Security Testing Tools in Strix: 9 Built-In Scanners and When to Use Each
Strix integrates nine specialized security testing tools—including Subfinder, Naabu, Nmap, SQLMap, Semgrep, Nuclei, Katana, httpx, and ffuf—into a unified agent-driven framework that executes commands via strix/tools/executor.py and registers them through strix/tools/registry.py.
The open-source usestrix/strix repository provides a modular platform for autonomous security assessments. Each security testing tool is defined as a Markdown playbook under strix/skills/tooling/ and dynamically loaded at runtime, allowing agents to chain reconnaissance, enumeration, and exploitation tasks without hard-coded dependencies.
How Strix Orchestrates Security Testing Tools
Strix does not simply wrap third-party binaries; it abstracts them into tooling skills that agents discover based on scan mode (quick, standard, or deep).
The Tool Registry
The strix/tools/registry.py module maintains a central map of available capabilities. When an agent initializes, the registry loads skill definitions from the Markdown playbooks in strix/skills/tooling/ and exposes them as callable actions.
Command Execution and Sandboxing
Actual invocation flows through strix/tools/executor.py, which runs the CLI commands defined in each playbook inside sandboxed Docker containers. The strix/tools/terminal/terminal_actions_schema.xml file defines the terminal_execute interface that agents use to trigger these commands.
Structured Output Processing
Every tool is configured to output JSON or JSONL (via flags like -oJ, -j, or --json). This standardized format allows strix/tools/reporting/reporting_actions.py to ingest findings directly, perform deduplication, and enrich CVE data without custom parsing logic.
Phase 1: Reconnaissance and Network Enumeration
Subfinder — Passive Subdomain Enumeration
When to use: Run Subfinder at the very beginning of an assessment to build a complete inventory of subdomains without sending traffic to the target.
This tool performs passive enumeration using certificate transparency logs and search engines. According to the playbook in strix/skills/tooling/subfinder.md, agents invoke it to generate a seed list for subsequent scanning.
subfinder -d example.com -all -recursive -rl 20 -timeout 30 -silent -oJ -o subfinder.jsonl
Naabu — Fast Port Scanning
When to use: Deploy Naabu immediately after identifying live hosts to quickly narrow down which ports are open before launching heavier scans.
Naabu excels at high-speed TCP SYN or connect scans. The naabu.md playbook specifies flags for rate limiting and JSONL output so the registry can pipe results directly into Nmap or Nuclei workflows.
naabu -list hosts.txt -top-ports 100 -scan-type c -Pn -rate 300 -c 25 -timeout 1000 -retries 1 -verify -silent -j -o naabu.jsonl
Nmap — Service Discovery and Version Detection
When to use: Execute Nmap after Naabu has bounded the attack surface to perform deep service fingerprinting and NSE script execution.
The nmap.md playbook configures a two-pass approach: a quick discovery scan followed by an enrichment pass. This prevents wasting time on closed ports while still capturing banner data and version strings.
nmap -n -Pn --open --top-ports 100 -T4 --max-retries 1 --host-timeout 90s -oA nmap_quick <target>
Phase 2: Web Application Mapping
Katana — Web Crawling
When to use: Run Katana once you have confirmed web services (via Nmap or httpx) to map the full attack surface including JavaScript-rendered endpoints and hidden parameters.
Defined in strix/skills/tooling/katana.md, this tool builds a structured map of the application for downstream fuzzing.
katana -u https://app.example.com -d 2 -depth 3 -timeout 20 -silent -output katana.jsonl
httpx — HTTP Probing and Banner Grabbing
When to use: Use httpx to validate that URLs discovered during subdomain enumeration or crawling are actually reachable, and to collect metadata like status codes, titles, and TLS fingerprints.
The playbook at strix/skills/tooling/httpx.md emphasizes JSON output for automated filtering of 200/403 responses before sending to ffuf or Nuclei.
httpx -l urls.txt -status-code -content-length -title -silent -json -o httpx.jsonl
Phase 3: Vulnerability Discovery
Nuclei — Template-Based Scanning
When to use: Execute Nuclei against confirmed live hosts to rapidly test for known CVEs, misconfigurations, and policy violations at high throughput.
