mitan: a Chinese-language penetration testing workbench distributed as a binary
密探渗透测试工具包含资产信息收集,子域名爆破,搜索语法,资产测绘(聚合测绘,FO FA,Hunter,Quake,Zoomeye,DayDayMap,censys,shodan, 零零信安),指纹识别,敏感信息采集,文件扫描、端口扫描、弱口令破解、jwt密钥爆破、Sessionkey,heapdump, 微信小程序,密码本,随机用户,社工字典,AI渗透(MCP、代码审计)等功能
At a glance
- What is it?
- A Rust and Tauri desktop tool that bundles asset mapping, fuzzing, cloud and AI modules, with the software shipped through GitHub Releases rather than as source.
- Who is it for?
- mitan is worth knowing about as an example of a project whose documentation is the product page. It bundles around fifty capabilities that would otherwise mean installing a dozen separate tools, adds project-level state so results from one engagement do not mix into another, and exposes the whole toolset as MCP tools so an agent can drive it.
- Can I use it commercially?
- Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
- Is it still maintained?
- Yes. The repository last received commits 22 days ago.
- What is it written in?
- GitHub does not report a main language for this repository.
Answers come from the project's GitHub data, last synced on September 20, 2026, and from our analysis. They are not legal advice.
Editorial analysis
A repository that contains documentation, not code
The most important thing to establish about this project is what it is. The repository tree is short: a README, an assets directory for screenshots, and two further Markdown documents. There is no source directory, no build file and no dependency manifest. The application is built with Rust and Tauri and distributed as a downloadable binary for Windows, Mac and Linux through GitHub Releases, with the README pointing there directly.
That is not a criticism, it is a fact that changes how you evaluate the tool. You cannot read the code, you cannot build it from source and you cannot contribute code. You can read the screenshots, read the FAQ, install the binary and use it, which is what the README is written for. The language metadata and licence fields in the repository are both empty, so this article makes no claim about what licence the software is distributed under.
The project describes itself as a project-level, one-stop security detection and operations tool, integrating asset mapping, intelligence gathering, vulnerability detection, cloud security, AI automation and MCP tooling across more than fifty full-chain capabilities. Its purpose is to let a security team survey assets, triage risk and close gaps as routine operations work rather than one-off engagements.
The version story runs to two generations. Version 1.0 was released in April 2024 as a JavaFX application, went through 19 updates, and the author credits more than 70 contributors with bug fixes along with three WeChat groups with over 1,300 members. Version 2.0 was planned from 2025 as a rewrite in Rust, aimed at closing gaps in features, interface and experience.
Nine groups of capability
The feature navigation is organised into nine groups, and the grouping tells you what kind of operator this is built for. Subject query covers single and batch lookups, ICP registration queries, IP attribution, search syntax and sensitive information gathering. Spatial mapping is the largest group, aggregating FO FA, Hunter, Quake, Zoomeye, DayDayMap, censys, shodan and a Chinese service called Lingling Xin'an, plus a keyword comparison table and icon hash calculation.
Fuzzing and brute forcing takes in fingerprint recognition, JSFinder for JavaScript endpoint extraction, directory scanning, subdomain brute forcing, port scanning, weak credential testing, POC scanning and generation, JWT brute forcing and Swagger enumeration. The toolbox adds Sessionkey and heapdump analysis, WeChat mini-program handling, a password dictionary, random user generation, a social engineering dictionary, antivirus identification, encoding and decoding, data processing, reverse shell and project asset sorting. Cloud security covers OSS management, cloud hosts, and specific exploitation and key checks for WeChat, DingTalk, Feishu, map services and Baidu face recognition.
Then there are three that are less common in tools of this kind: a weapon library, a proxy pool, and an AI penetration testing section covering MCP, skills, an AI assistant, automated penetration and code auditing. A site navigation page rounds it out.
