline` (zero network egress) |
| **GuardDog** | Behavioural malware analysis of a package (install hooks, obfuscation, exfil, typosquat) | Apache-2.0 | https://github.com/DataDog/guarddog | Installed via `pip` (`guarddog==3.0.1`) in `scanners/supply_chain_analyzer/Dockerfile`; invoked as a CLI subprocess (`guarddog <eco> scan`) via `scanners/supply_chain_common/guarddog_runner.py`, only inside the hardened DIRTY analyzer image |
| **Semgrep** | Static-analysis engine used internally by GuardDog | LGPL-2.1 | https://github.com/semgrep/semgrep | Pulled in transitively by GuardDog inside `supply_chain_analyzer`; runs as a separate process, `pip`-replaceable |
| **YARA** | Pattern-matching engine used internally by GuardDog | BSD-3-Clause | https://github.com/VirusTotal/yara | Pulled in transitively by GuardDog inside `supply_chain_analyzer` |
| **retire.js** | Black-box JS library + version harvest from target-served JavaScript (L2) | Apache-2.0 | https://github.com/RetireJS/retire.js | Installed via `npm install -g retire@5.4.3` in `scanners/supply_chain_analyzer/Dockerfile`; invoked as a CLI subprocess via `scanners/supply_chain_common/retire_runner.py` (runner wired; L2 activation is a follow-up release) |

**OSV database (data, not code).** The offline OSV vulnerability database is **downloaded at runtime** by `osv-scanner --download-offline-databases` into the `redamon-osv-db` Docker volume (`scanners/supply_chain_common/osv_db_sync.py`); it is **not** bundled in any RedAmon image and is not redistributed by RedAmon. The aggregated OSV.dev data is published under **CC-BY-4.0** (individual records carry their upstream advisory sources). See https://osv.dev.

**CycloneDX SBOM format.** RedAmon synthesizes CycloneDX-format SBOMs itself (`scanners/supply_chain_common/artifact.py::to_cyclonedx`) to feed osv-scanner; it does **not** bundle or depend on any CycloneDX library. The CycloneDX specification is an OWASP project under Apache-2.0 (https://github.com/CycloneDX). Only the open format is used.

---

## Vulnerability Assessment (GVM/OpenVAS)

| Tool | Purpose | License | Source Repository | How Used |
|------|---------|---------|-------------------|----------|
| **GVM (Greenbone Vulnerability Management)** | Network vulnerability scanning (170,000+ NVTs) | AGPL-3.0 | https://github.com/greenbone | Multiple Docker images from `registry.community.greenbone.net` in `docker-compose.yml` |
| **gvmd** | GVM management daemon | AGPL-3.0 | https://github.com/greenbone/gvmd | Docker image: `registry.community.greenbone.net/community/gvmd:stable` |
| **ospd-openvas** | OpenVAS scanner daemon | AGPL-3.0 | https://github.com/greenbone/ospd-openvas | Docker image: `registry.community.greenbone.net/community/ospd-openvas:22.7.1` |
| **pg-gvm** | GVM PostgreSQL database | AGPL-3.0 | https://github.com/greenbone/pg-gvm | Docker image: `registry.community.greenbone.net/community/pg-gvm:stable` |
| **Greenbone Redis** | GVM data store | AGPL-3.0 | https://github.com/greenbone | Docker image: `registry.community.greenbone.net/community/redis-server:stable` |
| **Greenbone Feed Data** | Vulnerability tests, SCAP, CERT, NVT data | AGPL-3.0 | https://github.com/greenbone | Docker images for `vulnerability-tests`, `notus-data`, `scap-data`, `cert-bund-data`, `dfn-cert-data`, `data-objects`, `report-formats`, `gpg-data` |
| **python-gvm** | Python API client for GVM | GPL-3.0 | https://github.com/greenbone/python-gvm | Installed via `pip` in `scanners/gvm_scan/requirements.txt` |

---

## AI Gauntlet (Offensive AI/LLM Testing)

These red-team tools power the **AI Gauntlet** (RedAmon v5.0.0), the offensive AI/LLM testing module. garak, PyRIT, and Giskard are installed in **isolated per-tool Python virtualenvs** inside the `ai_attack_surface_scan` Docker image; promptfoo is installed as a Node.js CLI. Each is invoked as a **separate subprocess** by the scan container (mere aggregation). All four are permissively licensed (Apache-2.0 / MIT). Grading is performed by a local model served via Ollama, with zero external egress.

