Desktop scanner · 100% free

The Crucible Security scanner, in your dock.

The full security engine running locally on your machine. Scan internal networks, GitHub repos, and on-prem services that the cloud scanner can't reach. Download and run in under 60 seconds. Free.

100% free. The desktop scanner is free for everyone. No account required. Download, install, scan.
🛡️
Free web scanner — live now

Scan your site free — right in your browser

No install, no account. The free scanner checks TLS, security headers, exposed files, DNS/email auth, and more — instantly.

🌐 Run the free scan now — no install

🖥️ Desktop app for host-level scanning BETA

The web scanner checks your site from the outside. To scan the machine itself — running processes, persistence (LaunchAgents/Daemons), browser forensics, malware signatures (ClamAV/YARA), boot-volume integrity — you need the local desktop app. It runs 100% on your device; nothing leaves your machine.

  • macOS (Intel & Apple Silicon) — beta build in final code-signing & notarization before public release.
  • Requires Python 3.8+ (dependencies auto-install on first launch). Optional: brew install yara clamav for signature scanning.
  • Windows / Linux — planned.
🍎 Get the macOS beta on GitHubOpen-source · build from source or grab a signed build when posted
Honest status: the free web scanner is live. The native desktop app is a working beta going through Apple code-signing before we post a one-click installer — we won't ship an unsigned download that macOS flags as "damaged."
Why the desktop app

Reach what the cloud can't.

The web scanner sees public-internet endpoints. The desktop app sees your private network, your authenticated apps, and the code on your laptop. Same engine — wider field of view.

🔒

Authenticated scans

Log into the apps you actually run — Slack, GitHub, Google Workspace, Okta — and let Crucible Security inspect what only an authenticated user can see.

🌐

Internal network sweep

Scan RFC1918 ranges, on-prem services, and dev/staging environments behind your VPN. Findings stay local, hashes upload to Forensics.

📦

Local GitHub repos

Point the app at any local checkout for full code-quality analysis — secrets, dead links, broken imports, missing CSP headers in shipped builds.

Faster than the cloud

No round-trip to our servers. Scans complete in seconds, not minutes. Results sync to your Auto-Response dashboard so the team sees them too.

🍯

Honeypot Defense local deployer

Drop honeypots and canary tokens onto your own machines — the desktop app handles the install, registration, and live monitoring end-to-end.

📋

Offline reports

Generate signed PDF + JSON reports without an internet connection. Pass to auditors, regulators, or insurance brokers as-is.

System requirements
  • macOS: 13 Ventura+, Apple Silicon or Intel
  • Windows: 10 / 11, 64-bit
  • Linux: Ubuntu 22.04+, Fedora 38+, glibc 2.35+
  • RAM: 4 GB minimum, 8 GB recommended
  • Disk: 400 MB install, 2 GB for scan history
  • Network: outbound HTTPS to your Auto-Response instance

Builds are signed with the CRUCiBLE CAPiTAL SYSTEMS LLC Apple Developer ID and an EV code-signing certificate on Windows. SHA-256 hashes published at releases page for verification.

Notify me when builds drop

First in line. First scan.

We email you the moment macOS, Windows, and Linux builds are signed and posted. No marketing blasts in between.

No spam. Beta invites only. One email a month, max.
✓ You're on the list. Check your inbox for a confirmation from Crucible Security.