Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

Tools: recon (229)

Pentesting tools tagged recon. See all tools or the category key.

Team (best effort)

activedirectoryenum

Enumerate AD through LDAP.

recon Red Team

ad-ldap-enum

An LDAP based Active Directory user and group enumeration tool.

recon Red Team

ad-miner

Active Directory audit tool that extract data from Bloodhound to uncover security weaknesses and generate an HTML report

recon Red Team

adexplorersnapshot

AD Explorer snapshot parser.

recon Red Team

adidnsdump

Active Directory Integrated DNS dumping by any authenticated user.

recon Red Team

aiodnsbrute

Python 3 DNS asynchronous brute force utility.

recon Red Team

aquatone

A Tool for Domain Flyovers.

recon Red Team

asn

ASN, RPKI validity, BGP stats, IPv4v6, Prefix, URL, ASPath, Organization, IP reputation, IP geolocation, IP fingerprinti

recon Red Team

attacksurfacemapper

Tool that aims to automate the reconnaissance process.

recon Red Team

autosint

Tool to automate common osint tasks.

recon Red Team

aws-inventory

Discover resources created in an AWS account.

recon Red Team

aztarna

A footprinting tool for ROS and SROS systems.

recon Red Team

badkarma

Advanced network reconnaissance toolkit.

recon Red Team

basedomainname

Tool that can extract TLD (Top Level Domain), domain extensions (Second Level Domain + TLD), domain name, and hostname f

recon Red Team

bbot

Multipurpose scanner built to automate your Recon, Bug Bounties, and ASM.

recon Red Team

bfac

An automated tool that checks for backup artifacts that may disclose the web-application's source code.

recon Red Team

billcipher

Information Gathering tool for a Website or IP address.

recon Red Team

bloodhound-python

Python data collector for Bloodhound legcacy (v4)

recon Red Team

bridgekeeper

Scrape employee names from search engine LinkedIn profiles. Convert employee names to a specified username format.

recon Red Team

catnthecanary

An application to query the canary.pw data set for leaked data.

recon Red Team

ccrawldns

Retrieves from the CommonCrawl data set unique subdomains for a given domain name.

recon Red Team

chaos-client

Go client to communicate with Chaos dataset API.

recon Red Team

chronoleak

ICMP Timestamp Remote Time Leaker.

recon Red Team

citadel

A library of OSINT tools.

recon Red Team

cloud-buster

A tool that checks Cloudflare enabled sites for origin IP leaks.

recon Red Team

cloudfail

Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network.

recon Red Team

cloudlist

A tool for listing Assets from multiple Cloud Providers.

recon Red Team

cloudmare

A simple tool to find origin servers of websites protected by CloudFlare with a misconfiguration DNS.

recon Red Team

cloudunflare

Reconnaissance Real IP address for Cloudflare Bypass.

recon Red Team

cr3dov3r

Search for public leaks for email addresses + check creds against 16 websites.

recon Red Team

datasploit

Performs automated OSINT and more.

recon Red Team

dga-detection

DGA Domain Detection using Bigram Frequency Analysis.

recon Red Team

dns-parallel-prober

PoC for an adaptive parallelised DNS prober.

recon Red Team

dnsbrute

Multi-theaded DNS bruteforcing, average speed 80 lookups/second with 40 threads.

recon Red Team

dnscobra

DNS subdomain bruteforcing tool with Tor support through torsocks.

recon Red Team

dnsgrep

A utility for quickly searching presorted DNS names.

recon Red Team

dnsprobe

Allows you to perform multiple dns queries of your choice with a list of user supplied resolvers.

recon Red Team

dnssearch

A subdomain enumeration tool.

recon Red Team

dnsspider

A fast multithreaded bruteforcer of subdomains that leverages a wordlist and/or character permutation.

recon Red Team

domain-analyzer

Finds all the security information for a given domain name.

recon Red Team

domain-stats

A web API to deliver domain information from whois and alexa.

recon Red Team

domained

Multi Tool Subdomain Enumeration.

recon Red Team

domainhunter

Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing a

recon Red Team

dradis-ce

An open source framework to enable effective information sharing.

recon Red Team

elevate

Horizontal domain discovery tool you can use to discover other domains owned by a given company.

recon Red Team

enum4linux-ng-git

A next generation version of enum4linux

recon Red Team

enumerate-iam

Enumerate the permissions associated with an AWS credential set.

recon Red Team

enumerid

Enumerate RIDs using pure Python.

recon Red Team

exitmap

A fast and modular scanner for Tor exit relays.

recon Red Team

eyewitness-git

designed to take screenshots of websites, provide some server header info, and identify default credentials is possible

recon Red Team

facebot

A facebook profile and reconnaissance system.

recon Red Team

fav-up

IP lookup by favicon using Shodan.

recon Red Team

favfreak

Weaponizing favicon.ico for BugBounties , OSINT and what not.

recon Red Team

fbid

Show info about the author by facebook photo url.

recon Red Team

flashlight

Automated Information Gathering Tool for Penetration Testers.

recon Red Team

forager

Multithreaded threat Intelligence gathering utilizing.

recon Red Team

gasmask

All in one Information gathering tool - OSINT.

recon Red Team

gatecrasher

Network auditing and analysis tool developed in Python.

recon Red Team

geoedge

This little tools is designed to get geolocalization information of a host, it get the information from two sources (max

recon Red Team

gh-dork

Github dorking tool.

recon Red Team

ghunt

An offensive OSINT Google framework.

recon Red Team

git-hound

Pinpoints exposed API keys on GitHub. A batch-catching, pattern-matching, patch-attacking secret snatcher.

recon Red Team

git-wild-hunt

A tool to hunt for credentials in github wild AKA git*hunt.

recon Red Team

gitdorker

Python program to scrape secrets from GitHub through usage of a large repository of dorks.

recon Red Team

gitem

A Github organization reconnaissance tool.

recon Red Team

gitgraber

Monitor GitHub to search and find sensitive data in real time for different online services.

recon Red Team

githack

A `.git` folder disclosure exploit.

recon Red Team

github-dorks

Collection of github dorks and helper tool to automate the process of checking dorks.

recon Red Team

github-subdomains

Find subdomains on GitHub.

recon Red Team

gitmails

An information gathering tool to collect git commit emails in version control host services.

recon Red Team

gitminer

Tool for advanced mining for content on Github.

recon Red Team

gitrecon

OSINT tool to get information from a Github and Gitlab profile and find user's email addresses leaked on commits.

recon Red Team

go-windapsearch

Utility to enumerate users, groups and computers from a Windows domain through LDAP queries.

recon Red Team

goddi

Dumps Active Directory domain information.

recon Red Team

goodork

A python script designed to allow you to leverage the power of google dorking straight from the comfort of your command

recon Red Team

goog-mail

Enumerate domain emails from google.

recon Red Team

googlesub

A python script to find domains by using google dorks.

recon Red Team

goohak

Automatically Launch Google Hacking Queries Against A Target Domain.

recon Red Team

goop

Perform google searches without being blocked by the CAPTCHA or hitting any rate limits.

recon Red Team

gosint

OSINT framework in Go.

recon Red Team

gowitness-git

A golang web screenshot utility using Chrome Headless

recon Red Team

grabing

Counts all the hostnames for an IP adress

recon Red Team

graphinder

GraphQL endpoints finder using subdomain enumeration, scripts analysis and bruteforce.

recon Red Team

gwtenum

Enumeration of GWT-RCP method calls.

recon Red Team

hakrevdns

Small, fast tool for performing reverse DNS lookups en masse.

recon Red Team

halcyon

A repository crawler that runs checksums for static files found within a given git repository.

recon Red Team

hasere

Discover the vhosts using google and bing.

recon Red Team

hatcloud

Bypass CloudFlare with Ruby.

recon Red Team

hoper

Trace URL's jumps across the rel links to obtain the last URL.

recon Red Team

howmanypeoplearearound

Count the number of people around you by monitoring wifi signals.

recon Red Team

id-entify

Search for information related to a domain: Emails - IP addresses - Domains - Information on WEB technology - Type of Fi

recon Red Team

idswakeup

A collection of tools that allows to test network intrusion detection systems.