| Tool | Purpose | License | Source Repository | How Used |
|------|---------|---------|-------------------|----------|
| **garak** | Broad LLM vulnerability scanner (40 probe families: prompt injection, jailbreaks, encoding bypass, data leakage, toxicity, and more) | Apache-2.0 | https://github.com/NVIDIA/garak | Installed via `pip` into `/opt/venv-garak` in `scanners/ai_attack_surface_scan/Dockerfile`; invoked as `python -m garak` (REST generator) subprocess |
| **PyRIT** | Bounded multi-turn LLM jailbreak / risk-identification framework (crescendo, skeleton-key, TAP, many-shot) | MIT | https://github.com/Azure/PyRIT | Installed via `pip` into `/opt/venv-pyrit`; invoked via the `pyrit_run.py` runner as a subprocess |
| **Giskard** | App-tailored LLM safety/quality scanner (prompt injection, info disclosure, hallucination, bias, sycophancy) | Apache-2.0 | https://github.com/Giskard-AI/giskard | Installed via `pip` into `/opt/venv-giskard`; invoked via the `giskard_run.py` runner as a subprocess |
| **promptfoo** | LLM red-team eval over public attack datasets, with local encoding strategies | MIT | https://github.com/promptfoo/promptfoo | Installed via `npm install -g promptfoo` in `scanners/ai_attack_surface_scan/Dockerfile`; invoked as the `promptfoo` CLI (`redteam generate` + `eval`) |
| **Ollama** | Local model runtime serving the judge/grader (zero-egress grading) | MIT | https://github.com/ollama/ollama | Pulled as Docker image `ollama/ollama:latest` on demand by `recon_orchestrator/local_llm_manager.py`; queried over the local network only |
| **LiteLLM** | Routes Giskard's judge / embedding calls to the local Ollama (`ollama/<model>`) | MIT | https://github.com/BerriAI/litellm | Pulled in transitively by Giskard in `/opt/venv-giskard`; keeps all model calls local |

### Judge model & red-team datasets (fetched at runtime)

The judge/grader model and promptfoo's dataset plugins are **downloaded at scan time** (Ollama model pull / HuggingFace), not bundled in the RedAmon image. They are not redistributed by RedAmon; each is governed by its own upstream terms.

| Resource | Purpose | License | Source | Notes |
|----------|---------|---------|--------|-------|
| **Qwen2.5-7B-Instruct** | Default local judge / grader model | Apache-2.0 | https://huggingface.co/Qwen/Qwen2.5-7B-Instruct | Pulled by Ollama as `qwen2.5:7b`; operator-configurable |
| **nomic-embed-text** | Embedding model for Giskard's detectors | Apache-2.0 | https://huggingface.co/nomic-ai/nomic-embed-text-v1.5 | Pulled by Ollama when an embedding detector runs |
| **BeaverTails** | promptfoo harmful-prompt dataset | CC-BY-NC-4.0 | https://huggingface.co/datasets/PKU-Alignment/BeaverTails | Fetched at runtime. **NonCommercial license** — review before use in a commercial engagement |
| **HarmBench** | promptfoo standardized harmful-behavior dataset | MIT | https://github.com/centerforaisafety/HarmBench | Fetched at runtime |
| **L1B3RT4S (Pliny)** | promptfoo jailbreak corpus | See repository | https://github.com/elder-plinius/L1B3RT4S | Community jailbreak corpus, fetched at runtime; consult the repository for current terms |

---

## Tunneling

| Tool | Purpose | License | Source Repository | How Used |
|------|---------|---------|-------------------|----------|
| **Ngrok** | TCP tunneling for reverse shells (optional) | Proprietary (free tier) | https://ngrok.com/ | Binary downloaded in `mcp/kali-sandbox/Dockerfile` |
| **Chisel** | Multi-port TCP tunneling | MIT | https://github.com/jpillora/chisel | Binary downloaded in `mcp/kali-sandbox/Dockerfile` |

---

## DoS / Stress Testing

| Tool | Purpose | License | Source Repository | How Used |
|------|---------|---------|-------------------|----------|
| **hping3** | Packet crafting and stress testing | GPL-2.0 | https://github.com/antirez/hping | Installed via `apt-get` in `mcp/kali-sandbox/Dockerfile` |
| **slowhttptest** | Slow HTTP attack testing | Apache-2.0 | https://github.com/shekyan/slowhttptest | Installed via `apt-get` in `mcp/kali-sandbox/Dockerfile` |

---

## Technology Fingerprinting

| Tool | Purpose | License | Source Repository | How Used |
|------|---------|---------|-------------------|----------|
| **python-Wappalyzer** | Technology detection on web targets | GPL-3.0 | https://github.com/chorsley/python-Wappalyzer | Installed via `pip` in `recon/Dockerfile` |

---

## Databases

| Tool | Purpose | License | Source Repository | How Used |
|------|---------|---------|-------------------|----------|
| **Neo4j Community** | Graph database for attack surface mapping | GPL-3.0 (Neo4j Community) | https://github.com/neo4j/neo4j | Docker image: `neo4j:5.26-community` in `docker-compose.yml` |
| **PostgreSQL** | Relational database for project settings | PostgreSQL License (BSD-like) | https://github.com/postgres/postgres | Docker image: `postgres:16-alpine` in `docker-compose.yml` |

---

## Wordlists & Data Resources

| Resource | Purpose | License | Source Repository | How Used |
|----------|---------|---------|-------------------|----------|
| **SecLists** | Security assessment wordlists (directories, passwords, payloads) | MIT | https://github.com/danielmiessler/SecLists | Downloaded in `recon/Dockerfile` for web content discovery |
| **Trickest Resolvers** | Curated DNS resolver list | MIT | https://github.com/trickest/resolvers | Downloaded at runtime in `recon/entrypoint.sh` |
| **jhaddix all.txt** | Curated subdomain bruteforce wordlist | Unspecified (public gist) | https://gist.github.com/jhaddix/86a06c5dc309d08580a018c66354a056 | Downloaded in `recon/Dockerfile` for subdomain discovery |

---

## Web Frameworks & Application Stack

These are libraries and frameworks used to build RedAmon's own web application, API servers, and agent system.

| Library | Purpose | License | Source Repository | How Used |
|---------|---------|---------|-------------------|----------|
| **Next.js** | React framework for the web dashboard | MIT | https://github.com/vercel/next.js | `webapp/package.json` |
| **React** | UI component library | MIT | https://github.com/facebook/react | `webapp/package.json` |
| **Prisma** | Database ORM and schema management | Apache-2.0 | https://github.com/prisma/prisma | `webapp/package.json` |
| **FastAPI** | Python async web framework | MIT | https://github.com/tiangolo/fastapi | `recon_orchestrator/requirements.txt`, `agentic/requirements.txt` |
| **Uvicorn** | ASGI server | BSD-3-Clause | https://github.com/encode/uvicorn | `recon_orchestrator/requirements.txt`, `agentic/requirements.txt` |
| **Pydantic** | Data validation and settings management | MIT | https://github.com/pydantic/pydantic | Multiple `requirements.txt` files |

---

## AI / Agent Framework

| Library | Purpose | License | Source Repository | How Used |
|---------|---------|---------|-------------------|----------|
| **LangChain** | LLM application framework | MIT | https://github.com/langchain-ai/langchain | `agentic/requirements.txt` |
| **LangGraph** | Multi-agent orchestration framework | MIT | https://github.com/langchain-ai/langgraph | `agentic/requirements.txt` |
| **LangChain-Anthropic** | Anthropic model integration for LangChain | MIT | https://github.com/langchain-ai/langchain | `agentic/requirements.txt` |
| **LangChain-OpenAI** | OpenAI model integration for LangChain | MIT | https://github.com/langchain-ai/langchain | `agentic/requirements.txt` |
| **LangChain-Google-GenAI** | Google Gemini model integration for LangChain | MIT | https://github.com/langchain-ai/langchain-google | `agentic/requirements.txt` |
| **LangChain-Community** | Community LangChain integrations | MIT | https://github.com/langchain-ai/langchain | `agentic/requirements.txt` |
| **LangChain-AWS** | AWS Bedrock integration for LangChain | MIT | https://github.com/langchain-ai/langchain-aws | `agentic/requirements.txt` |
| **LangChain-Neo4j** | Neo4j graph integration for LangChain | MIT | https://github.com/langchain-ai/langchain | `agentic/requirements.txt` |
| **LangChain-Tavily** | Tavily search integration for LangChain | MIT | https://github.com/langchain-ai/langchain | `agentic/requirements.txt` |
| **LangChain-MCP-Adapters** | MCP server integration for LangChain | MIT | https://github.com/langchain-ai/langchain-mcp-adapters | `agentic/requirements.txt` |
| **FastMCP** | Fast Model Context Protocol server framework | MIT | https://github.com/jlowin/fastmcp | `mcp/requirements.txt` |
| **MCP SDK** | Model Context Protocol Python SDK | MIT | https://github.com/modelcontextprotocol/python-sdk | `mcp/requirements.txt`; also `recon/requirements.txt` (AI Surface Recon MCP handshake + `tools/list`) |
| **LangGraph-Checkpoint-Postgres** | Persistent LangGraph checkpointer (Fireteam state) | MIT | https://github.com/langchain-ai/langgraph | `agentic/requirements.txt` |
| **FAISS (faiss-cpu)** | Vector similarity search for the knowledge base | MIT | https://github.com/facebookresearch/faiss | `agentic/requirements-kb.txt` (optional `--kbase` install only) |
| **sentence-transformers** | Text embedding models for the vector knowledge base | Apache-2.0 | https://github.com/UKPLab/sentence-transformers | `agentic/requirements-kb.txt` (optional `--kbase` install only) |
| **PyTorch (torch)** | Tensor / deep-learning backend (transitive dep of sentence-transformers) | BSD-3-Clause | https://github.com/pytorch/pytorch | Pulled in transitively by `sentence-transformers` (optional `--kbase` install only) |

---

## Key Python Libraries

| Library | Purpose | License | Source Repository | How Used |
|---------|---------|---------|-------------------|----------|
| **Docker SDK for Python** | Docker API client | Apache-2.0 | https://github.com/docker/docker-py | `recon_orchestrator/requirements.txt` |
| **neo4j (Python driver)** | Neo4j database driver | Apache-2.0 | https://github.com/neo4j/neo4j-python-driver | Multiple `requirements.txt` files |
| **PyGithub** | GitHub API v3 client | LGPL-3.0 | https://github.com/PyGithub/PyGithub | `recon/requirements.txt`, `scanners/github_secret_hunt/requirements.txt`, `agentic/requirements.txt` |
| **GitPython** | Git repository interaction | BSD-3-Clause | https://github.com/gitpython-developers/GitPython | `agentic/requirements.txt` |
| **Paramiko** | SSH2 protocol library | LGPL-2.1 | https://github.com/paramiko/paramiko | `mcp/requirements.txt` |
| **Boto3** | AWS SDK for Python | Apache-2.0 | https://github.com/boto/boto3 | `agentic/requirements.txt` |
| **BeautifulSoup4** | HTML/XML parsing | MIT | https://www.crummy.com/software/BeautifulSoup/ | `mcp/requirements.txt` |
| **httpx** | Async HTTP client for Python | BSD-3-Clause | https://github.com/encode/httpx | `mcp/requirements.txt`, `agentic/requirements.txt` |
| **Requests** | HTTP library for Python | Apache-2.0 | https://github.com/psf/requests | Multiple `requirements.txt` files |
| **dnspython** | DNS toolkit for Python | ISC | https://github.com/rthalley/dnspython | `recon/requirements.txt` |
| **python-whois** | WHOIS lookup library | MIT | https://github.com/richardpenman/whois | `recon/requirements.txt` |
| **xmltodict** | XML to Python dict parser | MIT | https://github.com/martinblech/xmltodict | `scanners/gvm_scan/requirements.txt` |
| **SSE-Starlette** | Server-Sent Events for Starlette/FastAPI | BSD-3-Clause | https://github.com/sysid/sse-starlette | `recon_orchestrator/requirements.txt`, `mcp/requirements.txt` |
| **websockets** | WebSocket client and server library | BSD-3-Clause | https://github.com/python-websockets/websockets | `mcp/requirements.txt`, `agentic/requirements.txt` |
| **PyYAML** | YAML parser and emitter | MIT | https://github.com/yaml/pyyaml | `mcp/requirements.txt` |
| **PyCryptodome** | Cryptographic library | BSD-2-Clause | https://github.com/Legrandin/pycryptodome | `mcp/requirements.txt` |
| **PyJWT** | JSON Web Token implementation | MIT | https://github.com/jpadilla/pyjwt | `mcp/requirements.txt` |
| **NetworkX** | Graph/network analysis library | BSD-3-Clause | https://github.com/networkx/networkx | `agentic/requirements.txt` |
| **tree-sitter** | Incremental parsing system | MIT | https://github.com/tree-sitter/tree-sitter | `agentic/requirements.txt` |
| **tree-sitter-languages** | Pre-built Tree-sitter language grammars | MIT | https://github.com/grantjenks/py-tree-sitter-languages | `agentic/requirements.txt` |
| **mmh3** | MurmurHash3 bindings (favicon hashing for AI-frontend product detection) | MIT | https://github.com/hajimes/mmh3 | `recon/requirements.txt` (used by `recon/helpers/ai_signal_catalog.py`) |
| **yara-python** | YARA bindings — static MCP tool-poisoning rules (deterministic, no LLM) in AI Surface Recon | Apache-2.0 | https://github.com/VirusTotal/yara-python | `recon/requirements.txt` (lazy-imported by `recon/main_recon_modules/ai_surface_recon.py`) |
| **prance** | OpenAPI/Swagger `$ref`-resolving parser for AI Surface Recon OpenAPI discovery | MIT | https://github.com/RonnyPfannschmidt/prance | `recon/requirements.txt` (lazy-imported) |
| **openapi-spec-validator** | OpenAPI 2.0/3.0/3.1 validation backend for prance | Apache-2.0 | https://github.com/python-openapi/openapi-spec-validator | `recon/requirements.txt` |
| **jq.py** | Python bindings for jq (Julius probe-pack `models.extract` expressions); bundles libjq | BSD-2-Clause | https://github.com/mwilliamson/jq.py | `recon/requirements.txt` (lazy-imported) |
| **markdownify** | HTML to Markdown converter (Tradecraft Lookup curated-resource crawl) | MIT | https://github.com/matthewwithanm/python-markdownify | `agentic/requirements.txt` |
| **pypdf** | Pure-Python PDF text extraction (Tradecraft Lookup) | BSD-3-Clause | https://github.com/py-pdf/pypdf | `agentic/requirements.txt` |
| **lxml** | C-backed XML/HTML parser | BSD-3-Clause | https://github.com/lxml/lxml | `agentic/requirements.txt` |
| **psycopg** | PostgreSQL adapter for Python (persistent LangGraph checkpointer) | LGPL-3.0 | https://github.com/psycopg/psycopg | `agentic/requirements.txt` |
| **OpenAI Python SDK** | OpenAI API client (vector knowledge base, provider-agnostic LLM calls) | Apache-2.0 | https://github.com/openai/openai-python | `agentic/requirements.txt` |

