# 使用 Homebrew, Nix 安装 gsan

查看 gsan 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

## 安装

```sh
sudo av install brew:gsan
```

其他安装命令:

### macOS

- Homebrew (100%):

```sh
brew install gsan
```

  证据: local Homebrew formula metadata

### Linux

- Nix (92%):

```sh
nix profile install nixpkgs#gsan
```

  证据: nixpkgs package indexes: pkgs/by-name/gs/gsan/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

## 软件包事实

- **软件包键:** brew:gsan
- **软件包管理器:** Homebrew
- **版本:** 5.0.0
- **来源摘要:** Extract subdomains from SSL certificates in HTTPS sites
- **主页:** <https://franccesco.github.io/getaltname/>
- **仓库:** <https://github.com/franccesco/getaltname>
- **最后更新:** 2026-08-02T20:52:09+09:00
- **已生成:** 2026-08-03T19:37:03+00:00

## 可执行文件

- gsan (别名)

## 安装行为

- Bottle: 不可用

## 版本和新鲜度

- 页面生成时间: 2026-08-03
- 管理器版本: 5.0.0
## 项目历史与用法

GSAN, from the getaltname project, is a small reconnaissance CLI for extracting Subject Alternative Names from HTTPS certificates. Its distinctive point is that it connects directly to servers rather than relying on Certificate Transparency logs.

### 项目历史

The GitHub repository was created in November 2017, and early releases appeared in March 2018. The release stream moved quickly through 0.x and 1.x versions in 2018, reached 3.x during 2018 and 2019, published 4.2.3 in October 2020, and published 5.0.0 in August 2024.

The README and GitHub Pages site present a focused tool: pass a domain or pipe domain and IP:PORT lists into `gsan`, extract DNS names from the certificate SAN extension, and optionally write output for other tools.

### 采用历史

GSAN's adoption evidence is narrow but clear: it is packaged for Homebrew and Nix and documented for pipx and Docker use. Its audience is security practitioners doing subdomain enumeration, especially in cases where direct certificate inspection is useful for internal servers, self-signed certificates, or targets not covered by public Certificate Transparency logs.

### 使用方式

Basic usage is `gsan example.com`, producing the SAN DNS names found in the HTTPS certificate. The documentation also shows piping many targets with xargs, using Docker, combining results from Shodan, applying timeouts, writing an output file, and passing that output to Nmap.

### 为什么软件包爱好者会关心

GSAN is package-manager interesting as a tiny Python security CLI whose value comes from composing with other tools. It takes certificate metadata, emits target lists, and fits into Unix pipelines with Shodan, xargs, Docker, and Nmap.

### 时间线

- 2017: GitHub repository created.
- 2018: 0.2.0 through 2.0.0 releases published in March.
- 2018: 3.0.3 release published in July.
- 2019: 3.0.13 and v3.0.14 releases published.
- 2020: v4.2.3 release published.
- 2024: v5.0.0 release published.

### Related projects

- Shodan is shown in the README as a source of HTTPS targets for GSAN.
- Nmap is shown as a downstream consumer of GSAN output files.
- Certificate Transparency log tools are related but differ from GSAN's direct TLS-connection approach.

### 来源

- <https://api.github.com/repos/franccesco/getaltname>
- <https://api.github.com/repos/franccesco/getaltname/releases?per_page=50>
- <https://franccesco.github.io/getaltname/>
- <https://github.com/franccesco/getaltname>


## 安全说明

broad file, network, media, or database tool signal.

- **Geiger 风险:** blue / 中
- broad file, network, media, or database tool signal

## 其他软件包管理器记录

- Nix - gsan: normalized package name match | nixpkgs package indexes: pkgs/by-name/gs/gsan/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1


## Combined YAML source

View the package source record on GitHub. [combined/gsan.yml](https://github.com/mxcl/pkgdb/blob/main/combined/gsan.yml)


## 来源

- pkg.so package database
- Geiger risk classifier
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
