URL: YouTube
URL: Canva
Jacis is a Brazilian software project developed in Python as the final project for CS50P (CS50's Introduction to Programming with Python).
Its name is inspired by Jaci, the Moon goddess in Tupi-Guarani mythology.
The project provides a visual OSINT tool that transforms publicly available information into an interactive graph, making it easier to understand a target's technology stack and the publicly disclosed vulnerabilities associated with the detected services.
The project was created with the following goals:
- Demonstrate Python programming concepts.
- Apply OSINT techniques using publicly available information.
- Provide a visual representation of a target's technologies.
- Associate detected services with public vulnerabilities (CVEs).
- Build an intuitive graph-based interface for security analysis.
After receiving a domain name or IP address, Jacis performs an analysis using public information sources.
The analyzed target becomes the central node of the graph.
From this node, edges are created connecting:
- detected technologies;
- identified products and services;
- publicly disclosed vulnerabilities (CVEs).
Each category is displayed using a different color, making the graph easier to interpret.
Critical vulnerabilities are highlighted in red, and their node size increases according to their severity, allowing users to quickly identify the most relevant security issues.
The goal is to provide a simple and intuitive visualization of publicly available information.
Jacis retrieves vulnerability information through the official National Vulnerability Database (NVD) API v2.
Endpoint:
https://services.nvd.nist.gov/rest/json/cves/2.0
Requests are performed in real time using HTTP.
All required dependencies are listed in:
requirements.txt
Install them with:
pip install -r requirements.txtDependencies may also be installed manually if preferred.
Start the application with:
python3 jacis.pyYou can also provide a domain name or IP address directly as a command-line argument:
python3 jacis.py example.comor
python3 jacis.py 8.8.8.8The project uses sys.argv to process command-line arguments.
Before starting the analysis, regular expressions (Regex) validate whether the provided input is a valid domain name or IPv4 address. Invalid inputs are rejected with an appropriate error message.
After the scan is completed, Jacis generates an interactive graph where the analyzed domain or IP address becomes the central node.
Edges connect this node to the detected services and technologies, such as web servers (for example, Nginx), CSS frameworks (such as Tailwind CSS), and other components discovered during the analysis. Each category is represented by a different color, as shown in the graph legend.
Public vulnerabilities appear as red nodes. These nodes represent CVEs (Common Vulnerabilities and Exposures), an internationally recognized catalog of publicly disclosed cybersecurity vulnerabilities. The displayed CVEs are associated with the detected products and services and are retrieved through the official National Vulnerability Database (NVD) API.
When execution finishes, the application displays the location of the generated graph.html file.
In most cases, opening this file in your browser is sufficient to view the interactive graph.
If your browser restricts local JavaScript execution, you can either:
- open the
graph.htmlfile manually from the project directory; or - launch it using the Live Server extension for Visual Studio Code.
Jacis was developed exclusively for educational, digital forensics, cybersecurity research, and OSINT purposes.
The software:
- uses only publicly available information;
- queries public APIs;
- does not exploit vulnerabilities;
- does not perform attacks;
- does not attempt unauthorized access.
The reported CVEs refer to the third-party products and services detected during the analysis and don't necessarily indicate that the analyzed website or server is vulnerable.
Jacis doesn't provide capabilities that facilitate malicious activity. It's purpose is to organize and visualize public information, assisting students, researchers, incident responders, and security professionals in understanding a target's observable technology stack.
Undergraduate student in Computer Science at the Pontifical Catholic University of Minas Gerais (PUC Minas).
This project is licensed under the MIT License.


