Skip to content
crypt0rrPublic

About

(Continuously) scans your internet facing infrastructure to discover exposed ports and services, helping you identify changes and reduce your external attack surface.

Topics

Resources

Security policy

Stars

5 stars

Watchers

0 watching

Forks

Latest commit

 

History

530 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

EdgeWatch

CI CodeQL Latest release Container Go version License

EdgeWatch is a self-hosted network-surface monitor. It schedules TCP and UDP scans, learns what is expected, and notifies you when the observed surface changes. It ships as one Docker image with an embedded web console and SQLite storage.

EdgeWatch.mp4

Only scan systems you own or are authorized to assess. Full-range UDP scans can take many hours and generate significant traffic.

Quick start

Requirements: Docker Engine 25 or later and Docker Compose v2 on a host supporting host networking and scanner capabilities. From a checkout of this repository:

cp config.example.yaml config.yaml

Create the data directory for your Docker mode. For standard rootful Docker:

sudo install -d -m 0750 -o 0 -g 0 ./data

For rootless Docker:

install -d -m 0750 ./data

With user-namespace remapping, use the host UID mapped to container UID 0. The container runs as UID 0 with filesystem capabilities dropped; keep data owned by that mapped identity and do not use world-writable permissions. For an existing deployment, read the installation and backup guides before changing ownership, mounts, or images.

docker compose pull
docker compose up -d
docker compose logs edgewatch | grep setup_token

Open http://127.0.0.1:8080 and create the first administrator with the one-time setup token, which expires after 15 minutes. The listener is loopback-only. For a remote host, tunnel from your workstation:

ssh -L 8080:127.0.0.1:8080 user@docker-host

Then add notification destinations and create your first monitoring job in the console. Runtime state and generated encryption keys live in ./data; back them up together.

Documentation

The full user, operator, and maintainer documentation is available at edgewatch.offsec.nl. The website source lives in docs/.

Report vulnerabilities privately as described in SECURITY.md.

License

Copyright (c) 2026 Bart. Released under AGPL-3.0-only; bundled components retain their separate licenses in THIRD_PARTY_LICENSES.md. Releases before v0.25.0 retain their published MIT terms. See the license and source-code guide for the source link requirements when deploying a modified build.

About

(Continuously) scans your internet facing infrastructure to discover exposed ports and services, helping you identify changes and reduce your external attack surface.

Topics

Resources

Security policy

Stars

5 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages