Abstract
Foxguard is an open-source Cybersecurity & Ethical Hacking project. A fast universal code security scanner, written in Rust. Batteries included: supports 14 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥. foxguard-github-app writes newline-delimited JSON logs. Completed and failed scans use event=foxguard.scan.completed and event=foxguard.scan.failed, with delivery, installation, repository, PR, commit, duration, and usage_scope fields for correlation. It is built using Rust. The complete source code is publicly available on GitHub under the MIT License, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.
1. Introduction
foxguard-github-app writes newline-delimited JSON logs. Completed and failed scans use event=foxguard.scan.completed and event=foxguard.scan.failed, with delivery, installation, repository, PR, commit, duration, and usage_scope fields for correlation. Keep identifiers as log fields, not metric labels.
Set FOXGUARD_INTERNAL_ACCOUNTS to a comma-separated list of your own GitHub accounts and organizations. Matching is case-insensitive. Other owners are classified as external; an unset list or missing owner produces unknown. External activity is not proof of a paying customer, and scans are not people.
Persist FOXGUARD_INSTALLATIONS_PATH and FOXGUARD_PULL_REQUEST_JOBS_PATH on durable storage. Monitor foxguard.installations.reconcile_failed alongside scan failures; foxguard.installations.reconciled reports the total and internal/external/unknown installation counts after a successful refresh. Size FOXGUARD_PR_WORKERS against measured scanner peak memory and the container memory limit: child-process OOM kills can occur without restarting the hosted application.
2. Objective
A fast universal code security scanner, written in Rust. Batteries included: supports 14 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
This project demonstrates how Rust can be applied to a real-world Cybersecurity & Ethical Hacking problem.
4. Technology Stack
5. System Requirements
General requirements for this technology stack — check the README for exact versions.
- Rust toolchain (rustup / cargo)
- Git (to clone the repository)
6. Installation & Setup
git clone https://github.com/0sec-labs/foxguard.git
cd foxguard- uses: 0sec-labs/foxguard/action@v0.14.0
- repo: https://github.com/0sec-labs/foxguard
- id: foxguard
npx foxguard . # zero install
pipx install foxguard # prebuilt CLI from PyPI
curl -fsSL https://foxguard.dev/install.sh | sh # prebuilt binary (macOS/Linux)
cargo install foxguard # from source- uses: 0sec-labs/foxguard/action@v0.14.0
with:
path: .
severity: medium
fail-on-findings: "true"
upload-sarif: "true"repos:
- repo: https://github.com/0sec-labs/foxguard
rev: v0.14.0
hooks:
- id: foxguardfoxguard . # scan everything
foxguard diff main . # only new findings vs main
foxguard tui . # interactive terminal review
foxguard secrets . # leaked credentials and keys
foxguard sca . # dependency vulnerabilities from OSV
foxguard pqc . # post-quantum crypto audit
foxguard --format sarif . > results.sarif
foxguard --format semgrep-json . # Semgrep CLI-compatible JSONFull setup instructions are in the project README.
7. Future Enhancements
Suggested extensions you can add to make this your own project.
- Add logging and alert notifications (email / Telegram)
- Write a threat model document for the tool
- Package it with Docker for safe lab testing
8. Viva / Review Questions
Common questions examiners ask for projects in this domain.
- Which threat or attack does this project defend against?
- What detection or protection technique is used and what are its limits?
- How are false positives and false negatives handled?
- Which cryptographic algorithms or security standards are involved?
- What legal and ethical rules apply when testing a tool like this?
9. Source Code & License
This project is developed by 0sec-labs and published on GitHub under the MIT License. Please follow the license terms and credit the original author when you use or modify this code.
Want to build this as your internship project?
Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.
Apply for Cybersecurity & Ethical Hacking Internship