S4E just found a low-severity finding from http response time checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
S4E Labs

Open research.
Open code.

We build in the open, contribute to the ecosystem, and share what we learn so the entire security community benefits.

Open Source

Tools we built
for everyone.

S4E MCPGitHub

MCP server that brings the full S4E platform into your AI assistant. Connect Cursor, Claude Desktop, Claude Code, VS Code, or Windsurf and manage assets, launch Full/Light/Crawler scans, read findings, tune crawling, and review posture, all in natural language over HTTP. Per-user API token auth; no credentials stored on the server.

View on GitHub
Opservant SparkGitHub

Real-time security alert client. Monitors your assets continuously and fires notifications the instant a new vulnerability appears, a port opens, or a certificate expires.

View on GitHub
Opservant PlaybooksGitHub

Pre-built scan sequences for compliance, pentest, and reconnaissance. PCI-DSS, ISO 27001, full attack surface mapping. Select a goal, hit run, S4E does the rest.

View on GitHub
ShellGuardGitHub

A security layer between AI coding agents and your shell. Every command Claude Code, Cursor, or Codex suggests passes through ShellGuard first: logged, policy-checked, and blocked or allowed. Single Go binary, sub-millisecond overhead.

View on GitHub
ShellGuard for MacGitHub

Native macOS menu bar app for ShellGuard. One-click hook setup for every AI tool, live activity log, mode switching, and a policy editor, all from the menu bar. The security logic lives in the CLI; this is the GUI layer on top.

View on GitHub
Community

We give back
to the ecosystem.

Nuclei · Contributor
Nuclei
by ProjectDiscovery Top community contributor
#1daffainfo868 templates · 18,855 pts
#2pikpikcu352 templates · 11,175 pts
#3theamanrawat214 templates · 8,555 pts
#4s4e-io204 templates · 7,210 pts
View on ProjectDiscovery
Wapiti · Sponsor
Wapiti
Open source web vulnerability scanner we sponsor its development

Wapiti is one of the most capable open source web application vulnerability scanners. S4E sponsors its ongoing development to keep powerful security tooling free and accessible for everyone.

Web App ScannerPythonOpen SourceActive Sponsor
View on GitHub
Browser ExtensionFREEChrome · Firefox · Edge

Security intel,
always one tab away.

Install the S4E extension and scan from the tab you're already on. Save your session for authenticated scans, collect attack surface as you browse, and set crawl include/exclude rules without leaving the page.

Save your session and run authenticated scans
Collect attack surface as you browse
Add crawl include and exclude rules on the fly
Live findings snapshot from the toolbar
Add to Chrome it's free →
Total scan records50M+
Unique vulnerability types11,000+
Date range2022 to present
PII / raw targetsNone, fully anonymized
AccessAcademic & research orgs
Data Share

Real-world data
for researchers.

Aggregated and fully anonymized vulnerability scan data, available to academic researchers and security professionals. No PII, no raw targets pure signal for your research.

Request Access

Want to collaborate?

Reach out if you're working on security research, open source tooling, or data sharing initiatives.