Open-source project
TideSec/TscanPlus avatar
TideSec/TscanPlus

TscanPlus is a security workbench that grew out of a fingerprinting tool

A comprehensive network security scanning and operations tool for fast asset discovery, identification and detection, building a baseline asset inventory to help security teams reconnoiter assets and find weak points and attack surfaces.

4,411 stars250 forksUnknownLicense varies

At a glance

What is it?
A Chinese-language asset discovery and operations tool with 4,390 stars, no declared license or language, a 7000 character README, and a feature list that reads like an inventory of everything a red team team carries on a laptop.
Who is it for?
TscanPlus is best understood as a consolidation project rather than a new scanner, and its value is the joining of fingerprint results to subsequent checks rather than any single technique. If you are assessing it, the fingerprint database and the PoC corpus are the two assets that determine whether it is useful for you, and both are numbers the README states without a reproducible benchmark.
Can I use it commercially?
Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
Is it still maintained?
Yes. The repository last received commits 3 days ago.
What is it written in?
GitHub does not report a main language for this repository.

Answers come from the project's GitHub data, last synced on October 7, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The lineage explains why fingerprinting is the core

The README tells a clear origin story, and it is the most useful paragraph in the file because it explains the architecture. The author wrote a Python fingerprinting tool in 2019 called TideFinger, and with it built a free online fingerprint detection platform for the same team, which has since accumulated more than 30,000 users and runs roughly 2,000 fingerprint checks a day. In early 2023 the team built a Go version, TideFinger_Go, and gained experience in both web fingerprint and service fingerprint identification.

The next step matters more. A team member built Tscan based on Fscan, used internally, whose purpose was to collect and organize PoCs into an automated weapon library, so that fingerprint results could drive precise PoC checks. TscanPlus grew out of that: the README describes it as expanding on a foundation of fingerprints and PoCs with additional automation features.

So the design centre of the project is a join between two tables. A fingerprint database says what product answers on a host, and a PoC corpus says what to check once you know that. Almost every headline feature follows from that join: automatic annotation of more than 130 common CMS and framework targets, external integration with Nuclei, Afrog and Xray, and automatic triggering of password cracking or PoC checks when a scan matches a known service.

The README reports about 52,000 fingerprint entries and says fingerprinting 10,000 web systems takes 8 to 10 minutes. That figure comes from the project, with no reproducible measurement attached.

Two deliverables, one repository, and a distinction the README insists on

The repository holds more than the GUI application. There is a `TscanClient/` directory described in `TscanClient.md` as an independent command line version that no longer depends on a webview and can be run purely from a terminal. The 3.4.3 release notes repeat this distinction explicitly, saying TscanClient is separate from the tool's own cli mode.

That is worth pausing on, because it means two different things are being called CLI. The main application's cli mode appears to be the same engine driven without the graphical interface, while TscanClient is a distinct build. Both exist. The release notes give a download path inside the same repository tree rather than a separate release.

There is also an automation surface. Version 3.3.0, dated 2026-06-01, unified the graphical and command line versions and launched MCP support; 3.3.4 expanded MCP to three transports described as HTTP, SSE and Stdio; and 3.3.9 connected the AK management feature to MCP. A `TscanPlus-skill/` directory suggests an agent skill is bundled as well.

The tree also contains Chinese-named documents you would not find in an English-first project: a proxy pool management introduction, a bug feedback and key collection note, and a PoC submission and key collection note. Those last two indicate that some access is gated behind a key issued by the maintainers.

What the tool claims to detect, stated at a technical level

The main feature list, as the README categorizes it, covers information gathering, port probing, service identification, URL fingerprinting, PoC verification, weak credential checks, directory enumeration, UrlFinder, domain probing, network space search, and project management. The auxiliary list covers encoding and decoding, encryption and decryption, callback payloads, reverse shell generation, antivirus lookup, privilege escalation assistance, common command references, dictionary generation, Java encoding, asset sorting, host collision, 40x bypass, JWT cracking and IP geolocation.

Two of those deserve a neutral technical description rather than a retelling. Directory enumeration defaults to HEAD requests and allows custom concurrency, timeout, filtering and dictionary settings, with the DirSearch dictionary built in, the ability to import your own, and a fuzz tool to generate dictionaries. The credential side covers 48 common services with trimmed username and password dictionaries per service, aimed at internal weak credential auditing, and the listed services include SSH, RDP, SMB, MySQL, SQL Server, Oracle, MongoDB, Redis, PostgreSQL, Memcached, Elasticsearch, FTP, Telnet, WinRM, VNC, SVN, Tomcat, WebLogic, JBoss, Zookeeper, Socks5, SNMP, WMI, LDAP, SMTP, POP3, IMAP, RouterOS and WebDAV.

The coding and conversion module covers 36 types split into 8 encoding and decoding, 13 hash, 9 encryption, 3 Chinese national cryptography algorithms, 9 data formatting and 2 other. Named algorithms include AES, RSA, SM2, SM4, DES, 3DES, XOR, RC4, Rabbit, SM3, MD5, HMAC, SHA1 through SHA3 and NTLM. The proxy configuration is per module as well as global, supporting HTTP, HTTPS and SOCKS5 with authentication.

Stated plainly: this is a broad single-window inventory of common security operations tooling, and its defensible claim is breadth plus the fingerprint-to-PoC link, not depth in any one area.

Terms of use are restrictive in a way the metadata does not signal

GitHub reports no license for this repository, and no programming language either, which is worth pausing on before anything else. The absence of a license field usually means all rights reserved by default, and here the README adds explicit terms that are narrower than any standard open source grant.

The disclaimer and use permission section states that unauthorized commercial use of the tool is prohibited, and that modifying it and then using that modified version commercially without authorization is also prohibited. It states the tool is aimed only at legally authorized enterprise security work, that users should ensure their testing complies with local law and that sufficient authorization has been obtained, that illegal use is at the user's own risk with no liability accepted, and that installing or using the tool implies acceptance of these terms.

There is also a `soft/` directory in the tree, and a README section called lightweight arsenal covering directory enumeration, UrlFinder, host collision, 40x bypass, JWT decoding and cracking, IP attribution and proxy pool management. Another section is titled red team commands and covers commands, downloads, webshells, Java encoding, reverse shells and callback payloads, with counts given as 85 reverse shell commands, 26 categories of Windows internal lateral movement and persistence commands, 18 categories of Linux internal commands, 31 download commands and 21 MSF generation commands.

For an authorized internal security team these are ordinary utilities arranged in one place. For an organization that assumes a starred repository is permissively licensed and safe to build on commercially, this one is the opposite, and that is the single most important fact to establish before adoption.

The changelog is a pace-of-development signal and it is fast

The README embeds a version history that runs from 2.4 through 3.4.0, with dates attached to each entry, and it reads more like a work log than a changelog. Entries include v3.4.0 on 2026.08.06 adding unauthorized access detection to cli mode and fixing a crash in credential checking, v3.3.9 on 2026.07.27 adding more than 700 web fingerprints and connecting AK management to MCP, v3.3.4 adding the three MCP transport modes, v3.3.2 adding an unauthorized access module supporting 45 services, and v3.0.5 from 2025.10.03 fully upgrading the PoC engine and adding one-click PoC generation.

There is real inconsistency between that list and the release tags, and both are worth recording. The README's changelog stops at 3.4.0 dated 2026.08.06, but the repository has a v3.4.3 tag published 2026-09-01 and a v3.5.0 tag published 2026-09-19, and the tree contains a directory named `TscanPlus-v3.4.3/`. So the README trails the releases by roughly six weeks. Separately, the v3.5.0 release notes announce v3.5.1 while carrying the 3.5.0 tag, so the version named in the text and the version on the release disagree.

The v3.5.0 notes list the work in that release: an AI hub module integrating asset detection and vulnerability detection, Mapbox interfaces for the AK map feature, knowledge base and group interfaces for Feishu, additional CLI parameters including `-h`, `-o` and `-no`, JSON extraction in data processing, and a fix for false positives in some SQL blind injection PoCs. The v3.4.3 notes list cloud host power on, shutdown and restart operations, JWT functionality in MCP and CLI mode, a fix for a Docker Registry false positive, and a fix for MCP failing when a scan was invoked repeatedly.

Read together, this is a project shipping weekly, which is why the README and the release tags drift apart. Last push was 2026-09-19 and the project is not archived, with 23 open issues.

Why this repository is hard to evaluate from outside

Several practical obstacles sit in front of any evaluation. The README is written in Chinese, with an English version referenced through a link definition near the top, and an `README_EN.md` file present in the tree. There is no English prose on the repository page itself, so a reader who does not read Chinese depends on that second file.

The Chinese README is also one long page that stops partway through the version history, short of the sections its own table of contents promises: software usage with per-module walkthroughs, download instructions, acknowledgements and an FAQ. Those absent sections are precisely where installation, configuration and key acquisition would be documented, so the repository page describes what the tool does without describing how to run it.

The same applies to access. Two documents in the tree concern key collection, and several changelog entries mention offline key verification and key checking mechanisms, which suggests a licensed or registered component rather than a plain open build. Whether the core scanner requires a key is not stated anywhere in the README.

The comparative picture is also worth naming. Searching the project's short name surfaces other security tooling repositories rather than this one, and the related searches include TideSec-branded projects and adjacent Chinese security tools. For a tool this large, the practical evaluation path is a trial on infrastructure you are authorized to test, with the stated fingerprint and PoC counts treated as claims to check against your own target mix rather than as measured results.

Editorial conclusion

TscanPlus is best understood as a consolidation project rather than a new scanner, and its value is the joining of fingerprint results to subsequent checks rather than any single technique. If you are assessing it, the fingerprint database and the PoC corpus are the two assets that determine whether it is useful for you, and both are numbers the README states without a reproducible benchmark. One thing to settle before adopting it anywhere: the repository carries no license field, the README explicitly forbids unauthorized commercial use and forbids redistributing a modified build commercially, and the tools directory also holds material the maintainers call a lightweight arsenal. That is a narrower grant than an ordinary open source license, so read the terms rather than assuming MIT.

Frequently asked questions

What does TscanPlus do?

It is a combined asset discovery and operations tool: information gathering, port probing, service identification, URL fingerprinting, PoC verification, weak credential checks, directory enumeration, UrlFinder, domain probing, network space search and project management, plus auxiliary tooling for encoding, hashing, encryption and command generation.

Is TscanPlus open source and can I use it commercially?

GitHub reports no license for the repository, and the README states unauthorized commercial use is prohibited, including for a modified build. It also states the tool is for legally authorized enterprise security work and that using it implies accepting those terms, so read the disclaimer section before building anything on it.

What is the relationship between TscanPlus and TideFinger?

The author wrote TideFinger in Python in 2019 and built a free online fingerprint platform with it, then produced a Go version, TideFinger_Go. TscanPlus grew from a team tool called Tscan, based on Fscan, which collected PoCs into an automated library so that fingerprint results could drive targeted checks.

What is the newest TscanPlus version?

The newest release tag is v3.5.0, published 2026-09-19, whose notes announce an AI hub module integrating asset detection and vulnerability detection, and describe the release as v3.5.1. The previous tag, v3.4.3 from 2026-09-01, added cloud host power controls and JWT support in MCP and CLI mode. The README's own version list stops earlier, at v3.4.0.

Official sources

  1. Issues
  2. README
  3. Releases
  4. TideSec/TscanPlus on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/tidesec-tscanplus.svg)](https://hysenlabs.com/projects/tidesec-tscanplus)