VisorGraph
High-performance infrastructure mapping with native gVisor sandboxing
§ Workflow phase
- 01 hunt
- 02 analyze
- 03 enrich
- 04 report
- 05 instrument
Discovery. Finds what is exposed.
VisorGraph is a typed-provenance infrastructure mapper. 14 packages, ~6.7 MB static binary. Native gVisor sandboxing for safe probing of untrusted targets, Go Vuln DB integration, built-in Prometheus and debug endpoint probes.
What it does
- Typed-provenance graph output, every node carries the rule that produced it
- Rule-based exposure classification with confidence scoring
- Fixed-point passive saturation, then active probes gated on budget
- Sandbox-MITM detection, downgrades L7 conclusions when running inside an intercepting environment
- Prometheus and debug endpoint probes built in
- Go Vuln DB integration for CVE matching against discovered services
Why this exists
Recon outputs are often a flat list of findings stripped from their derivation. VisorGraph keeps the derivation: every finding carries the chain of probes that produced it, so you can replay the reasoning and audit it.
Source
§ Used in
Used in
SURVEYS · 06
- 01
Argo Workflows Population Survey — Cat-29 (2026-05-31)
- 02
LLM Guard survey: guardrail platforms Shodan-dark except /metrics side-channel
- 03
Cat-30: Specialty Data Layers — Population Survey
- 04
LangGraph Server Population Survey (2026-05-25)
- 05
Redis Stack / RedisInsight Population Survey (2026-05-25)
- 06
Arize AI Phoenix unauthenticated LLM-observability exposure (377-host population)
FIELD CASES · 06
- 01
Unauthenticated ML Training Server — velutina-service.ch
- 02
NCKU Edge Host: a Kubernetes Control Plane Behind a MikroTik Gateway
- 03
difinance.online — RedisInsight Credential Leak on Telegram DeFi Bot
- 04
116.202.28.181 — Pantaflow Live Transcription Server
- 05
Embedding Services Survey — Tier-2 Cloud (2026-05-21)
- 06
sub2api — Population survey: 7,720 indexed hosts, auth-on-default at scale, zero pool-leak
§ hunt layer
Same phase
- 01
aimap
nmap for AI infrastructure
- 02
JAXEN
Stateful Go recon framework with deep TLS forensics
- 03
VisorGoose
Government TLD AI discovery via CT logs, Shodan, DNS, and Ollama fingerprinting
- 04
menlohunt
GCP External Attack Surface Management with automated chain detection
- 05
recongraph
Seed-polymorphic recon engine with environmental contamination detection
- 06
VisorSD
Shodan exposure scanner + adversarial RAG security testing
- 07
VisorBishop
Cross-platform AI/LLM observability fingerprinter, 12 platforms, IP-direct-shadow probe