siparsecurity

Sipar Security — Cybersecurity Tools & Services
Actively Building · Open Source · Pakistan 🇵🇰

Cybersecurity tools and services built for everyone.

Sipar Security develops open-source security tools, provides professional security services, and conducts applied security research — built for real-world use, not enterprise budgets.

NEW DEVICE DETECTED · 192.168.1.201 · ARP SPOOF — HIGH CONFIDENCE · 192.168.1.1 · PORT SCAN DETECTED · 192.168.1.45 · ROGUE DEVICE FLAGGED · 192.168.1.88 · THREAT LEVEL: CRITICAL · 192.168.1.3 · SUBDOMAIN FOUND · api.target.com · ZONE TRANSFER REFUSED · ns1.target.com · CNAME TAKEOVER — VULNERABLE · blog.target.com → github.io · GHOSTCLAIM · FINGERPRINT MATCHED · GitHub Pages · POTENTIALLY VULNERABLE · shop.target.com → myshopify.com · NEW DEVICE DETECTED · 192.168.1.201 · ARP SPOOF — HIGH CONFIDENCE · 192.168.1.1 · PORT SCAN DETECTED · 192.168.1.45 · ROGUE DEVICE FLAGGED · 192.168.1.88 · THREAT LEVEL: CRITICAL · 192.168.1.3 · SUBDOMAIN FOUND · api.target.com · ZONE TRANSFER REFUSED · ns1.target.com · CNAME TAKEOVER — VULNERABLE · blog.target.com → github.io · GHOSTCLAIM · FINGERPRINT MATCHED · GitHub Pages · POTENTIALLY VULNERABLE · shop.target.com → myshopify.com ·
7+
Tools Released
100%
Open Source
0$
Cost to Use
PK 🇵🇰
Built in Pakistan
Our Tools
What we are building
All tools are free, open-source, and available on GitHub. Pro versions are available directly for advanced features.
Tool 01 · Network SecurityActive
Sipar Network Monitor
A Python-based network intrusion detection system. Detects every device, tracks online/offline status, flags ARP spoofing, port scans, rogue devices, and scores threats in real time.
v1.0 Released v2.0 Released v3.0 Released
View on GitHub →
Tool 02 · Offensive SecurityActive
ShadowMap
A web reconnaissance framework built for bug bounty hunters and penetration testers. Automates subdomain enumeration, DNS recon, technology fingerprinting, and port scanning into a single command — now fully open source with improved detection accuracy.
v1.0 Released Fully Open Source
View on GitHub →
Tool 03 · Offensive SecurityNew
GhostClaim
A subdomain takeover detection tool for penetration testers and bug bounty hunters. Enumerates subdomains, follows full CNAME chains, and fingerprints HTTP responses against known vulnerable services.
v1.0 Free Released Pro Available
Free → Pro →
Tool 04 · Attack Surface VisualizationPre-Alpha
Sipar Visualizer
Ingests output from Amass, httpx, nmap, and ShadowMap and renders an interactive attack surface graph as a single self-contained HTML file. No server, no setup, just open it in a browser.
Pre-Alpha
View on GitHub →
Tool 05 · API Discoveryv0.1
EchoRoute
A source map based endpoint recovery tool. Crawls a target, extracts and resolves JavaScript source maps, and surfaces hidden API endpoints, including sensitive routes that would otherwise stay buried in bundled code.
v0.1
View on GitHub →
Tool 06 · NGO & Nonprofit SecurityNew
OpenGuard
A free security scanner built for nonprofits and small teams with no dedicated security staff. Checks for exposed legacy admin panels, outdated CMS versions, exposed API keys in JavaScript, missing security headers, and subdomain takeover risk, then generates one plain-language HTML report with an overall risk rating.
v3.1 Released
View on GitHub →
Tool 07 · API SecurityIn Development
GQLRecon
A GraphQL security fuzzer for bug bounty hunters and penetration testers. Maps a target's full schema via introspection, tests for batching and alias based rate limit bypass, fuzzes query depth for resource exhaustion, and checks field level authorization for broken access control.
Stage 1: Schema Discovery Stage 2: Batching & Alias Abuse Stage 3: Depth Fuzzing Stage 4: Field Auth Testing Stage 5: Risk Scoring & Reports
View on GitHub →
Want the Pro version?
GhostClaim Pro adds 30+ service fingerprints, stealth modes, JSON export, and professional report generation.
Get Pro →
Follow us on GitHub to stay updated on new releases.
Network Monitor — Release History
Three versions. Each one better.
Every version is publicly available. Download any version from GitHub.
v1.0 — 2026
Version 1.0 — Foundation
First public release. ARP scan engine, event server, persistent logging, SOC dashboard, and auto interface detection.
ARP ScanningSOC DashboardEvent ServerPersistent Logging
Released
v2.0 — 2026
Version 2.0 — Device Intelligence
Device schema with first/last seen, offline detection after 3 missed scans, ARP spoof cooldown, MAC randomization handling, and upgraded dashboard.
Device SchemaOffline DetectionARP Spoof CooldownMAC Randomization Handling/stats API
Released
v3.0 — 2026
Version 3.0 — Attack Detection
Full attack detection engine. Confidence-scored ARP spoof, duplicate MAC detection, port scan detection, rogue device flagging, threat levels, risk decay, and cross-platform support.
ARP Spoof Confidence ScoringDuplicate MAC DetectionPort Scan DetectionRogue Device DetectionLOW/MEDIUM/HIGH/CRITICALLinux · Windows · Android
Latest
Capabilities
What the Network Monitor detects.
All features available in Version 3.0.
001
Device Discovery
ARP-based scanning finds every device — MAC, IP, first seen, last seen, cumulative risk score.
v1.0 +
002
Real-Time Tracking
7-second scan cycles. Online and offline status updates the moment something changes.
v1.0 +
003
ARP Spoof Detection
Confidence-scored — LOW, MEDIUM, HIGH. Cooldown timer and 60-second MAC randomization window.
v3.0
004
Port Scan Detection
Background thread watches for one IP probing multiple ports rapidly. Five ports in 10 seconds triggers alert.
v3.0
005
Duplicate MAC Detection
Same MAC address on two different IPs simultaneously — instantly flagged.
v3.0
006
Rogue Device Detection
Trusted baseline on first scan. Any device joining after is flagged as unknown immediately.
v3.0
007
Threat Level System
Every device scored LOW, MEDIUM, HIGH, or CRITICAL. Risk decays when device stays clean.
v3.0
008
SOC Dashboard
6 stat cards, threat badges, filtered alert panel, risk reset button. Accessible from any browser on same network.
v1.0 +
009
Persistent Logging
All events saved to disk as JSONL. Full device state rebuilt on every restart. Zero data loss.
v2.0 +
Platform Support
Runs everywhere.
One command to install. Dashboard accessible from any browser on the same network.
PlatformRun the ToolView Dashboard
Kali Linux✓ Full support
Ubuntu / Debian✓ Full support
Windows 10 / 11✓ Requires Npcap
Termux — Rooted Android✓ Full support
Termux — Not Rooted✗ Root required✓ Browser only
Any phone / tablet browser✓ Same WiFi, no setup
Founder
Sayed Muhammad Subayyal
Cybersecurity Researcher · Penetration Tester · Founder, Sipar Security

