Faraday Plugin List¶
The main purpose of Faraday is to re-use the available tools in the community to take advantage of them in a multiuser way.
You break it. We keep track of the pieces!
To maximize flexibility Faraday Plugins run only on the client, which means you can have custom, private plugins all for yourself!
There are three kinds of plugins available for Faraday; console, report and API also called online. However, these are not mutually exclusive, meaning that some tools have more than one Plugin to process their output. For example, Nmap has a Console plugin which allows you to run it directly from ZSH, but it also has a Report one, in order to import scans that were run outside of Faraday.
Console¶
Check Faraday-Cli to use this feature!
Plugins that intercept commands, fired directly when a command is detected in the console. These are transparent to you and no additional action on your part is needed.
Report¶
Use the web UI to import reports. Check this Article!
API¶
Plugin connectors or online (BeEF, Metasploit, Burp), these connect to external APIs or databases, or talk directly to Faraday's API.
Custom¶
If you think your favourite tool is missing code your own plugin or ask us to do it!
Console Plugins¶
Plugins that intercept and parse command output via Faraday CLI. 36 plugins.
| Name | ID | Command | Report |
|---|---|---|---|
| Amap Output Plugin | Amap | Yes | No |
| arp-scan network scanner | arp-scan | Yes | No |
| BeEF Online Service Plugin | Beef | Yes | No |
| brutexss | brutexss | Yes | No |
| DiG | dig | Yes | No |
| Dirb | dirb | Yes | No |
| Dirsearch (Legacy) | dirsearch | Yes | No |
| Dnsenum XML Output Plugin | Dnsenum | Yes | No |
| Dnsmap Output Plugin | Dnsmap | Yes | No |
| Dnsrecon XML Output Plugin | Dnsrecon | Yes | No |
| Dnswalk XML Output Plugin | Dnswalk | Yes | No |
| Fierce Output Plugin | Fierce | Yes | No |
| Ftp | ftp | Yes | No |
| Goohost XML Output Plugin | Goohost | Yes | No |
| hping3 | Hping3 | Yes | No |
| Hydra XML Output Plugin | Hydra | Yes | No |
| Medusa Output Plugin | Medusa | Yes | No |
| ndiff | Ndiff | Yes | No |
| netdiscover | Netdiscover | Yes | No |
| nextnet | nextnet | Yes | No |
| pasteAnalyzer JSON Output Plugin | pasteAnalyzer | Yes | No |
| PeepingTom | peepingtom | Yes | No |
| Ping | ping | Yes | No |
| propecia port scanner | propecia | Yes | No |
| rdpscan | rdpscan | Yes | No |
| Reverseraider XML Output Plugin | Reverseraider | Yes | No |
| Skipfish Output Plugin | Skipfish | Yes | No |
| sshdefaultscan | sshdefaultscan | Yes | No |
| Telnet | Telnet | Yes | No |
| Theharvester XML Output Plugin | Theharvester | Yes | No |
| Traceroute | Traceroute | Yes | No |
| Wcscan XML Output Plugin | Wcscan | Yes | No |
| Webfuzzer Output Plugin | Webfuzzer | Yes | No |
| Wfuzz Plugin | Wfuzz | Yes | No |
| Whois | whois | Yes | No |
| xsssniper | xsssniper | Yes | No |
Report Plugins¶
Plugins that import tool output files via the Faraday web UI. Supports XML, JSON, CSV, ZIP and other formats. 67 plugins.
| Name | ID | Command | Report | Format |
|---|---|---|---|---|
| Acunetix XML Output Plugin | Acunetix | No | Yes | XML |
| Acunetix360 Output Plugin | Acunetix360 | No | Yes | JSON |
| Acunetix JSON Output Plugin | Acunetix_Json | No | Yes | JSON |
| Appscan XML Plugin | Appscan | No | Yes | XML |
| Appscan CSV Output Plugin | Appscan_CSV | No | Yes | CSV |
| AppSpider XML Output Plugin | AppSpider | No | Yes | XML |
| AWS Inspector JSON Output Plugin | AWSInspector_Json | No | Yes | JSON |
| Bandit XML Output Plugin | Bandit | No | Yes | XML |