---

## Key Node.js Libraries

| Library | Purpose | License | Source Repository | How Used |
|---------|---------|---------|-------------------|----------|
| **neo4j-driver** | Neo4j database driver for Node.js | Apache-2.0 | https://github.com/neo4j/neo4j-javascript-driver | `webapp/package.json` |
| **@tanstack/react-query** | Async state management for React | MIT | https://github.com/TanStack/query | `webapp/package.json` |
| **@tanstack/react-table** | Headless table UI for React | MIT | https://github.com/TanStack/table | `webapp/package.json` |
| **XTerm.js** | Terminal emulator for the browser | MIT | https://github.com/xtermjs/xterm.js | `webapp/package.json` (`@xterm/xterm`, `@xterm/addon-fit`, `@xterm/addon-web-links`) |
| **Three.js** | 3D graphics library | MIT | https://github.com/mrdoob/three.js | `webapp/package.json` |
| **react-force-graph-2d/3d** | Force-directed graph visualization | MIT | https://github.com/vasturiano/react-force-graph | `webapp/package.json` |
| **Recharts** | Charting library for React | MIT | https://github.com/recharts/recharts | `webapp/package.json` |
| **react-markdown** | Markdown renderer for React | MIT | https://github.com/remarkjs/react-markdown | `webapp/package.json` |
| **react-syntax-highlighter** | Syntax highlighting for React | MIT | https://github.com/react-syntax-highlighter/react-syntax-highlighter | `webapp/package.json` |
| **remark-gfm** | GitHub Flavored Markdown plugin | MIT | https://github.com/remarkjs/remark-gfm | `webapp/package.json` |
| **Lucide React** | Icon library for React | ISC | https://github.com/lucide-icons/lucide | `webapp/package.json` |
| **React Flow (@xyflow/react)** | Node-based diagram UI (recon workflow / tool-node view) | MIT | https://github.com/xyflow/xyflow | `webapp/package.json` |
| **react-icons** | Popular icon packs as React components | MIT | https://github.com/react-icons/react-icons | `webapp/package.json` |
| **jose** | JavaScript JSON Web Token / JWE / JWS implementation | MIT | https://github.com/panva/jose | `webapp/package.json` |
| **bcryptjs** | Pure-JS bcrypt password hashing | MIT | https://github.com/dcodeIO/bcrypt.js | `webapp/package.json` |
| **Zod** | TypeScript-first schema validation | MIT | https://github.com/colinhacks/zod | `webapp/package.json` |
| **Archiver** | Streaming archive generation (ZIP) | MIT | https://github.com/archiverjs/node-archiver | `webapp/package.json` |
| **JSZip** | ZIP file creation and reading | MIT (dual-licensed MIT/GPL-3.0; used by RedAmon under MIT) | https://github.com/Stuk/jszip | `webapp/package.json` |
| **SheetJS (xlsx)** | Spreadsheet parser and writer | Apache-2.0 | https://github.com/SheetJS/sheetjs | `webapp/package.json` |
| **pdf-parse** | PDF text extraction | MIT | https://gitlab.com/nicola.zanon/pdf-parse | `webapp/package.json` |
| **Mammoth** | DOCX to HTML/Markdown converter | BSD-2-Clause | https://github.com/mwilliamson/mammoth.js | `webapp/package.json` |
| **d3-force** | Force-directed graph layout | ISC | https://github.com/d3/d3-force | `webapp/package.json` |
| **three-spritetext** | Text sprites for Three.js | MIT | https://github.com/vasturiano/three-spritetext | `webapp/package.json` |
| **TypeScript** | Typed JavaScript superset | Apache-2.0 | https://github.com/microsoft/TypeScript | `webapp/package.json` (devDependency) |
| **ESLint** | JavaScript/TypeScript linter | MIT | https://github.com/eslint/eslint | `webapp/package.json` (devDependency) |
| **Vitest** | Unit testing framework | MIT | https://github.com/vitest-dev/vitest | `webapp/package.json` (devDependency) |

---

## Guinea Pig / Vulnerable Test Applications

These are intentionally vulnerable applications included for testing purposes only.

| Application | Purpose | License | Source Repository | How Used |
|-------------|---------|---------|-------------------|----------|
| **DVWS-Node** | Damn Vulnerable Web Services (Node.js) | MIT | https://github.com/snoopysecurity/dvws-node | Cloned in `testing/guinea_pigs/dvws-node/setup.sh` |
| **Log4Shell Vulnerable App** | Log4j RCE demonstration (CVE-2021-44228) | Apache-2.0 | https://github.com/christophetd/log4shell-vulnerable-app | Docker image: `ghcr.io/christophetd/log4shell-vulnerable-app:latest` |
| **vsftpd 2.3.4** | Backdoored FTP server (CVE-2011-2523) | GPL-2.0 | N/A (pre-built image) | Docker image: `clintmint/vsftpd-2.3.4:1.0` |
| **Apache Tomcat 8.5.19** | JSP upload RCE (CVE-2017-12617) | Apache-2.0 | https://github.com/vulhub/vulhub | Docker image: `vulhub/tomcat:8.5.19` |
| **Apache httpd 2.4.49** | Path traversal RCE (CVE-2021-41773) | Apache-2.0 | https://github.com/apache/httpd | Built from source in `testing/guinea_pigs/apache_2.4.49/Dockerfile` |
| **Apache httpd 2.4.25** | Auth bypass (CVE-2017-3167) | Apache-2.0 | https://github.com/apache/httpd | Built from source in `testing/guinea_pigs/apache_2.4.25/Dockerfile` |
| **node-serialize 0.0.4** | Deserialization RCE demo | MIT | https://github.com/luin/serialize | Built from `testing/guinea_pigs/node_serialize_1.0.0/Dockerfile` |

