Faraday Vulnerability Manager
Aggregate and normalize scanner and pentest results so teams track and remediate vulnerabilities in one shared workspace.
- Source repo
- infobyte/faraday
- Stars
- ★ 6.8k
- Last updated
- 14d ago
- License
- GPL-3.0
- Primary language
- Python
- FA score
- 40/100 · Major gaps
At a glance
- How it runs
- Works with
- Universal · cross-platform
- Cost
- Free tier plus a paid hosted plan
- Setup effort
- Medium · a few setup steps
- You'll need
- Typical use
- Pentest teams where several operators scan in parallel and need all findings merged into one shared workspace instead of merging spreadsheets by hand.
- Not a fit if
- Solo users who want a single scanner, not a server plus database
- Environments that require a zero-dependency offline single binary
- Teams that only need one-off scan output and no shared aggregation
- Source review
- 40/100 · Major gaps 2 safety controls not found
What does this agent do, and when should you use it?
Faraday is an open-source vulnerability management platform from Infobyte, licensed GPL-3.0 and built in Latin America but used worldwide. It aggregates and normalizes output from security tools, organizes findings into a truly multiuser workspace, and exposes them through dashboards and visualizations aimed at both managers and analysts. The product consists of a server (faraday-server), a database bootstrap command (faraday-manage initdb), a web UI on port 5985, and the faraday-cli terminal client. Teams can either run scanners directly, or import previously generated artifacts, and can drive scanners remotely through the separate Faraday Agents Dispatcher. Over 80 tools are supported via plugins.
Faraday reads, aggregates and normalizes security tool output through two plugin types. Console plugins interpret the output of tools you execute, for example faraday-cli tool run "nmap www.exampledomain.com" parses the Nmap run and sends the data to a named workspace. Report plugins import previously generated artifacts such as XML or JSON, for example faraday-cli tool report burp.xml. The README states more than 80 supported tools, with the full list in the Plugin-List wiki page. Collected findings land in a multiuser workspace and can be explored through different visualizations in the web UI; faraday-cli can also fetch workspace metrics for automation. The server is bootstrapped with faraday-manage initdb and started with faraday-server, listening on 5985, where the default login is user faraday with the password produced by the installation. Remote scanner execution is provided by the Faraday Agents Dispatcher, and the API is documented separately.
- Pentest teams where several operators scan in parallel and need all findings merged into one shared workspace instead of merging spreadsheets by hand.
- DevSecOps engineers wiring Bandit, OWASP ZAP or SonarQube into GitHub, Jenkins, TravisCI or GitLab pipelines and routing results into a single tracker.
- Security managers who need dashboards and vulnerability metrics rather than raw scanner output.
- Analysts who already have a Burp XML report and want to import and explore it visually instead of reading raw text.
- Automation engineers using faraday-cli from terminal scripts or CI jobs to pull workspace metrics and trigger work.
- Teams that need remote execution: Faraday Agents Dispatcher lets the platform run scanners or tools remotely and collect the results.
How do you install or deploy this agent?
The easiest path is the official docker-compose example: download and bring it up.
wget https://raw.githubusercontent.com/infobyte/faraday/master/docker-compose.yaml
docker-compose upRunning the Docker image directly requires a PostgreSQL instance to be available first.
docker run \
-v $HOME/.faraday:/home/faraday/.faraday \
-p 5985:5985 \
-e PGSQL_USER='postgres_user' \
-e PGSQL_HOST='postgres_ip' \
-e PGSQL_PASSWD='postgres_password' \
-e PGSQL_DBNAME='postgres_db_name' \
faradaysec/faraday:latestPyPi install:
pip3 install faradaysec
faraday-manage initdb
faraday-serverBinary packages (Debian/RPM) are on the releases page:
sudo apt install faraday-server_amd64.deb
faraday-manage initdb
sudo systemctl start faraday-serverFrom source:
pip3 install virtualenv
virtualenv faraday_venv
source faraday_venv/bin/activate
git clone [email protected]:infobyte/faraday.git
pip3 install .
faraday-manage initdb
faraday-serverAfter installation, add your user to the faraday group. The README defers detailed, platform-specific instructions to the installation wiki.
How do you use this agent?
Start the server, then open the web UI and log in as faraday with the password produced during installation:
http://localhost:5985Install the CLI client:
pip3 install faraday-cliRun a tool through Faraday and push results into a workspace:
faraday-cli tool run "nmap www.exampledomain.com"Import a report you already have:
faraday-cli tool report burp.xmlWhat are this agent's strengths and limitations?
- Normalizes findings from many tools into one multiuser workspace, which is the collaboration model single-machine scanners lack.
- Two plugin paths — Console for live tool runs and Report for existing XML/JSON artifacts — cover both active and retrospective workflows.
- Multiple documented deployment paths: docker-compose, Docker, PyPi, Debian/RPM packages and source installs.
- Ships a dedicated CLI (faraday-cli) plus published API and CLI documentation, making CI/CD and automation integration straightforward.
- Faraday Agents Dispatcher adds remote scanner execution driven from the platform.
- Requires standing up a server plus PostgreSQL; initdb, database env vars and service management go well beyond a single-binary tool.
- The README pushes install detail out to external wikis and docs sites, so a fully self-contained configuration reference is not in the repo.
- The Docker route depends on an external PostgreSQL you must supply, along with its credentials and database name.
- Although the repository description mentions AI and autonomous pentesting topics, the README details only aggregation, plugins, CLI and the Agents Dispatcher, so those AI capabilities are not verifiable from this source.
- The workflow and UI are oriented to teams; solo, one-off scanning is heavyweight for this design.
How does this agent compare with similar options?
Key facts side by side with the most closely related agents.
| Agent | Source review | Form / cost | Stars | Updated | Language | Full support on |
|---|---|---|---|---|---|---|
| Faraday Vulnerability Manager This agent | 40 · Major gaps | Self-hosted serviceFreemium | ★ 6.8k | 14d ago | Python | — |
| DarkMoon Autonomous Pentesting | 48 · Major gaps | CLIFree + model costs | ★ 984 | today | Python | OpenAI API · Claude API |
| Strix AI Pentesting | 62 · Some gaps | CLIFreemium | ★ 65k | 7d ago | Python | ChatGPT · Codex · Claude Code · OpenAI API · Claude API |
| PentestCode | 55 · Major gaps | CLIFree + model costs | ★ 726 | 29d ago | TypeScript | OpenAI API · Claude API |
How does FollowAgents rate this agent?
Why each dimension lost points
Evidence is limited to README install instructions, SECURITY.md disclosure process, and dependency lists; no least-privilege design, user confirmation, data-flow description, or rollback plan is present. SECURITY.md mentions SSL for transport, a thin sensitive-data note; the dependency list pins many versions (celery==5.4.0, werkzeug==2.3.8) but shows no vulnerability scanning or mitigation, so dependency_security scores 1. least_privilege, user_confirmation, and rollback have no evidence and score 0 or 1.
Test files assert polling, debouncing, and a safety cap for finalize_report, indicating a reasonably self-consistent internal state machine (2); dependency availability is only declared in requirements with no lockfile or hash verification (1); failure messages visible to users are not evidenced in tests (1).
README covers Docker, PyPI, binary packages, and source installs plus CI/CD scenarios (2); it does not define Agent capability boundaries such as scan scope or permission scope (1); trigger conditions for when scans run are not described in-repo (1); environment fit is supported by platform-conditional dependencies (darwin vs non-darwin) (2).
README is well structured with complete install notes (2); LICENSE is the full GPL-3.0 text (3); there is no CHANGELOG file, only an external RELEASE.md link (1); no known-limitations section (0); naming stability is only visible via pyproject script entry points (1); maintenance responsibility is only implied by the SECURITY.md email (1).
README shows CLI output and dashboard screenshots, supporting output usability (2); clear marginal value as a vulnerability aggregation platform (2); cost-benefit lacks quantified evidence such as resource usage or scan duration (1).
README claims mostly point to external docs and whitepapers, limiting in-repo traceability (1); no cross-corroboration between tests and README (1); fact/inference separation is acceptable, with tests explicitly marking skip reasons (1).
- Not found in source: confirmation before actingTurn on (or add) a confirmation step before it acts, and try it in a sandbox or test environment before real data.
- Not found in source: rollback or recovery pathBack up first, or work on a git branch or snapshot, so its changes can be undone.
- No AGENTS.md or agent manifest is provided, so the Agent's permission boundaries and trigger conditions cannot be confirmed.
- The dependency list pins several versions but shows no vulnerability scanning or mitigation, posing known-vulnerability risk.
- No evidence of rollback or user-confirmation mechanisms; automated scanning may cause unintended external effects.
- README claims mostly point to external docs, limiting in-repo verifiability.
FAQ
Is Faraday free to use?
What infrastructure does it require?
Can I import reports I already generated?
faraday-cli tool report burp.xml. The README claims support for more than 80 tools, listed on the Plugin-List page.