Tools: recon (229)
Pentesting tools tagged recon. See all tools or the category key.
activedirectoryenum
Enumerate AD through LDAP.
ad-ldap-enum
An LDAP based Active Directory user and group enumeration tool.
ad-miner
Active Directory audit tool that extract data from Bloodhound to uncover security weaknesses and generate an HTML report
adexplorersnapshot
AD Explorer snapshot parser.
adidnsdump
Active Directory Integrated DNS dumping by any authenticated user.
aiodnsbrute
Python 3 DNS asynchronous brute force utility.
aquatone
A Tool for Domain Flyovers.
asn
ASN, RPKI validity, BGP stats, IPv4v6, Prefix, URL, ASPath, Organization, IP reputation, IP geolocation, IP fingerprinti
attacksurfacemapper
Tool that aims to automate the reconnaissance process.
autosint
Tool to automate common osint tasks.
aws-inventory
Discover resources created in an AWS account.
aztarna
A footprinting tool for ROS and SROS systems.
badkarma
Advanced network reconnaissance toolkit.
basedomainname
Tool that can extract TLD (Top Level Domain), domain extensions (Second Level Domain + TLD), domain name, and hostname f
bbot
Multipurpose scanner built to automate your Recon, Bug Bounties, and ASM.
bfac
An automated tool that checks for backup artifacts that may disclose the web-application's source code.
billcipher
Information Gathering tool for a Website or IP address.
bloodhound-python
Python data collector for Bloodhound legcacy (v4)
bridgekeeper
Scrape employee names from search engine LinkedIn profiles. Convert employee names to a specified username format.
catnthecanary
An application to query the canary.pw data set for leaked data.
ccrawldns
Retrieves from the CommonCrawl data set unique subdomains for a given domain name.
chaos-client
Go client to communicate with Chaos dataset API.
chronoleak
ICMP Timestamp Remote Time Leaker.
citadel
A library of OSINT tools.
cloud-buster
A tool that checks Cloudflare enabled sites for origin IP leaks.
cloudfail
Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network.
cloudlist
A tool for listing Assets from multiple Cloud Providers.
cloudmare
A simple tool to find origin servers of websites protected by CloudFlare with a misconfiguration DNS.
cloudunflare
Reconnaissance Real IP address for Cloudflare Bypass.
cr3dov3r
Search for public leaks for email addresses + check creds against 16 websites.
datasploit
Performs automated OSINT and more.
dga-detection
DGA Domain Detection using Bigram Frequency Analysis.
dns-parallel-prober
PoC for an adaptive parallelised DNS prober.
dnsbrute
Multi-theaded DNS bruteforcing, average speed 80 lookups/second with 40 threads.
dnscobra
DNS subdomain bruteforcing tool with Tor support through torsocks.
dnsgrep
A utility for quickly searching presorted DNS names.
dnsprobe
Allows you to perform multiple dns queries of your choice with a list of user supplied resolvers.
dnssearch
A subdomain enumeration tool.
dnsspider
A fast multithreaded bruteforcer of subdomains that leverages a wordlist and/or character permutation.
domain-analyzer
Finds all the security information for a given domain name.
domain-stats
A web API to deliver domain information from whois and alexa.
domained
Multi Tool Subdomain Enumeration.
domainhunter
Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing a
dradis-ce
An open source framework to enable effective information sharing.
elevate
Horizontal domain discovery tool you can use to discover other domains owned by a given company.
enum4linux-ng-git
A next generation version of enum4linux
enumerate-iam
Enumerate the permissions associated with an AWS credential set.
enumerid
Enumerate RIDs using pure Python.
exitmap
A fast and modular scanner for Tor exit relays.
eyewitness-git
designed to take screenshots of websites, provide some server header info, and identify default credentials is possible
facebot
A facebook profile and reconnaissance system.
fav-up
IP lookup by favicon using Shodan.
favfreak
Weaponizing favicon.ico for BugBounties , OSINT and what not.
fbid
Show info about the author by facebook photo url.