As documented in strix/skills/tooling/nuclei.md, this tool consumes the JSONL outputs from Naabu and httpx to run targeted templates without manual configuration.
nuclei -l targets.txt -as -s critical,high -rl 50 -c 20 -bs 20 -timeout 10 -retries 1 -silent -j -o nuclei.jsonl
ffuf — Fuzzing for Hidden Resources
When to use: Deploy ffuf after Katana has mapped the surface to brute-force hidden files, directories, parameters, or authentication bypasses via dictionary attacks.
The ffuf.md playbook specifies JSON output and match filters (e.g., -mc 200,403) to ensure only relevant findings enter the reporting pipeline.
ffuf -u https://app.example.com/FUZZ -w wordlist.txt -mc 200,403 -t 100 -json -o ffuf.jsonl
Phase 4: Vulnerability Validation
SQLMap — Automated SQL Injection Testing
When to use: Invoke SQLMap only after a potential injection vector has been identified (e.g., via ffuf or Katana logs) to confirm exploitability and assess database access levels.
The sqlmap.md playbook configures batch mode and conservative risk settings to prevent destructive operations while still proving vulnerability.
sqlmap -u "https://target.tld/item?id=1" -p id --batch --level 2 --risk 1 --threads 5 --timeout 10 --random-agent
Phase 5: Static Analysis
Semgrep — SAST and Secret Detection
When to use: Run Semgrep against source code repositories during CI/CD pipelines or early assessment phases to catch insecure patterns, hardcoded secrets, and OWASP Top 10 issues before deployment.
Defined in strix/skills/tooling/semgrep.md, this tool operates on filesystem paths rather than live hosts, making it the only non-network-based scanner in the suite.
semgrep scan --config p/default --metrics=off --json --output semgrep.json --quiet /workspace
Summary
- Strix packages nine security testing tools as modular skills under
strix/skills/tooling/, each with a dedicated Markdown playbook. - The
strix/tools/registry.pymodule dynamically loads these tools, whilestrix/tools/executor.pyruns them in sandboxed containers via theterminal_executeaction defined instrix/tools/terminal/terminal_actions_schema.xml. - Subfinder and Naabu handle initial reconnaissance; Nmap performs deep enumeration.
- Katana and httpx map web applications; ffuf discovers hidden resources.
- Nuclei scans for known vulnerabilities; SQLMap validates injection flaws.
- Semgrep provides static analysis for source code.
- All tools emit JSON/JSONL for consumption by
strix/tools/reporting/reporting_actions.py, ensuring seamless data flow from discovery to final report generation.
Frequently Asked Questions
What is the complete list of security testing tools included in Strix?
Strix includes nine integrated tools: Subfinder (subdomain enumeration), Naabu (port scanning), Nmap (service discovery), Katana (web crawling), httpx (HTTP probing), ffuf (fuzzing), Nuclei (vulnerability scanning), SQLMap (SQL injection testing), and Semgrep (static code analysis). Each tool is configured via a Markdown playbook in strix/skills/tooling/.
How does Strix decide which security testing tool to run?
Agents select tools based on the current scan mode (quick, standard, or deep) and the assessment phase. The strix/tools/registry.py exposes all available skills, and the agent logic—guided by the playbooks—determines whether to run passive reconnaissance (Subfinder), fast port scanning (Naabu), or active exploitation (SQLMap).
Can I add custom security testing tools to Strix?
Yes. The modular architecture allows you to add new tooling skills by creating a Markdown playbook in strix/skills/tooling/ and updating the registration logic in strix/tools/registry.py. You do not need to modify core agent code, provided the new tool supports JSON/JSONL output for compatibility with the reporting subsystem.
How does Strix ensure safe execution of these security testing tools?
All commands are executed inside sandboxed Docker containers managed by strix/tools/executor.py, which enforces resource limits and network isolation. Additionally, tools like SQLMap run with conservative --risk and --level settings by default, and the terminal_execute schema in strix/tools/terminal/terminal_actions_schema.xml defines strict timeouts to prevent runaway processes.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →