tblue
passive blue-team HTTP security scanner that runs locally
TLDR
SYNOPSIS
tblue -u URL [options]
DESCRIPTION
tblue is a Python scanner (PyPI package tblue) with hundreds of read-only checks: headers, CSP, cookies, TLS, secrets in JS, DNS email records, and more. Default mode is passive: CI fails the build if a default scanner sends POST or an injection payload.Findings stay on disk (`~/.tblue/scans/` plus the report you pass). Some modules query public intel (crt.sh, OSV, NVD), which discloses the domain or version to those services. Use --skip on enrichment modules for offline runs.An MCP server (`python -m tblue.mcpserver`) exposes **scan**, **listmodules, and explain_module**.
PARAMETERS
-u URL
Target. Must be a site you own or have permission to test.--probe
Enable ~12 side-effect-free probes (GraphQL introspection, CORS reflection, TLS ciphers, DNS enum).--active
Enable intrusive checks (auth attempts, password-reset posts, injection payloads, port scans). Implies --probe.-o file
HTML report path.--json / --sarif / --siem / --splunk / --sigma / --sentinel
Machine output formats.--only / --skip
Comma-separated module or category lists.--cookie / --bearer / --header / --auth
Session credentials, sent only to the target host (2.0.1+).--fail-on severity / --fail-below n
CI gates: finding severity and/or numeric score.--browser
Playwright-powered SPA/DOM checks.-d depth
Crawl depth.
CAVEATS
Unauthorized scanning is illegal. --active can lock accounts, send mail, and trip WAFs. Authenticated scans before 2.0.1 could leak credentials to third parties or follow redirects off-host; use 2.0.1+ and rotate old secrets. Findings are heuristics, not exploit proof. HTTP_PROXY/HTTPS_PROXY see request metadata.
HISTORY
MIT project by taylannuhogluofficial-png. Current release 2.0.1 on PyPI (`pip install tblue`).