flashlight
Automated Information Gathering Tool for Penetration Testers.
forager
Multithreaded threat Intelligence gathering utilizing.
gasmask
All in one Information gathering tool - OSINT.
gatecrasher
Network auditing and analysis tool developed in Python.
geoedge
This little tools is designed to get geolocalization information of a host, it get the information from two sources (max
gh-dork
Github dorking tool.
ghunt
An offensive OSINT Google framework.
git-hound
Pinpoints exposed API keys on GitHub. A batch-catching, pattern-matching, patch-attacking secret snatcher.
git-wild-hunt
A tool to hunt for credentials in github wild AKA git*hunt.
gitdorker
Python program to scrape secrets from GitHub through usage of a large repository of dorks.
gitem
A Github organization reconnaissance tool.
gitgraber
Monitor GitHub to search and find sensitive data in real time for different online services.
githack
A `.git` folder disclosure exploit.
github-dorks
Collection of github dorks and helper tool to automate the process of checking dorks.
github-subdomains
Find subdomains on GitHub.
gitmails
An information gathering tool to collect git commit emails in version control host services.
gitminer
Tool for advanced mining for content on Github.
gitrecon
OSINT tool to get information from a Github and Gitlab profile and find user's email addresses leaked on commits.
go-windapsearch
Utility to enumerate users, groups and computers from a Windows domain through LDAP queries.
goddi
Dumps Active Directory domain information.
goodork
A python script designed to allow you to leverage the power of google dorking straight from the comfort of your command
goog-mail
Enumerate domain emails from google.
googlesub
A python script to find domains by using google dorks.
goohak
Automatically Launch Google Hacking Queries Against A Target Domain.
goop
Perform google searches without being blocked by the CAPTCHA or hitting any rate limits.
gosint
OSINT framework in Go.
gowitness-git
A golang web screenshot utility using Chrome Headless
grabing
Counts all the hostnames for an IP adress
graphinder
GraphQL endpoints finder using subdomain enumeration, scripts analysis and bruteforce.
gwtenum
Enumeration of GWT-RCP method calls.
hakrevdns
Small, fast tool for performing reverse DNS lookups en masse.
halcyon
A repository crawler that runs checksums for static files found within a given git repository.
hasere
Discover the vhosts using google and bing.
hatcloud
Bypass CloudFlare with Ruby.
hoper
Trace URL's jumps across the rel links to obtain the last URL.
howmanypeoplearearound
Count the number of people around you by monitoring wifi signals.
id-entify
Search for information related to a domain: Emails - IP addresses - Domains - Information on WEB technology - Type of Fi
idswakeup
A collection of tools that allows to test network intrusion detection systems.
infoga
Tool for gathering e-mail accounts information from different public sources (search engines, pgp key servers).
inquisitor
OSINT Gathering Tool for Companies and Organizations.
intelplot
OSINT Tool to Mark Points on Offline Map.
intrace-git
Traceroute-like application piggybacking on existing TCP connections
ip-tracer
Track and retrieve any ip address information.
ip2clue
A small memory/CPU footprint daemon to lookup country (and other info) based on IP (v4 and v6).
iptodomain
This tool extract domains from IP address based in the information saved in virustotal.
ipv666
Golang IPv6 address enumeration.
ircsnapshot
Tool to gather information from IRC servers.
isr-form
Simple html parsing tool that extracts all form related information and generates reports of the data. Allows for quick
ivre-docs
Network recon framework based on Nmap, Masscan, Zeek (Bro), Argus, Netflow,... (documentation)
ivre-web
Network recon framework based on Nmap, Masscan, Zeek (Bro), Argus, Netflow,... (web application)
jackdaw
Collect all information in your domain, show you graphs on how domain objects interact with each-other and how to exploi
jsearch
Simple script that grep infos from javascript files.
kacak
Tools for penetration testers that can enumerate which users logged on windows system.
kamerka
Build interactive map of cameras from Shodan.
keye
Recon tool detecting changes of websites based on content-length differences.