recon Red Team

infoga

Tool for gathering e-mail accounts information from different public sources (search engines, pgp key servers).

recon Red Team

inquisitor

OSINT Gathering Tool for Companies and Organizations.

recon Red Team

intelplot

OSINT Tool to Mark Points on Offline Map.

recon Red Team

intrace-git

Traceroute-like application piggybacking on existing TCP connections

recon Red Team

ip-tracer

Track and retrieve any ip address information.

recon Red Team

ip2clue

A small memory/CPU footprint daemon to lookup country (and other info) based on IP (v4 and v6).

recon Red Team

iptodomain

This tool extract domains from IP address based in the information saved in virustotal.

recon Red Team

ipv666

Golang IPv6 address enumeration.

recon Red Team

ircsnapshot

Tool to gather information from IRC servers.

recon Red Team

isr-form

Simple html parsing tool that extracts all form related information and generates reports of the data. Allows for quick

recon Red Team

ivre-docs

Network recon framework based on Nmap, Masscan, Zeek (Bro), Argus, Netflow,... (documentation)

recon Red Team

ivre-web

Network recon framework based on Nmap, Masscan, Zeek (Bro), Argus, Netflow,... (web application)

recon Red Team

jackdaw

Collect all information in your domain, show you graphs on how domain objects interact with each-other and how to exploi

recon Red Team

jsearch

Simple script that grep infos from javascript files.

recon Red Team

kacak

Tools for penetration testers that can enumerate which users logged on windows system.

recon Red Team

kamerka

Build interactive map of cameras from Shodan.

recon Red Team

keye

Recon tool detecting changes of websites based on content-length differences.

recon Red Team

lanmap2

Passive network mapping tool.

recon Red Team

ldapenum

Enumerate domain controllers using LDAP.

recon Red Team

lft

A layer four traceroute implementing numerous other features.

recon Red Team

lhf

A modular recon tool for pentesting.

recon Red Team

linux-exploit-suggester-git

A Perl script that tries to suggest exploits based OS version number

recon Red Team

linux-exploit-suggester.sh

Linux privilege escalation auditing tool.

recon Red Team

littlebrother

OSINT tool to get informations on French, Belgian and Swizerland people.

recon Red Team

loot

Sensitive information extraction tool.

recon Red Team

machinae

A tool for collecting intelligence from public sites/feeds about various security-related pieces of data.

recon Red Team

mail-crawl

Tool to harvest emails from website.

recon Red Team

massbleed

SSL Vulnerability Scanner.

recon Red Team

mdns-recon

An mDNS recon tool written in Python.

recon Red Team

metabigor

Intelligence Tool but without API key.

recon Red Team

metafinder

Search for documents in a domain through Search Engines (Google, Bing and Baidu). The objective is to extract metadata.

recon Red Team

mildew

Dotmil subdomain discovery tool that scrapes domains from official DoD website directories and certificate transparency

recon Red Team

monocle

A local network host discovery tool. In passive mode, it will listen for ARP request and reply packets. In active mode,

recon Red Team

nasnum

Script to enumerate network attached storages.

recon Red Team

necromant

Python Script that search unused Virtual Hosts in Web Servers.

recon Red Team

neglected

Facebook CDN Photo Resolver.

recon Red Team

netkit-bsd-finger

BSD-finger ported to Linux.

recon Red Team

netkit-rusers

Logged in users; Displays who is logged in to machines on local network.

recon Red Team

netkit-rwho

Remote who client and server (with Debian patches).

recon Red Team

netscout

OSINT tool that finds domains, subdomains, directories, endpoints and files.

recon Red Team

nohidy

The system admins best friend, multi platform auditing tool.

recon Red Team

nsec3map

A tool to enumerate the resource records of a DNS zone using its DNSSEC NSEC or NSEC3 chain.

recon Red Team

nsec3walker

Enumerate domain names using DNSSEC.

recon Red Team

ntlmrecon-git

A tool to enumerate information from NTLM authentication enabled web endpoints.

recon Red Team

ntp-ip-enum

Script to pull addresses from a NTP server using the monlist command. Can also output Maltego resultset.

recon Red Team

nullinux

Tool that can be used to enumerate OS information, domain information, shares, directories, and users through SMB null s

recon Red Team

omnibus

OSINT tool for intelligence collection, research and artifact management.

