Automated Web Technology Fingerprinting & CVE Discovery Engine
SNARE is a high-performance reconnaissance tool built in Go, designed specifically for security researchers and bug bounty hunters. It automatically probes target domains to identify running technologies, web servers, and framework versions, then cross-references them against indexed CVE vulnerability databases to highlight potential attack surfaces.
╭──────────────────────────────────────────────────────────────────────────────────────────────────────────╮
│ TARGET: https://example-vulnerable-host.com │
├──────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Tech: OpenSSL v1.0.1e │
│ └─ [VULNERABLE] CVE-2014-0160 -> Heartbleed: Out-of-bounds read in TLS heartbeat extension leading to │
│ memory disclosure │
│ Tech: Apache HTTP Server v2.4.25 │
│ ├─ [VULNERABLE] CVE-2017-9798 -> OptionsBleed: Memory disclosure in OPTIONS HTTP method │
│ └─ [VULNERABLE] CVE-2021-41773 -> Path traversal and remote code execution in Apache 2.4.49 │
╰──────────────────────────────────────────────────────────────────────────────────────────────────────────╯
-
Smart Probe & HTTP Transport Accepts bare domain names, standard HTTP/HTTPS URLs, or IP addresses Performs automatic protocol fallback (tries HTTPS first with SSL verification disabled, falling back to HTTP if needed) Operates asynchronously using a concurrent worker pool for maximum speed
-
Technology Fingerprinting Engine Leverages projectdiscovery/wappalyzergo for high-speed pattern matching. Analyzes HTTP response headers, cookies, HTML bodies, and meta tags. Extracts exact version numbers when exposed
-
Manual Technology Queries: Accepts manual tech:version entries directly to search CVEs without sending network traffic to a host
- Go Install (Recommended)
go install github.com/t-onix/snare@latest- Build from Source
git clone https://github.com/t-onix/snare.git
cd snare
go mod tidy
go install .SNARE - Web Technology Fingerprinting & CVE Discovery Engine
Usage:
snare [flags]
Flags:
-c int
Number of concurrent workers (default 10)
-d string
Single target domain or URL
-f string
File containing list of targets
-json
Output results as structured JSON lines
-no-banner
Disable startup ASCII banner
-o string
File to save raw results
-rt int
Number of request retries for target scanning (default 3)
-t string
Manual technology & version lookup (e.g. nextjs:1.2.3 or apache:2.4.49)
-update
Update SNARE to the latest version via go install
- Single Target Scan
snare -d example.com
Or
echo target.com | snare- Multi-threaded Scan from File & Save Output
snare -f hosts -c 25 -o results- Pipeline Integration
subfinder -d target.com -silent | httprobe | snare -c 30 -o results- Manual Technology Lookup
snare -t "nextjs:1.2.3,apache:2.4.49,openssl:1.0.1f"- JSON Output Format
snare -d example.com -json | jq- JSON Output structure:
{
"target": "https://example.com",
"timestamp": "2026-07-24T15:33:50Z",
"technologies": [
{
"tech": {
"name": "apache",
"version": "2.4.49"
},
"cves": [
{
"id": "CVE-2021-41773",
"summary": "Path traversal and remote code execution in Apache 2.4.49"
}
]
}
]
}Contributions are welcome! If you find a bug or have a feature request, please open an issue or submit a pull request