The honest read on that list is that this is an aggregation tool. Most of these capabilities exist as individual open source projects, and what mitan adds is a single interface, shared project state and consistent output. That is real value for a solo tester, and it is also why the list reads the way it does.
The three features that are genuinely different
Three entries go beyond aggregation and are worth describing separately.
The first is aggregated mapping with a syntax conversion algorithm. The README states the tool can translate common search syntax for one mapping engine into the equivalent syntax for several others automatically, so one query fans out across engines instead of being hand-rewritten per engine. The stated benefit is removing conversion mistakes made by hand, and given how much the syntax differs between these services, that is a reasonable claim rather than a thin one.
The second is breakpoint resume for scanning. Fingerprint identification, JSFinder, directory scanning, subdomain brute forcing, port scanning, weak credential testing and POC scanning all gained resume support, so a long scan continues from where it stopped rather than starting over. For a full-subdomain sweep this is the difference between a usable tool and an unusable one, since a scan that dies at hour three otherwise starts at zero.
The third is heapdump analysis, which parses Java heap dump files looking for database connection strings, SQL, IP addresses and JWT tokens. That is a specific, unglamorous and frequently useful capability, aimed at the situation where you have already found a way to trigger a dump on a Java service and want to know what that service is connected to.
The MCP integration is arguably a fourth. The README states the MCP server exposes 39 tools across general functions, project context, subject queries, mapping engines, fuzzing, cloud security and other areas, and that results from agent calls are written back into the project's history so that AI-driven and human-driven work end up in one record. Note that the feature heading above it advertises 43 tools while the body text says 39, so the exact count in the current build is not settled by the README.
Project-level state as the central idea
If there is one design decision that distinguishes mitan from a folder of scripts, it is that all collected information is managed at the project level. The README's first featured item is project data management, and the reasoning is given explicitly: strict separation of data records between different projects so they cannot be confused, plus the ability to review history later and pull anything from it for follow-up work or reuse.
That sounds administrative until you have run a real engagement, where the difference between a tool that accumulates results in one flat list and one that partitions them by engagement is the difference between usable output and an afternoon spent sorting exports.
The related feature is project asset sorting, added to the toolbox in release 2.0.3, which takes a set of discovered assets and sorts them into the project's structure. Combined with the resume support and the history writes from MCP calls, the picture is of a tool that expects long-running engagements rather than one-off checks.
Release 2.0.3, published 2026-09-08, shows the kind of work this produces. Its ten entries include a fix for limited Excel export width in the POC module, two Windows border and corner resize fixes, an improvement to how many MCP tools Claude Code recognises, password-cracking queue progress and filtering improvements, adding an Oracle service to the password module, the asset sorting feature, and making the subdomain brute force port configurable. Ten items, most of them from named community contributors.
A commercial tier built on activation codes
The monetisation is unusually visible in the README, and it shapes how the tool is used. Subscription is sold as single-user VIP and team VIP. The stated purpose of the fee is to cover the token consumption of the AI modules during development and testing, and the author also mentions anniversary gifts and recognition for contributors who supply POCs and fingerprints.
There is then a detailed schedule for earning free activation codes, which is the most distinctive part of the document. Submitting a valid bug that is confirmed earns one year of VIP. Contributing substantive resources such as high-quality fingerprints, POCs or third-party API keys earns three. Publishing an introduction on a public account, in a video channel or on a blog earns twenty codes above 1,000 reads or plays and thirty above 2,000. Referring a friend who buys VIP earns six months of personal VIP per paid referral, with eight full years for a team plan referral and three for a paid knowledge-plan membership. Sponsoring a public event can also earn codes.
Two conditions are attached to the licence. VIP activation is limited to the person who activated it, and transferring or sharing it invalidates the licence. The author also reserves the right to change features, adjust licensing policy or end the service without notice.
The practical consequence is that the free tier and the paid tier are separated by an activation check rather than by a feature list, which means you cannot tell from the README what the paid tier unlocks. The FAQ mentions the About screen will prompt for automatic updates, so the licence check is at least visible in the interface rather than hidden.
Installing on each platform, and the two warnings
The FAQ section covers all three platforms, and two of its answers are worth knowing before you start.
On Windows, where support means Windows 11 or later, the FAQ anticipates antivirus false positives and suggests comparing a hash of your local installer against the one on GitHub. If they match and you are confident the file is official, the advice is to allow-list it. The second Windows point is that the application depends on WebView2 at runtime; if it is missing the installer offers to fetch it, and if that stalls you install it manually.
On macOS, the FAQ addresses the message that the app is damaged and cannot be opened, and attributes it to the binary not being code signed by Apple. The two remedies it offers are enabling third-party sources with `sudo spctl --master-disable` and deleting the quarantine attribute from the application bundle with `sudo xattr -r -d com.apple.quarantine` applied to the app path.
On Linux there are two package shapes. For the AppImage, you grant permission and run it:
chmod +x mitan_linux_aarch64.AppImage./mitan_linux_aarch64.AppImageFor the Debian package, chosen to match your architecture:
sudo dpkg -i Linux_arm64.deband then launch it by name:
mitanThe macOS advice deserves a caveat rather than an endorsement. Disabling Gatekeeper system-wide and stripping quarantine attributes are the standard workaround for an unsigned build, and they also remove protections you may want for other software. Running the tool inside a VM is the safer route if you are doing real assessment work, which is good practice for a penetration testing tool generally.
Editorial conclusion
mitan is worth knowing about as an example of a project whose documentation is the product page. It bundles around fifty capabilities that would otherwise mean installing a dozen separate tools, adds project-level state so results from one engagement do not mix into another, and exposes the whole toolset as MCP tools so an agent can drive it. The catch is equally clear from the repository: there is no source here, only Markdown, and the compiled application is fetched from Releases. Licensing is likewise unstated in the repository metadata, and the VIP activation model described in the README means the paid tier is a licence key rather than an open feature set. If you want the features, install the binary and read the disclaimer section first; if you want to audit what it does to your network, you cannot from this repository.
Frequently asked questions
Is the mitan source code available?
No. The repository contains a README, screenshot assets and two further Markdown documents, with no source directory, build file or dependency manifest. The application is built with Rust and Tauri and distributed as a Windows, Mac or Linux binary through GitHub Releases, so it can be installed and used but not built from source or audited from the repository.
What does mitan actually do?
It aggregates around fifty security testing capabilities into one desktop interface, grouped into subject lookup, spatial mapping across engines such as Hunter, Quake, Zoomeye, censys and shodan, fuzzing and brute forcing, a general toolbox, cloud security checks, a proxy pool, an AI section with MCP and code auditing, and site navigation. All results are managed per project rather than in a single flat list.
How does mitan differ from standalone tools like subfinder or nuclei?
The individual capabilities largely exist as separate open source projects. What mitan adds is one interface over them, a mapping syntax converter that translates one query across several engines, resume support for long scans, and project-level storage so results from separate engagements stay separate. The trade is that you give up the ability to read or modify any of it.
Does mitan work with AI agents through MCP?
Yes. The README describes an MCP server exposing tools across general functions, project context, subject queries, mapping engines, fuzzing, cloud security and other areas, and results from agent calls are written back into the project's history. One thing to note is that the README is inconsistent about the count, with the section heading advertising 43 tools and the body text saying 39.
How does mitan get macOS to open its unsigned app?
The FAQ attributes the damaged-app message to the binary not being signed by Apple and offers two console commands: enabling third-party sources with `sudo spctl --master-disable`, and deleting the quarantine attribute from the application bundle with `sudo xattr -r -d com.apple.quarantine`. Both also weaken macOS protections for other software, so running the tool in a virtual machine is the safer option.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/kkbo8005-mitan)