LicenseApache License 2.0
Programming languageGolang
AuthorDavid Adrian
Latest release0.0.1 []

ZGrab is a stateful application-layer scanner. It works together with ZMap and is also part of the ZMap project. ZGrab is written in Go and supports multiple protocols, including:

  • HTTP
  • FTP
  • IMAP
  • POP3
  • Modbus
  • Siemens S7
  • SMTP
  • SSH
  • Telnet
  • Tridium Fox

Why this tool?

This tool can be used to grab banner of services, including those using SSL/TLS. Such usage can be useful for security assessments or find out what particular service is running on an internal system.

Usage and audience

ZGrab is commonly used for penetration testing, security assessment, or vulnerability scanning. Target users for this tool are pentesters.

Author and Maintainers

ZGrab is under development by David Adrian.

Certificate Transparency

Google's Certificate Transparency project audits the way SSL/TLS certificates are used and its underlying cryptographic system.



Cipherscan is a tool to test the ordering of SSL/TLS ciphers on a given target. It tests the major versions of SSL, TLS, and any extensions of these protocols.