| Burp XML Output Plugin | Burp | No | Yes | XML |
| Checkmarx XML Output Plugin | Checkmarx | No | Yes | XML |
| CIS XML Output Plugin | CIS | No | Yes | XML |
| Cobalt CSV Output Plugin | Cobalt | No | Yes | CSV |
| Crowdstrike JSON Output Plugin | Crowdstrike_Json | No | Yes | JSON |
| dirsearch Plugin for JSON output | dirsearchjson | No | Yes | JSON |
| DNSX Multiline JSON Plugin | dnsx | No | Yes | JSON |
| Faraday CSV Plugin | faraday_csv | No | Yes | CSV |
| Faraday Json | Faraday_JSON | No | Yes | JSON |
| Faraday Asset CSV Importer | faradayasset_csv | No | Yes | CSV |
| Fortify XML Output Plugin | Fortify | No | Yes | FPR |
| Gitleaks | gitleaks | No | Yes | JSON |
| Core Impact XML Output Plugin | CoreImpact | No | Yes | XML |
| Invicti XML Output Plugin | Invicti | No | Yes | XML |
| Junit XML Output Plugin | Junit | No | Yes | XML |
| Kubescape Json | Kubescape_JSON | No | Yes | JSON |
| Maltego MTGX & MTGL Output Plugin | Maltego | No | Yes | ZIP |
| Microsoft Baseline Security Analyzer | MBSA | No | Yes | XML |
| Metasploit XML Output Plugin | Metasploit | No | Yes | XML |
| ncrack XML Plugin | ncrack | No | Yes | XML |
| Nessus XML Output Plugin | Nessus | No | Yes | XML |
| Nessus Sc Output Plugin | Nessus_sc | No | Yes | CSV |
| Netsparker XML Output Plugin | Netsparker | No | Yes | XML |
| NetsparkerCloud XML Output Plugin | NetsparkerCloud | No | Yes | XML |
| Nexpose XML 2.0 Report Plugin | NexposeFull | No | Yes | XML |
| Nipper XML Output Plugin | Nipper | No | Yes | XML |
| OpenScap XML Output Plugin | OpenScap | No | Yes | XML |
| Openvas XML Output Plugin | Openvas | No | Yes | XML |
| OWASP Dependency Check Plugin | owaspDependencyCheck | No | Yes | CSV |
| Pentera Json Output Plugin | Pentera_Json | No | Yes | JSON |
| Ping Castle XML Output Plugin | PingCastle | No | Yes | XML |
| Popeye JSON Output Plugin | Popeye_Json | No | Yes | JSON |
| Prowler | prowler | No | Yes | JSON |
| Prowler (Legacy) | prowler_legacy | No | Yes | JSON |
| Qualysguard XML Output Plugin | Qualysguard | No | Yes | XML |
| QualysWebapp XML Output Plugin | QualysWebapp | No | Yes | XML |
| Reconng XML Output Plugin | Reconng | No | Yes | XML |
| Retina XML Output Plugin | Retina | No | Yes | XML |
| Saint | saint | No | Yes | CSV |
| Sarif Plugin | Sarif | No | Yes | JSON |
| SecScoreCard_CSV Output Plugin | SecScoreCard_CSV | No | Yes | CSV |
| Semgrep Json | Semgrep_JSON | No | Yes | JSON |
| Snyk | Snyk | No | Yes | JSON |
| SonarQube API Plugin | sonarqubeAPI | No | Yes | JSON |
| Sourceclear | sourceclear | No | Yes | JSON |
| SSL Labs | ssllabs | No | Yes | JSON |
| Sslyze Plugin | Sslyze_XML | No | Yes | XML |
| Subfinder Plugin for JSON output | subfinderjson | No | Yes | JSON |
| Syhunt XML Plugin | Syhunt | No | Yes | XML |
| Tenable IO JSON Vuln Export Plugin | tenableio_export_json | No | Yes | JSON |
| Terraform Plugin JSON Output Plugin | TerraformPluginJson | No | Yes | JSON |
| Trivy JSON Output Plugin | Trivy_Json | No | Yes | JSON |
| Webinspect | Webinspect | No | Yes | XML |
| WhatWebPlugin | whatweb | No | Yes | JSON |
| whitesource | whitesource | No | Yes | JSON |
| Windows Defender Jsonl | WindowsDefender_JSONL | No | Yes | JSONL |
| Zap XML Output Plugin | Zap | No | Yes | XML |
| Zap Json Output Plugin | Zap_Json | No | Yes | JSON |
Deprecated:
| Name | ID | Command | Report | Notes |
|---|---|---|---|---|
| Ip360 CSV Output Plugin | Ip360 | No | No | Non-functional / legacy plugin. No command regex, no report format class. |
Dual-Mode Plugins¶
Plugins that support both console command interception and report file import. 15 plugins.
