Open-source, self-hosted attack surface management. Discover, monitor and secure your internet-facing assets with AI-assisted analysis — deploy with Docker in minutes.
I've been building OASM (Open Attack Surface Management), an open-source security platform designed to help developers and security teams discover, monitor, and scan their attack surface.
I wanted to build something that gives people more control over their security tooling without requiring them to pay for an expensive SaaS platform or hand over their infrastructure data to a third party.
What is OASM?
OASM helps you manage your attack surface and run security scans from a centralized platform.
A few things I'm focusing on:
Free & open source — You can explore and use the platform without a paid subscription.
Self-hosted — Run OASM on your own infrastructure and maintain control over your data and scanning environment.
Integrations — Connect different tools and services to bring security-related information into one place.
Worker nodes — Run scans through worker nodes, with the goal of making scanning more flexible and scalable.
Centralized visibility — Manage assets and review discovered vulnerabilities from a single platform.
Why I built it
Security tools are often fragmented. You might have one tool for asset discovery, another for vulnerability scanning, and other services for managing your infrastructure or source code.
I wanted to explore whether these workflows could be brought together in a self-hostable platform that developers can customize and extend.
OASM is still an early-stage project, and I'm actively developing it. I'm especially interested in feedback from people who work with security automation, attack surface management, or self-hosted infrastructure.
Hey everyone!
I've been building OASM (Open Attack Surface Management), an open-source security platform designed to help developers and security teams discover, monitor, and scan their attack surface.
I wanted to build something that gives people more control over their security tooling without requiring them to pay for an expensive SaaS platform or hand over their infrastructure data to a third party.
What is OASM?
OASM helps you manage your attack surface and run security scans from a centralized platform.
A few things I'm focusing on:
Free & open source — You can explore and use the platform without a paid subscription.
Self-hosted — Run OASM on your own infrastructure and maintain control over your data and scanning environment.
Integrations — Connect different tools and services to bring security-related information into one place.
Worker nodes — Run scans through worker nodes, with the goal of making scanning more flexible and scalable.
Centralized visibility — Manage assets and review discovered vulnerabilities from a single platform.
Why I built it
Security tools are often fragmented. You might have one tool for asset discovery, another for vulnerability scanning, and other services for managing your infrastructure or source code.
I wanted to explore whether these workflows could be brought together in a self-hostable platform that developers can customize and extend.
OASM is still an early-stage project, and I'm actively developing it. I'm especially interested in feedback from people who work with security automation, attack surface management, or self-hosted infrastructure.
If you're interested, check it out:
Website: https://oasm.dev
Marketplace: https://oasm.dev/marketplace
I'd love to hear your thoughts:
What integrations would you want to see in a platform like this?
Would you prefer running all scanning workers yourself, or having a hybrid setup?
What features are missing from existing open-source security platforms?
Thanks for checking it out!