Smap

a drop-in replacement for Nmap powered by shodan.io

Cybersecurity & Ethical HackingGoAGPL-3.0

Abstract

Smap is an open-source Cybersecurity & Ethical Hacking project. A drop-in replacement for Nmap powered by shodan.io. Smap is a passive port scanner built with shodan.io's free API. It takes the same command line arguments as Nmap and produces the same output, which makes it a drop-in replacement for Nmap. It is built using Go. Key capabilities include: Scans 200 hosts per second; Doesn't require any account/api key; Vulnerability detection. The complete source code is publicly available on GitHub under the GNU Affero General Public License v3.0, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.

1. Introduction

Smap is a passive port scanner built with shodan.io's free API. It takes the same command line arguments as Nmap and produces the same output, which makes it a drop-in replacement for Nmap.

2. Objective

a drop-in replacement for Nmap powered by shodan.io

This project demonstrates how Go can be applied to a real-world Cybersecurity & Ethical Hacking problem.

3. Key Features / Modules

  • Scans 200 hosts per second
  • Doesn't require any account/api key
  • Vulnerability detection
  • Supports nmap's output formats
  • Service and version fingerprinting
  • Makes no contact to the targets in passive mode
  • Optional nmap acceleration using Shodan's reported ports

4. Technology Stack

Go

5. System Requirements

General requirements for this technology stack — check the README for exact versions.

  • Go 1.20 or later
  • Git (to clone the repository)

6. Installation & Setup

git clone https://github.com/s0md3v/Smap.git
cd Smap

Full setup instructions are in the project README.

7. Future Enhancements

Suggested extensions you can add to make this your own project.

  • Add logging and alert notifications (email / Telegram)
  • Write a threat model document for the tool
  • Package it with Docker for safe lab testing

8. Viva / Review Questions

Common questions examiners ask for projects in this domain.

  1. Which threat or attack does this project defend against?
  2. What detection or protection technique is used and what are its limits?
  3. How are false positives and false negatives handled?
  4. Which cryptographic algorithms or security standards are involved?
  5. What legal and ethical rules apply when testing a tool like this?

9. Source Code & License

This project is developed by s0md3v and published on GitHub under the GNU Affero General Public License v3.0. Please follow the license terms and credit the original author when you use or modify this code.

Want to build this as your internship project?

Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.

Apply for Cybersecurity & Ethical Hacking Internship