Cerberus, a three-headed hound, emerging from a cave
Free. Open source. Self-hosted.
Get Cerberus
Four heads. One gate.

Nothing gets past Cerberus.

Run Cerberus on your own machine with Docker. Local users, run history, PDF-ready reports, and encrypted model credentials stay under your control. Passive checks are the safe default; authorized active tools are an explicit opt-in.

I · EXPOSURE

The Surface

The first head watches what the world can see. Leaked API keys, missing security headers, exposed config files, open directories. The low-hanging fruit an attacker grabs in the first thirty seconds.

II · DNS & EXPOSURE

The Nose

The second head checks DNS, public metadata, exposed files, security headers, and other signals that reveal too much to an attacker.

III · VITALITY

The Health

The third head guards your vitals. Speed, build quality, and the technical rot that quietly bleeds customers and rankings even when no one is attacking you at all.

IV · ACTIVE TESTING

The Hunt

The fourth head runs explicitly authorized Nuclei, OWASP ZAP, and conservative sqlmap checks from isolated workers. It stays disabled until the owner opts in.

Why it matters
One leak of customer data can cost you $100 to $750 per record.

Cerberus gives self-hosters a plain-English, prioritized view of public exposure, configuration problems, and performance issues. It is a diagnostic—not a penetration-test authorization slip or a promise that a site is secure.

Local firstScan history stays in the Docker volume you control.
Safe defaultActive tools require opt-in and per-run authorization.
Plain EnglishEvery finding ranked by severity, with what the test observed and why it matters.
Run it yourself

One repo. One setup command.

Clone the public repository and let the setup script generate secrets, pull the hardened stack, and wait for health. Cerberus is free software under AGPL-3.0.

1

Clone the repository from GitHub.

2

Run ./scripts/setup.sh.

3

Open the local console and create the first owner.

Install Cerberus Help & operations View on GitHub Buy me a coffee

Only scan websites you own or are explicitly authorized to assess. Read the Help, Terms, Privacy Policy, and Disclaimer before use.