Repository navigation
Releases: DarkRX1/RXScan
Release list
RXScan 1.0.2
RXScan 1.0.2 is the first correctly versioned 1.x release of RXScan.
RXScan is a reconnaissance and evidence engine combining network scanning, public-source search, investigation, correlation, persistence, and explainable project intelligence.
Highlights
- Native TCP and UDP discovery and scanning
- Evidence-based service identification and fingerprinting
- OS, device, TLS, SSH, web, and software intelligence
- Public-source username search with a 100-provider corpus
- Investigation workflows with bounded public transforms
- Evidence graph and relationship correlation
- Exposure intelligence with secret-safe handling
- Persistent project history and coverage-aware diffs
- Explicit, scope-gated network pivots from investigation workflows
- Human, JSON, and JSONL output
- Deadline, cancellation, concurrency, retry, and resource-budget enforcement
- Conservative confidence and evidence semantics throughout
Safety and scope
RXScan is designed for authorized reconnaissance.
Network activity remains scope-controlled. Public-source investigation does not automatically pivot into active network scanning; network pivots require explicit enablement and scope authorization.
RXScan does not provide credential guessing, brute force, exploitation, authentication bypass, or destructive actions.
Release verification
This release passed the full formatting, compilation, Clippy, locked test-suite, diff, and search-corpus lint gates before tagging.
The installed release binary reports rxscan 1.0.2.
Version history note
Earlier v1.0.0 and v1.0.1 tags were published with package metadata that still reported 0.1.0. Those historical tags have intentionally been left unchanged.
v1.0.2 is the first 1.x tag whose committed Cargo metadata and binary version correctly report the 1.x release version.
RXScan v0.1.0-rc.1
Changelog
v0.1.0 (prerelease, unreleased)
First public prerelease candidate of RXScan, covering implementation phases
0–20 on Linux x86_64.
Capabilities. Native reconnaissance pipeline: target normalization with
deny-by-default scope; reactive scheduler with budgets, backpressure,
cancellation, and retries; host discovery (ICMP echo + TCP reachability);
TCP connect port scanning; service identification over native handshakes
(SSH/HTTP/TLS/HTTPS/FTP/SMTP/Redis/MySQL/PostgreSQL/generic, no auth);
bounded HTTP/1.1 observations with redirects and certificates; bounded
crawling of confirmed endpoints; response baselines with soft-404 handling;
managed content discovery (embedded + streaming user wordlists); safe
single-parameter GET fuzzing from observed inputs; native UDP DNS
observations; typed JSONL output; versioned checkpoints with resume;
offline scan diff with coverage-aware certainty; deterministic attention
analysis (attention is not severity); offline reports
(human/JSON/JSONL/raw); offline multi-scan project graph with bounded
queries.
Release hardening (Phase 20). Single-derivation speed governor;
fail-fast unreadable wordlists and unknown config keys; atomic scan output;
broken-pipe-safe machine output with a documented exit-code contract;
checkpoint-validity fixes so real multi-stage scans persist (typed port
assets, owned-evidence anchors, cross-task asset merges, resolvable
relationships, asymmetric crawl/content contact rule); golden schema
fixtures; release validation script and gate benchmark.
Known limitations. Linux x86_64 only; hard caps everywhere (tasks,
concurrency, hosts, evidence, registries, 8 MiB checkpoints, 16 MiB
projects); ICMP degrades without privileges; no exploit/vuln/credential/
stealth capability by design; external mid-run cancellation handle absent
(per-task timeouts and the global budget bound runs instead); project
multi-writer conflicts fail loudly rather than merging; release artifacts
are checksummed but not cryptographically signed; no crates.io publication,
man page, or shell completions yet. LICENSE file pending maintainer
confirmation (manifest declares MIT).