---

## Runtime Languages & Build Tools (in Agent Container)

The agent container (`agentic/Dockerfile`) bundles multiple language runtimes for code analysis:

| Tool | Version | License | How Used |
|------|---------|---------|----------|
| **Node.js** | 20 LTS | MIT | Installed in `agentic/Dockerfile` |
| **Go** | 1.22.10 | BSD-3-Clause | Installed in `agentic/Dockerfile` |
| **Ruby** + Bundler | System | BSD-2-Clause / MIT | Installed via `apt-get` in `agentic/Dockerfile` |
| **OpenJDK** + Maven | Headless | GPL-2.0 (w/ Classpath Exception) / Apache-2.0 | Installed via `apt-get` in `agentic/Dockerfile` |
| **PHP** + Composer | CLI | PHP-3.01 / MIT | Installed via `apt-get` in `agentic/Dockerfile` |
| **.NET SDK** | 8 | MIT | Installed in `agentic/Dockerfile` |
| **ripgrep** | System | MIT / Unlicense (dual) | Installed via `apt-get` in `agentic/Dockerfile` |
| **Yarn** | Classic | BSD-2-Clause | JS package manager, `npm install -g yarn` in `agentic/Dockerfile` |
| **pnpm** | Latest | MIT | JS package manager, `npm install -g pnpm` in `agentic/Dockerfile` |
| **uv** | Latest | Apache-2.0 / MIT (dual) | Python package installer for `uvx` MCP servers, `pip install uv` in `agentic/Dockerfile` |

---

## AGPL-3.0 Source Code Availability

In compliance with the AGPL-3.0 license, the complete corresponding source code for all AGPL-licensed components is available at the repositories listed above. If you have received a RedAmon Docker image containing any of these tools and cannot access their source code at the listed repositories, please contact the maintainers at devergo.sam@gmail.com and we will provide the source code.

## License Compatibility Note

RedAmon's own source code is released under the **MIT License**.

### Separate-process tools (CLI / Docker containers)

The majority of third-party tools are invoked as **separate processes** via CLI commands, Docker containers, or network APIs. Under the GPL, AGPL, and related copyleft licenses this constitutes "mere aggregation" (GPL v3 sec. 5, AGPL v3 sec. 5) and does **not** require RedAmon's own source code to adopt a copyleft license. Any modifications made to those tools themselves must still comply with their respective licenses.

### GPL-3.0 libraries linked at the Python import level

The following GPL-3.0-licensed Python libraries are **imported directly** into RedAmon source code. Under the GPL-3.0, the resulting combined work in each container must be distributed under GPL-3.0-compatible terms:

| Library | License | Container | Source files affected |
|---------|---------|-----------|----------------------|
| **python-gvm** | GPL-3.0 | `gvm_scan` | All `.py` files in `scanners/gvm_scan/` |
| **python-Wappalyzer** | GPL-3.0 | `recon` | Files in `recon/` that import Wappalyzer |

Accordingly, **the Python source files listed above are dual-licensed MIT AND GPL-3.0**. You may use, copy, and distribute them under either license. When they are combined with the GPL-3.0 libraries they import, the combined executable is governed by the GPL-3.0.

All other RedAmon source code (the webapp, the agent, the recon orchestrator, MCP servers, shell scripts, Dockerfiles, and configuration) remains under the MIT License only.

### LGPL libraries

Several LGPL-licensed libraries (PyGithub, Paramiko, psycopg, ldap3) are used via standard Python imports or dynamic linking. The LGPL explicitly permits this without requiring the calling code to adopt LGPL or GPL terms, provided the libraries can be replaced or re-linked by the end user. Since RedAmon installs these via standard `pip` (user-replaceable), this condition is satisfied.

### AGPL network-interaction obligation

AGPL-3.0 extends the GPL-3.0 copyleft to users who interact with the software **over a network**. Several tools in RedAmon (GVM/OpenVAS, Nuclei, Naabu, Katana, HTTPx, Subfinder, DNSx, Masscan, TruffleHog, Hydra, Kiterunner, Arjun) are AGPL-3.0. RedAmon does not modify any of these tools. Their unmodified source code is available at the repositories listed in this document. If you modify any AGPL-3.0 component and make it available over a network, you must offer the corresponding source code to users of that network service.

---

*Last updated: August 2026*
