
faraday is an open source vulnerability management platform that aggregates, normalizes, and tracks scanner output from dozens of tools, built for authorized pentest teams and security programs.
| Tool | infobyte/faraday — open source, multiuser vulnerability management platform written in Python |
| Category | Vulnerability management / findings aggregation and orchestration |
| Primary Use | Centralizing and normalizing output from tools like nmap, Nessus, and Burp Suite into shared workspaces for authorized assessments |
| Safe Use | Intended for penetration testers, security auditors, and defensive teams working within explicitly authorized engagements, internal labs, and remediation tracking programs |
| Telemetry Note | As a management layer it generates no scanning traffic itself; its Postgres database and API logs record all ingested findings, giving defenders a full audit trail of assessment activity |
faraday, maintained by infobyte and written in Python under GPL-3.0, attacks a problem every consulting and internal security team knows intimately: the findings pile up faster than they can be organized. The README frames security as two difficult tasks — discovering information and keeping track of it — and positions faraday as the answer to the second. Rather than being yet another scanner, it is a vulnerability management platform that sits above the tools you already run, aggregating and normalizing their output into a multiuser workspace where analysts and managers can explore it through different visualizations. With roughly 6748 stars and a topic list spanning penetration-testing, devsecops, and vulnerability-management, it is one of the more mature open source entries in this space.
The architecture that emerges from the README is client-server. A faraday-server process fronts the persistence layer, backed by Postgres, and exposes both a web UI on port 5985 and a documented REST API. This separation matters operationally: consultants can run scanners in the field, ship results to a central server, and have the whole team work against the same normalized dataset. The multiuser emphasis is explicit in the README's framing — faraday was built to take advantage of community tools "in a truly multiuser way", which distinguishes it from single-analyst note-taking tools.
Ingestion is where faraday earns its keep. The plugin system, hosted in the separate faraday_plugins repository, supports more than 80+ tools including the heavy hitters referenced in the repo topics: nmap, Nessus, and Burp Suite. The README distinguishes two plugin types, and the split is architecturally significant. Console plugins interpret the live output of tools you execute, so you can run a command and watch the parsed results flow into a workspace in real time. Report plugins instead import previously generated artifacts — XML and JSON files — which is the natural fit for importing third-party scan deliverables or replaying output produced offline.
The companion faraday-cli client is what turns the platform from a web dashboard into something an operator can script. Installed via pip3 install faraday-cli, it provides terminal access to workspaces, metrics, and the tool-running machinery. The README's example shows the ergonomics: faraday-cli tool run "nmap ..." wraps the scan, parses the output, and pushes the structured results to a workspace — the console shows the familiar nmap output followed by confirmation that data was sent. For importing artifacts, faraday-cli tool report burp.xml does the same for a saved Burp export. This is deliberately automation-friendly, and the docs position faraday-cli as the hook for CI/CD integration.
That pipeline story is a major theme. The README links whitepapers covering integration with GitHub, Jenkins, TravisCI, and Gitlab, wiring scanners like Bandit, OWASP ZAP, and SonarQube into continuous delivery so findings land in faraday automatically. For a DevSecOps program, this converts the platform from a pentest notebook into a continuously updated vulnerability inventory — exactly the "continuous scanning" and "orchestration" use cases its GitHub topics advertise.
There is also a remote execution layer: Faraday Agents Dispatcher gives the platform the ability to run scanners remotely and retrieve results. This is worth noting for architecture reviews, because it means a faraday deployment can act as an orchestration hub dispatching tooling across segments — powerful in an authorized lab or enterprise assessment, and something that should sit inside a well-defined trust boundary with proper access controls on the server.
Installation is unusually well covered. The recommended quick start is docker-compose, with a docker-compose.yaml fetched from the repo and brought up with docker-compose up. A plain docker run path is documented too, requiring an external Postgres instance and passing connection details via PGSQL_USER, PGSQL_HOST, PGSQL_PASSWD, and PGSQL_DBNAME environment variables with the config volume mounted at $HOME/.faraday and port 5985 published. For those avoiding containers, pip3 install faradaysec followed by faraday-manage initdb and faraday-server gets a server running, and Debian/RPM packages are available on the releases page with a systemd service. Source installs via virtualenv are documented as well.
Once running, the web interface is reachable at hxxp://localhost:5985, with initial credentials using faraday as the username and a password supplied by the installer. The faraday-manage utility is the operational Swiss army knife for database initialization, and the README notes that package installs require adding your user to the faraday group — a small but telling detail about how the Debian packaging handles permissions on shared resources.
From a defensive perspective, faraday is a remediation-tracking instrument as much as an assessment tool. The README pitches its visualizations as useful to "managers and analysts alike", and the dashboards shown in the docs support triage and trend-watching across workspaces. Because everything is normalized into a Postgres-backed data model reachable through a documented API, blue teams can pull structured vulnerability data into ticketing systems or risk registers instead of juggling per-scanner report formats.
Custom integrations are first-class. The plugin repository accepts pull requests, and the README claims creating custom plugins is straightforward — meaning an organization with an in-house scanner or an unusual tool can teach faraday to parse its output without forking the server. Combined with the direct API access documented at api.faradaysec.com, the platform is designed to be extended rather than worked around.
Maturity signals are solid: a RELEASE.md changelog, a hosted documentation site, an active issue tracker, Discord community channels, and a commercial arm (faradaysec.com) offering cloud trials — a common and generally healthy open-core pattern where the GPL-licensed server remains freely deployable. Anyone evaluating it should still do the usual diligence on the plugin supply chain, since third-party parsers execute in the context of your management server.
For authorized professionals, faraday fits a clear niche: it is the connective tissue between discovery and remediation. Pentest teams get shared workspaces and consistent reporting; DevSecOps teams get continuous ingestion from pipeline scanners; and defenders get a normalized, queryable record of what was found, when, and whether it was fixed. It is not a scanner itself, and that is precisely the point — it makes the eighty-plus scanners you already trust work together.
infobyte/faraday.Educational analysis for authorized security professionals. Use only in controlled, authorized environments.
Related coverage
0 comentários:
Post a Comment
Note: Only a member of this blog may post a comment.