Faraday Vulnerability Manager

Aggregate and normalize scanner and pentest results so teams track and remediate vulnerabilities in one shared workspace.

Source repo
infobyte/faraday
Stars
★ 6.8k
Last updated
14d ago
License
GPL-3.0
Primary language
Python

At a glance

How it runs
Self-hosted serviceCLIWeb app
Works with
Universal · cross-platform
Cost
Free tier plus a paid hosted plan
Setup effort
Medium · a few setup steps
You'll need
DockerDocker ComposePostgreSQLPython 3 (pip3)Shell / CLINetwork accessLocal filesystem
Typical use
Pentest teams where several operators scan in parallel and need all findings merged into one shared workspace instead of merging spreadsheets by hand.
Not a fit if
  • Solo users who want a single scanner, not a server plus database
  • Environments that require a zero-dependency offline single binary
  • Teams that only need one-off scan output and no shared aggregation

What does this agent do, and when should you use it?

Faraday is an open-source vulnerability management platform from Infobyte, licensed GPL-3.0 and built in Latin America but used worldwide. It aggregates and normalizes output from security tools, organizes findings into a truly multiuser workspace, and exposes them through dashboards and visualizations aimed at both managers and analysts. The product consists of a server (faraday-server), a database bootstrap command (faraday-manage initdb), a web UI on port 5985, and the faraday-cli terminal client. Teams can either run scanners directly, or import previously generated artifacts, and can drive scanners remotely through the separate Faraday Agents Dispatcher. Over 80 tools are supported via plugins.

Faraday reads, aggregates and normalizes security tool output through two plugin types. Console plugins interpret the output of tools you execute, for example faraday-cli tool run "nmap www.exampledomain.com" parses the Nmap run and sends the data to a named workspace. Report plugins import previously generated artifacts such as XML or JSON, for example faraday-cli tool report burp.xml. The README states more than 80 supported tools, with the full list in the Plugin-List wiki page. Collected findings land in a multiuser workspace and can be explored through different visualizations in the web UI; faraday-cli can also fetch workspace metrics for automation. The server is bootstrapped with faraday-manage initdb and started with faraday-server, listening on 5985, where the default login is user faraday with the password produced by the installation. Remote scanner execution is provided by the Faraday Agents Dispatcher, and the API is documented separately.

  1. Pentest teams where several operators scan in parallel and need all findings merged into one shared workspace instead of merging spreadsheets by hand.
  2. DevSecOps engineers wiring Bandit, OWASP ZAP or SonarQube into GitHub, Jenkins, TravisCI or GitLab pipelines and routing results into a single tracker.
  3. Security managers who need dashboards and vulnerability metrics rather than raw scanner output.
  4. Analysts who already have a Burp XML report and want to import and explore it visually instead of reading raw text.
  5. Automation engineers using faraday-cli from terminal scripts or CI jobs to pull workspace metrics and trigger work.
  6. Teams that need remote execution: Faraday Agents Dispatcher lets the platform run scanners or tools remotely and collect the results.

How do you install or deploy this agent?

The easiest path is the official docker-compose example: download and bring it up.

wget https://raw.githubusercontent.com/infobyte/faraday/master/docker-compose.yaml
docker-compose up

Running the Docker image directly requires a PostgreSQL instance to be available first.

docker run \
    -v $HOME/.faraday:/home/faraday/.faraday \
    -p 5985:5985 \
    -e PGSQL_USER='postgres_user' \
    -e PGSQL_HOST='postgres_ip' \
    -e PGSQL_PASSWD='postgres_password' \
    -e PGSQL_DBNAME='postgres_db_name' \
    faradaysec/faraday:latest

PyPi install:

pip3 install faradaysec
faraday-manage initdb
faraday-server

Binary packages (Debian/RPM) are on the releases page:

sudo apt install faraday-server_amd64.deb
faraday-manage initdb
sudo systemctl start faraday-server

From source:

pip3 install virtualenv
virtualenv faraday_venv
source faraday_venv/bin/activate
git clone [email protected]:infobyte/faraday.git
pip3 install .
faraday-manage initdb
faraday-server

After installation, add your user to the faraday group. The README defers detailed, platform-specific instructions to the installation wiki.

How do you use this agent?

Start the server, then open the web UI and log in as faraday with the password produced during installation:

http://localhost:5985

Install the CLI client:

pip3 install faraday-cli

Run a tool through Faraday and push results into a workspace:

faraday-cli tool run "nmap www.exampledomain.com"

Import a report you already have:

faraday-cli tool report burp.xml

What are this agent's strengths and limitations?

Pros
  • Normalizes findings from many tools into one multiuser workspace, which is the collaboration model single-machine scanners lack.
  • Two plugin paths — Console for live tool runs and Report for existing XML/JSON artifacts — cover both active and retrospective workflows.
  • Multiple documented deployment paths: docker-compose, Docker, PyPi, Debian/RPM packages and source installs.
  • Ships a dedicated CLI (faraday-cli) plus published API and CLI documentation, making CI/CD and automation integration straightforward.
  • Faraday Agents Dispatcher adds remote scanner execution driven from the platform.
Limitations
  • Requires standing up a server plus PostgreSQL; initdb, database env vars and service management go well beyond a single-binary tool.
  • The README pushes install detail out to external wikis and docs sites, so a fully self-contained configuration reference is not in the repo.
  • The Docker route depends on an external PostgreSQL you must supply, along with its credentials and database name.
  • Although the repository description mentions AI and autonomous pentesting topics, the README details only aggregation, plugins, CLI and the Agents Dispatcher, so those AI capabilities are not verifiable from this source.
  • The workflow and UI are oriented to teams; solo, one-off scanning is heavyweight for this design.

