This product was not featured by Product Hunt yet. It will not be visible on their landing page and won't be ranked (cannot win product of the day regardless of upvotes).
Open-source, self-hosted attack surface management. Discover, monitor and secure your internet-facing assets with AI-assisted analysis — deploy with Docker in minutes.
I've been building OASM (Open Attack Surface Management), an open-source security platform designed to help developers and security teams discover, monitor, and scan their attack surface.
I wanted to build something that gives people more control over their security tooling without requiring them to pay for an expensive SaaS platform or hand over their infrastructure data to a third party.
What is OASM?
OASM helps you manage your attack surface and run security scans from a centralized platform.
A few things I'm focusing on:
Free & open source — You can explore and use the platform without a paid subscription.
Self-hosted — Run OASM on your own infrastructure and maintain control over your data and scanning environment.
Integrations — Connect different tools and services to bring security-related information into one place.
Worker nodes — Run scans through worker nodes, with the goal of making scanning more flexible and scalable.
Centralized visibility — Manage assets and review discovered vulnerabilities from a single platform.
Why I built it
Security tools are often fragmented. You might have one tool for asset discovery, another for vulnerability scanning, and other services for managing your infrastructure or source code.
I wanted to explore whether these workflows could be brought together in a self-hostable platform that developers can customize and extend.
OASM is still an early-stage project, and I'm actively developing it. I'm especially interested in feedback from people who work with security automation, attack surface management, or self-hosted infrastructure.
OASM was submitted on Product Hunt and earned 2 upvotes and 1 comments, placing #156 on the daily leaderboard. Open-source, self-hosted attack surface management. Discover, monitor and secure your internet-facing assets with AI-assisted analysis — deploy with Docker in minutes.
OASM was featured in Open Source (68.9k followers), GitHub (41.4k followers) and Security (2.9k followers) on Product Hunt. Together, these topics include over 52.7k products, making this a competitive space to launch in.
Who hunted OASM?
OASM was hunted by Vinh. A “hunter” on Product Hunt is the community member who submits a product to the platform — uploading the images, the link, and tagging the makers behind it. Hunters typically write the first comment explaining why a product is worth attention, and their followers are notified the moment they post. Around 79% of featured launches on Product Hunt are self-hunted by their makers, but a well-known hunter still acts as a signal of quality to the rest of the community. See the full all-time top hunters leaderboard to discover who is shaping the Product Hunt ecosystem.
Want to see how OASM stacked up against nearby launches in real time? Check out the live launch dashboard for upvote speed charts, proximity comparisons, and more analytics.
Hey everyone!
I've been building OASM (Open Attack Surface Management), an open-source security platform designed to help developers and security teams discover, monitor, and scan their attack surface.
I wanted to build something that gives people more control over their security tooling without requiring them to pay for an expensive SaaS platform or hand over their infrastructure data to a third party.
What is OASM?
OASM helps you manage your attack surface and run security scans from a centralized platform.
A few things I'm focusing on:
Free & open source — You can explore and use the platform without a paid subscription.
Self-hosted — Run OASM on your own infrastructure and maintain control over your data and scanning environment.
Integrations — Connect different tools and services to bring security-related information into one place.
Worker nodes — Run scans through worker nodes, with the goal of making scanning more flexible and scalable.
Centralized visibility — Manage assets and review discovered vulnerabilities from a single platform.
Why I built it
Security tools are often fragmented. You might have one tool for asset discovery, another for vulnerability scanning, and other services for managing your infrastructure or source code.
I wanted to explore whether these workflows could be brought together in a self-hostable platform that developers can customize and extend.
OASM is still an early-stage project, and I'm actively developing it. I'm especially interested in feedback from people who work with security automation, attack surface management, or self-hosted infrastructure.
If you're interested, check it out:
Website: https://oasm.dev
Marketplace: https://oasm.dev/marketplace
I'd love to hear your thoughts:
What integrations would you want to see in a platform like this?
Would you prefer running all scanning workers yourself, or having a hybrid setup?
What features are missing from existing open-source security platforms?
Thanks for checking it out!