Command Overview
Global Flags
Use the same configuration file for Web UI and CLI workflows when CLI scan results should appear in the same workspace database.
Activate
Online activation:
Run
vulnscan license after activation to verify target scope, expiration, activation count, and feature availability.
License, Fingerprint, and Deactivation
Show license status:Start the Web UI
Start on the default local address:
On first run, open the printed URL and create the initial administrator account.
Scan
Thescan command runs discovery, fingerprinting, vulnerability detection, enrichment, deduplication, risk scoring, persistence, and report export.
Scan One Target
Scan Multiple Targets
Scan From a Target File
Createtargets.txt:
Include Subdomains
Authenticated Web Scan
Cookie-based session:Generate Reports
CSV and JSON:Scan Flags
Subdomain Discovery
Enumerate subdomains:
Use subdomain discovery before broad scans when you need to understand scope and target count.
Offline Preparation
Prepare scanner artifacts and vulnerability intelligence data for offline or pre-baked environments:Update and Version
Print version:Automation Patterns
Nightly External Scan
CI Security Gate
Vietnamese Customer Report
CLI Quality Checklist
- Use licensed targets only.
- Keep the CLI configuration aligned with the Web UI workspace when data consistency is required.
- Prefer target files for repeatable automation.
- Use dedicated test credentials for authenticated scans.
- Store reports in a controlled output directory.
- Use JSON for integrations and CSV for remediation tracking.
- Review high-severity results in the Web UI when collaborative triage is needed.