lanmap2
Passive network mapping tool.
ldapenum
Enumerate domain controllers using LDAP.
lft
A layer four traceroute implementing numerous other features.
lhf
A modular recon tool for pentesting.
linux-exploit-suggester-git
A Perl script that tries to suggest exploits based OS version number
linux-exploit-suggester.sh
Linux privilege escalation auditing tool.
littlebrother
OSINT tool to get informations on French, Belgian and Swizerland people.
loot
Sensitive information extraction tool.
machinae
A tool for collecting intelligence from public sites/feeds about various security-related pieces of data.
mail-crawl
Tool to harvest emails from website.
massbleed
SSL Vulnerability Scanner.
mdns-recon
An mDNS recon tool written in Python.
metabigor
Intelligence Tool but without API key.
metafinder
Search for documents in a domain through Search Engines (Google, Bing and Baidu). The objective is to extract metadata.
mildew
Dotmil subdomain discovery tool that scrapes domains from official DoD website directories and certificate transparency
monocle
A local network host discovery tool. In passive mode, it will listen for ARP request and reply packets. In active mode,
nasnum
Script to enumerate network attached storages.
necromant
Python Script that search unused Virtual Hosts in Web Servers.
neglected
Facebook CDN Photo Resolver.
netkit-bsd-finger
BSD-finger ported to Linux.
netkit-rusers
Logged in users; Displays who is logged in to machines on local network.
netkit-rwho
Remote who client and server (with Debian patches).
netscout
OSINT tool that finds domains, subdomains, directories, endpoints and files.
nohidy
The system admins best friend, multi platform auditing tool.
nsec3map
A tool to enumerate the resource records of a DNS zone using its DNSSEC NSEC or NSEC3 chain.
nsec3walker
Enumerate domain names using DNSSEC.
ntlmrecon-git
A tool to enumerate information from NTLM authentication enabled web endpoints.
ntp-ip-enum
Script to pull addresses from a NTP server using the monlist command. Can also output Maltego resultset.
nullinux
Tool that can be used to enumerate OS information, domain information, shares, directories, and users through SMB null s
omnibus
OSINT tool for intelligence collection, research and artifact management.
onioff
An onion url inspector for inspecting deep web links.
operative-framework
OSINT investigation framework
osint-spy
Performs OSINT scan on email/domain/ip_address/organization.
osinterator
Open Source Toolkit for Open Source Intelligence Gathering.
osintgram
OSINT tool offering an interactive shell to perform analysis on Instagram account of any users by its nickname.
parsero-git
A Robots.txt audit tool
pastemonitor
Scrape Pastebin API to collect daily pastes, setup a wordlist and be alerted by email when you have a match..
pdfgrab
Tool for searching pdfs withthin google and extracting pdf metadata.
pius-pi
Organizational asset discovery tool with 20+ plugins covering certificate transparency, passive DNS, and all 5 Regional
pmapper
A tool for quickly evaluating IAM permissions in AWS.
postenum
Clean, nice and easy tool for basic/advanced privilege escalation techniques.
protosint
Python script that helps you investigate Protonmail accounts and ProtonVPN IP addresses.
punter
Hunt domain names using DNSDumpster, WHOIS, Reverse WHOIS, Shodan, Crimeflare.
puredns
Fast domain resolver and subdomain bruteforcing with accurate wildcard filtering.
pwned
A command-line tool for querying the 'Have I been pwned?' service.
pwned-search
Pwned Password API lookup.
pwnedornot
Tool to find passwords for compromised email addresses.
pymeta
Auto Scanning to SSL Vulnerability.
python-api-dnsdumpster
Unofficial Python API for http://dnsdumpster.com/.
python-ivre
Network recon framework based on Nmap, Masscan, Zeek (Bro), Argus, Netflow,... (library)
python2-api-dnsdumpster
Unofficial Python API for http://dnsdumpster.com/.
python2-ivre
Network recon framework based on Nmap, Masscan, Zeek (Bro), Argus, Netflow,... (library)
python2-shodan
Python library and command-line utility for Shodan (https://developer.shodan.io).