Cybersecurity researcher and penetration tester focused on network security, wireless security, vulnerability assessment, and open-source security tool development. Works with Linux environments, particularly Kali Linux, applying structured methodologies for security testing and defensive assessments. Actively contributes to the cybersecurity community through vulnerability disclosure, open-source development, and academic research. Currently studying at Islamia College Peshawar.

Published Research · 2026
Simulating and Mitigating Rogue Access Point Attacks in Wi-Fi Networks Using Open-Source Tools
Journal of Soft Computing and Artificial Intelligence
Network SecurityPenetration TestingWireless SecurityEthical HackingKali LinuxPythonOpen-Source ToolsVulnerability AssessmentBug BountySubdomain Takeover
17
Years old
7+
Tools released
1
Published paper
PK 🇵🇰
Pakistan
FAQ
Common questions
Answers to what people ask most often about our tools and services.
Are your tools really free?
Yes — completely free. All tools are open-source and published on GitHub under the MIT License. You can download, use, and modify them at no cost. A Pro version with advanced features is available separately for GhostClaim.
What is subdomain takeover and why does GhostClaim matter?
Subdomain takeover happens when a subdomain points to an external service (like GitHub Pages or Heroku) that has been deleted or abandoned. An attacker can claim that service and take control of the subdomain. GhostClaim automates the detection of this vulnerability across all subdomains of a target domain.
Can I use the Network Monitor on my home WiFi?
Yes. The Network Monitor is specifically designed for home users, IT administrators, and small businesses. You can run it on Linux (including Kali), Windows 10/11 with Npcap, or Android via Termux if rooted. The dashboard is viewable from any browser on the same network.
Is ShadowMap fully free now?
Yes. ShadowMap was previously split into Free and Pro editions. It's now a single fully open-source release with all features included — subdomain enumeration, DNS recon, technology fingerprinting, and port scanning — along with improved detection accuracy and fewer false positives.
What does Sipar Visualizer do?
Sipar Visualizer takes the raw output from Amass, httpx, nmap, and ShadowMap and turns it into a single interactive attack surface graph, delivered as one self-contained HTML file. No install, no server, just open it in a browser. It is currently pre-alpha.
What does EchoRoute do?
EchoRoute discovers hidden API endpoints by decoding JavaScript source maps. It crawls a target, extracts and resolves source maps, and surfaces routes that were never meant to be publicly visible, flagging sensitive ones like account deletion endpoints automatically. It is currently version 0.1.
What does OpenGuard do?
OpenGuard is a free security scanner built for nonprofits and small teams without dedicated security staff. It checks a domain for exposed legacy admin panels (like phpMyAdmin or cPanel), outdated CMS versions, exposed API keys in JavaScript, missing security headers, and subdomain takeover risk, then generates a single plain-language HTML report with an overall risk rating. It is currently version 3.1.
What is the difference between Free and Pro versions?
ShadowMap is now fully open source with no Pro split. For GhostClaim, the Free version covers core detection with 10 service fingerprints, while GhostClaim Pro adds 30+ service fingerprints, stealth modes, JSON export, and HTML/PDF report generation.
How do I get a Pro version?
Reach out to us via the contact options on our Services page. We send you the files directly — no payment platform, no license key, no internet activation required.
How do I report a bug or suggest a feature?
Open an issue on the relevant GitHub repository. We actively read and respond to issues.

Ready to get started?

Get our tools free on GitHub, order a fixed price report, or message us directly.