| Name | ID | Command | Report | Format |
|---|---|---|---|---|
| Arachni XML Output Plugin | Arachni | Yes | Yes | XML |
| Grype JSON Plugin | grype | Yes | Yes | JSON |
| Lynis DAT Output Plugin | Lynis | Yes | Yes | DAT |
| Naabu | naabu | Yes | Yes | JSON |
| Nikto XML Output Plugin | Nikto | Yes | Yes | XML |
| Nmap XML Output Plugin | Nmap | Yes | Yes | XML |
| Nuclei | nuclei | Yes | Yes | JSON |
| Nuclei (Legacy) | nuclei_legacy | Yes | Yes | JSON |
| Shodan | shodan | Yes | Yes | JSON |
| Sslyze Json | Sslyze_JSON | Yes | Yes | JSON |
| W3af XML Output Plugin | W3af | Yes | Yes | XML |
| Wapiti XML Output Plugin | Wapiti | Yes | Yes | XML |
| WPscan | wpscan | Yes | Yes | JSON |
| Onapsis X1 XML Output Plugin | X1 | Yes | Yes | XML |
References to the Tools¶
- Acunetix (REPORT) (XML)
- Acunetix360 (REPORT) (JSON)
- Amap (CONSOLE)
- Appscan (REPORT) (XML)
- AppSpider (REPORT) (XML)
- Arachni (REPORT, CONSOLE) (XML)
- arp-scan (CONSOLE)
- AWS Inspector (REPORT) (JSON)
- Bandit (REPORT) (XML)
- BeEF (CONSOLE)
- brutexss (CONSOLE)
- Burp Suite (REPORT) (XML)
- Checkmarx (REPORT) (XML)
- CIS Benchmark (REPORT) (XML)
- Cobalt (REPORT) (CSV)
- Core Impact (REPORT) (XML)
- CrowdStrike (REPORT) (JSON)
- DiG (CONSOLE)
- Dirb (CONSOLE)
- Dirsearch (CONSOLE, REPORT)
- Dnsenum (CONSOLE)
- Dnsmap (CONSOLE)
- Dnsrecon (CONSOLE)
- Dnswalk (CONSOLE)
- DNSX (REPORT) (JSON)
- Faraday CSV (REPORT) (CSV)
- Faraday JSON (REPORT) (JSON)
- Fierce (CONSOLE)
- Fortify (REPORT) (FPR)
- ftp (CONSOLE)
- Gitleaks (REPORT) (JSON)
- Goohost (CONSOLE)
- Grype (CONSOLE, REPORT) (JSON)
- hping3 (CONSOLE)
- Hydra (CONSOLE)
- Invicti (REPORT) (XML)
- Junit (REPORT) (XML)
- Kubescape (REPORT) (JSON)
- Lynis (CONSOLE, REPORT) (DAT)
- Maltego (REPORT) (ZIP)
- Microsoft Baseline Security Analyzer (REPORT) (XML)
- Medusa (CONSOLE)
- Metasploit (REPORT) (XML)
- Naabu (CONSOLE, REPORT) (JSON)
- Ncrack (REPORT) (XML)
- Ndiff (CONSOLE)
- Nessus (REPORT) (XML)
- Nessus SC (REPORT) (CSV)
- Netdiscover (CONSOLE)
- Netsparker (REPORT) (XML)
- NetsparkerCloud (REPORT) (XML)
- Nexpose (REPORT) (XML)
- NextNet (CONSOLE)
- Nikto (CONSOLE, REPORT) (XML)
- Nipper (REPORT) (XML)
- Nmap (CONSOLE, REPORT) (XML)
- Nuclei (CONSOLE, REPORT) (JSON)
- OpenScap (REPORT) (XML)
- Openvas (REPORT) (XML)
- OWASP Dependency Check (REPORT) (CSV)
- pasteAnalyzer (CONSOLE)
- Peeping Tom (CONSOLE)
- Pentera (REPORT) (JSON)
- Ping (CONSOLE)
- PingCastle (REPORT) (XML)
- Popeye (REPORT) (JSON)
- propecia (CONSOLE)
- Prowler (REPORT) (JSON)
- Qualysguard (REPORT) (XML)
- QualysWebApp (REPORT) (XML)
- rdpscan (CONSOLE)
- Recon-NG (REPORT) (XML)
- Retina (REPORT) (XML)
- Reverseraider (CONSOLE)
- Saint (REPORT) (CSV)
- SARIF (REPORT) (JSON)
- SecurityScorecard (REPORT) (CSV)
- Semgrep (REPORT) (JSON)
- Shodan (CONSOLE, REPORT) (JSON)
- Skipfish (CONSOLE)
- Snyk (REPORT) (JSON)
- SonarQube (REPORT) (JSON)
- SourceClear (REPORT) (JSON)
- sshdefaultscan (CONSOLE)
- SSL Labs (REPORT) (JSON)
- SSLyze (CONSOLE, REPORT) (XML, JSON)
- Subfinder (REPORT) (JSON)
- Syhunt (REPORT) (XML)
- Telnet (CONSOLE)
- Tenable IO (REPORT) (JSON)
- Terraform (REPORT) (JSON)
- theHarvester (CONSOLE)
- Traceroute (CONSOLE)
- Trivy (REPORT) (JSON)
- W3af (CONSOLE, REPORT) (XML)
- Wapiti (CONSOLE, REPORT) (XML)
- Wcscan (CONSOLE)
- Webfuzzer (CONSOLE)
- WebInspect (REPORT) (XML)
- Wfuzz (CONSOLE)
- WhatWeb (REPORT) (JSON)
- WhiteSource (REPORT) (JSON)
- Whois (CONSOLE)
- Windows Defender (REPORT) (JSONL)
- WPScan (CONSOLE, REPORT) (JSON)
- X1 / Onapsis (CONSOLE, REPORT) (XML)
- xsssniper (CONSOLE)
- Zap (REPORT) (XML, JSON)