How does this agent compare with similar options?

Key facts side by side with the most closely related agents.

Agent Source review Form / cost Stars Updated Language Full support on
Faraday Vulnerability Manager This agent 40 · Major gaps Self-hosted serviceFreemium ★ 6.8k 14d ago Python —
DarkMoon Autonomous Pentesting 48 · Major gaps CLIFree + model costs ★ 984 today Python OpenAI API · Claude API
Strix AI Pentesting 62 · Some gaps CLIFreemium ★ 65k 7d ago Python ChatGPT · Codex · Claude Code · OpenAI API · Claude API
PentestCode 55 · Major gaps CLIFree + model costs ★ 726 29d ago TypeScript OpenAI API · Claude API

How does FollowAgents rate this agent?

FollowAgents source review · FARS-2.1
Major gaps
40/ 100 5-point scale 2.0 / 5
Trust 7/29
Reliability 6/14
Adaptability 9/18
Convention 8/18
Effectiveness 7/13
Verifiability 3/8
Why each dimension lost points
Trust7 / 29 · 1.2/5

Evidence is limited to README install instructions, SECURITY.md disclosure process, and dependency lists; no least-privilege design, user confirmation, data-flow description, or rollback plan is present. SECURITY.md mentions SSL for transport, a thin sensitive-data note; the dependency list pins many versions (celery==5.4.0, werkzeug==2.3.8) but shows no vulnerability scanning or mitigation, so dependency_security scores 1. least_privilege, user_confirmation, and rollback have no evidence and score 0 or 1.

Reliability6 / 14 · 2.1/5

Test files assert polling, debouncing, and a safety cap for finalize_report, indicating a reasonably self-consistent internal state machine (2); dependency availability is only declared in requirements with no lockfile or hash verification (1); failure messages visible to users are not evidenced in tests (1).

Adaptability9 / 18 · 2.5/5

README covers Docker, PyPI, binary packages, and source installs plus CI/CD scenarios (2); it does not define Agent capability boundaries such as scan scope or permission scope (1); trigger conditions for when scans run are not described in-repo (1); environment fit is supported by platform-conditional dependencies (darwin vs non-darwin) (2).

Convention8 / 18 · 2.2/5

README is well structured with complete install notes (2); LICENSE is the full GPL-3.0 text (3); there is no CHANGELOG file, only an external RELEASE.md link (1); no known-limitations section (0); naming stability is only visible via pyproject script entry points (1); maintenance responsibility is only implied by the SECURITY.md email (1).

Effectiveness7 / 13 · 2.7/5

README shows CLI output and dashboard screenshots, supporting output usability (2); clear marginal value as a vulnerability aggregation platform (2); cost-benefit lacks quantified evidence such as resource usage or scan duration (1).

Verifiability3 / 8 · 1.9/5

README claims mostly point to external docs and whitepapers, limiting in-repo traceability (1); no cross-corroboration between tests and README (1); fact/inference separation is acceptable, with tests explicitly marking skip reasons (1).

Risks and how to mitigate them
  • Not found in source: confirmation before actingTurn on (or add) a confirmation step before it acts, and try it in a sandbox or test environment before real data.
  • Not found in source: rollback or recovery pathBack up first, or work on a git branch or snapshot, so its changes can be undone.
  • No AGENTS.md or agent manifest is provided, so the Agent's permission boundaries and trigger conditions cannot be confirmed.
  • The dependency list pins several versions but shows no vulnerability scanning or mitigation, posing known-vulnerability risk.
  • No evidence of rollback or user-confirmation mechanisms; automated scanning may cause unintended external effects.
  • README claims mostly point to external docs, limiting in-repo verifiability.
Evidence confidence: Low Reviewed Oct 01, 2026 Reviewed revision 2ccc12a2b630
See the full review method →

FAQ

Is Faraday free to use?
The code is GPL-3.0 and can be self-hosted. The README also links a vendor cloud trial and demos at cloud.faradaysec.com, so a hosted offering exists, but pricing is not documented in the repository.
What infrastructure does it require?
PostgreSQL must be reachable. In the Docker path you pass PGSQL_USER, PGSQL_HOST, PGSQL_PASSWD and PGSQL_DBNAME as environment variables; the server listens on port 5985 by default.
Can I import reports I already generated?
Yes. Report plugins import previously generated artifacts such as XML or JSON, e.g. faraday-cli tool report burp.xml. The README claims support for more than 80 tools, listed on the Plugin-List page.
Can it run inside a CI/CD pipeline?
Yes. The project publishes whitepapers for GitHub, Jenkins, TravisCI and GitLab integrating Bandit, OWASP ZAP and SonarQube, and recommends faraday-cli for scan automation and workspace metrics.
How does remote scanner execution work?
Through the separate Faraday Agents Dispatcher project, which gives Faraday the ability to run scanners or tools remotely from the platform and retrieve the results.
View on GitHub ↗ Install ↓

Related agents