recon Red Team

onioff

An onion url inspector for inspecting deep web links.

recon Red Team

operative-framework

OSINT investigation framework

recon Red Team

osint-spy

Performs OSINT scan on email/domain/ip_address/organization.

recon Red Team

osinterator

Open Source Toolkit for Open Source Intelligence Gathering.

recon Red Team

osintgram

OSINT tool offering an interactive shell to perform analysis on Instagram account of any users by its nickname.

recon Red Team

parsero-git

A Robots.txt audit tool

recon Red Team

pastemonitor

Scrape Pastebin API to collect daily pastes, setup a wordlist and be alerted by email when you have a match..

recon Red Team

pdfgrab

Tool for searching pdfs withthin google and extracting pdf metadata.

recon Red Team

pius-pi

Organizational asset discovery tool with 20+ plugins covering certificate transparency, passive DNS, and all 5 Regional

recon Red Team

pmapper

A tool for quickly evaluating IAM permissions in AWS.

recon Red Team

postenum

Clean, nice and easy tool for basic/advanced privilege escalation techniques.

recon Red Team

protosint

Python script that helps you investigate Protonmail accounts and ProtonVPN IP addresses.

recon Red Team

punter

Hunt domain names using DNSDumpster, WHOIS, Reverse WHOIS, Shodan, Crimeflare.

recon Red Team

puredns

Fast domain resolver and subdomain bruteforcing with accurate wildcard filtering.

recon Red Team

pwned

A command-line tool for querying the 'Have I been pwned?' service.

recon Red Team

pwned-search

Pwned Password API lookup.

recon Red Team

pwnedornot

Tool to find passwords for compromised email addresses.

recon Red Team

pymeta

Auto Scanning to SSL Vulnerability.

recon Red Team

python-api-dnsdumpster

Unofficial Python API for http://dnsdumpster.com/.

recon Red Team

python-ivre

Network recon framework based on Nmap, Masscan, Zeek (Bro), Argus, Netflow,... (library)

recon Red Team

python2-api-dnsdumpster

Unofficial Python API for http://dnsdumpster.com/.

recon Red Team

python2-ivre

Network recon framework based on Nmap, Masscan, Zeek (Bro), Argus, Netflow,... (library)

recon Red Team

python2-shodan

Python library and command-line utility for Shodan (https://developer.shodan.io).

recon Red Team

quickrecon

A python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gather

recon Red Team

raccoon

A high performance offensive security tool for reconnaissance and vulnerability scanning.

recon Red Team

rdwatool

A python script to extract information from a Microsoft Remote Desktop Web Access (RDWA) application.

recon Red Team

recon-ng-git

A full-featured Web Reconnaissance framework written in Python.

recon Red Team

reconnoitre

A security tool for multithreaded information gathering and service enumeration.

recon Red Team

reconscan

Network reconnaissance and vulnerability assessment tools.

recon Red Team

recsech

Tool for doing Footprinting and Reconnaissance on the target web.

recon Red Team

red-hawk

All in one tool for Information Gathering, Vulnerability Scanning and Crawling.

recon Red Team

reverseip

Ruby based reverse IP-lookup tool.

recon Red Team

revipd

A simple reverse IP domain scanner.

recon Red Team

ridrelay

Enumerate usernames on a domain where you have no creds by using SMB Relay with low priv.

recon Red Team

ripdc

A script which maps domains related to an given ip address or domainname.

recon Red Team

rita

Real Intelligence Threat Analytics.

recon Red Team

rusthound-ce

Active Directory data collector for BloodHound community edition (v5).

recon Red Team

s3enum

Amazon S3 bucket enumeration.

recon Red Team

scavenger

Crawler (Bot) searching for credential leaks on different paste sites.

recon Red Team

screamer

Fast Subnet Discovery.

recon Red Team

scylla

Find Advanced Information on a Username, Website, Phone Number, etc.

recon Red Team

seekr

A multi-purpose OSINT toolkit with a neat web-interface.

recon Red Team

server-status-pwn

A script that monitors and extracts requested URLs and clients connected to the service by exploiting publicly accessibl

recon Red Team

shard

A command line tool to detect shared passwords.

recon Red Team

shhgit

Find committed secrets and sensitive files across GitHub, Gists, GitLab and BitBucket or your local repositories in real

recon Red Team

shodanhat

Search for hosts info with shodan.

recon Red Team

shosubgo

Small tool to Grab subdomains using Shodan API.

recon Red Team

simplyemail

Email recon made fast and easy, with a framework to build on CyberSyndicates.

recon Red Team

sipi

Simple IP Information Tools for Reputation Data Analysis.

recon Red Team

smbcrunch

3 tools that work together to simplify reconnaissance of Windows File Shares.

recon Red Team

snscrape

A social networking service scraper in Python.

recon Red Team

socialscan

Check email address and username availability on online platforms.

recon Red Team

spfmap

A program to map out SPF and DKIM records for a large number of domains.

recon Red Team

spoofcheck

Simple script that checks a domain for email protections.

recon Red Team

spyse

Python API wrapper and command-line client for the tools hosted on spyse.com.

recon Red Team

sr

Perform subdomain enumeration, endpoint recognition, and more.

recon Red Team

ssl-hostname-resolver

CN (Common Name) grabber on X.509 Certificates over HTTPS.

recon Red Team

stardox

Github stargazers information gathering tool.

recon Red Team

subdomainer

A tool designed for obtaining subdomain names from public sources.

recon Red Team

sublert

A security and reconnaissance tool which leverages certificate transparency to automatically monitor new subdomains depl

recon Red Team

subscraper

Tool that performs subdomain enumeration through various techniques.

recon Red Team

svn-extractor

A simple script to extract all web resources by means of .SVN folder exposed over network.

recon Red Team

swamp

An OSINT tool for discovering associated sites through Google Analytics Tracking IDs.

recon Red Team

syborg

Recursive DNS Subdomain Enumerator with dead-end avoidance system.

recon Red Team

teamsuserenum

User enumeration with Microsoft Teams API

recon Red Team

thedorkbox

Comprehensive collection of Google Dorks & OSINT techniques to find Confidential Data.

recon Red Team

theharvester-git

Python tool for gathering e-mail accounts and subdomain names from different public sources (search engines, pgp key servers)

recon Red Team

tilt

An easy and simple tool implemented in Python for ip reconnaissance, with reverse ip lookup.

recon Red Team

tinfoleak

Get detailed information about a Twitter user activity.

recon Red Team

tinfoleak2

The most complete open-source tool for Twitter intelligence analysis.

recon Red Team

treasure

Hunt for sensitive information through githubs code search.

recon Red Team

trusttrees

A Tool for DNS Delegation Trust Graphing.

recon Red Team

ubiquiti-probing

A Ubiquiti device discovery tool.

recon Red Team

udork

Bash script that uses advanced Google search techniques to obtain sensitive information in files or directories, find Io

recon Red Team

uhoh365

Script to enumerate Office 365 users without performing login attempts

recon Red Team

uncover

Discover exposed hosts on the internet using multiple search engines.

recon Red Team

userrecon

Find usernames across over 75 social networks.

recon Red Team

vbrute

Virtual hosts brute forcer.

recon Red Team

vpnpivot

Explore the network using this tool.

recon Red Team

waldo

A lightweight and multithreaded directory and subdomain bruteforcer implemented in Python.

recon Red Team

waybackurls

Fetch all the URLs that the Wayback Machine knows about for a domain.

recon Red Team

waymore

Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan & VirusTotal.

recon Red Team

websearch

Search vhost names given a host range. Powered by Bing..

recon Red Team

weebdns

DNS Enumeration with Asynchronicity.

recon Red Team

whoxyrm

A reverse whois tool based on Whoxy API.

recon Red Team

windapsearch

Script to enumerate users, groups and computers from a Windows domain through LDAP queries.

recon Red Team

windows-exploit-suggester

This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential miss

recon Red Team

xray

A tool for recon, mapping and OSINT gathering from public networks.

recon Red Team

zeus-scanner

Advanced dork searching utility.

recon Red Team

zgrab

Grab banners (optionally over TLS).

recon Red Team