quickrecon
A python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gather
raccoon
A high performance offensive security tool for reconnaissance and vulnerability scanning.
rdwatool
A python script to extract information from a Microsoft Remote Desktop Web Access (RDWA) application.
recon-ng-git
A full-featured Web Reconnaissance framework written in Python.
reconnoitre
A security tool for multithreaded information gathering and service enumeration.
reconscan
Network reconnaissance and vulnerability assessment tools.
recsech
Tool for doing Footprinting and Reconnaissance on the target web.
red-hawk
All in one tool for Information Gathering, Vulnerability Scanning and Crawling.
reverseip
Ruby based reverse IP-lookup tool.
revipd
A simple reverse IP domain scanner.
ridrelay
Enumerate usernames on a domain where you have no creds by using SMB Relay with low priv.
ripdc
A script which maps domains related to an given ip address or domainname.
rita
Real Intelligence Threat Analytics.
rusthound-ce
Active Directory data collector for BloodHound community edition (v5).
s3enum
Amazon S3 bucket enumeration.
scavenger
Crawler (Bot) searching for credential leaks on different paste sites.
screamer
Fast Subnet Discovery.
scylla
Find Advanced Information on a Username, Website, Phone Number, etc.
seekr
A multi-purpose OSINT toolkit with a neat web-interface.
server-status-pwn
A script that monitors and extracts requested URLs and clients connected to the service by exploiting publicly accessibl
shard
A command line tool to detect shared passwords.
shhgit
Find committed secrets and sensitive files across GitHub, Gists, GitLab and BitBucket or your local repositories in real
shodanhat
Search for hosts info with shodan.
shosubgo
Small tool to Grab subdomains using Shodan API.
simplyemail
Email recon made fast and easy, with a framework to build on CyberSyndicates.
sipi
Simple IP Information Tools for Reputation Data Analysis.
smbcrunch
3 tools that work together to simplify reconnaissance of Windows File Shares.
snscrape
A social networking service scraper in Python.
socialscan
Check email address and username availability on online platforms.
spfmap
A program to map out SPF and DKIM records for a large number of domains.
spoofcheck
Simple script that checks a domain for email protections.
spyse
Python API wrapper and command-line client for the tools hosted on spyse.com.
sr
Perform subdomain enumeration, endpoint recognition, and more.
ssl-hostname-resolver
CN (Common Name) grabber on X.509 Certificates over HTTPS.
stardox
Github stargazers information gathering tool.
subdomainer
A tool designed for obtaining subdomain names from public sources.
sublert
A security and reconnaissance tool which leverages certificate transparency to automatically monitor new subdomains depl
subscraper
Tool that performs subdomain enumeration through various techniques.
svn-extractor
A simple script to extract all web resources by means of .SVN folder exposed over network.
swamp
An OSINT tool for discovering associated sites through Google Analytics Tracking IDs.
syborg
Recursive DNS Subdomain Enumerator with dead-end avoidance system.
teamsuserenum
User enumeration with Microsoft Teams API
thedorkbox
Comprehensive collection of Google Dorks & OSINT techniques to find Confidential Data.
theharvester-git
Python tool for gathering e-mail accounts and subdomain names from different public sources (search engines, pgp key servers)
tilt
An easy and simple tool implemented in Python for ip reconnaissance, with reverse ip lookup.
tinfoleak
Get detailed information about a Twitter user activity.
tinfoleak2
The most complete open-source tool for Twitter intelligence analysis.
treasure
Hunt for sensitive information through githubs code search.
trusttrees
A Tool for DNS Delegation Trust Graphing.
ubiquiti-probing
A Ubiquiti device discovery tool.
udork
Bash script that uses advanced Google search techniques to obtain sensitive information in files or directories, find Io
uhoh365
Script to enumerate Office 365 users without performing login attempts
uncover
Discover exposed hosts on the internet using multiple search engines.
userrecon
Find usernames across over 75 social networks.
vbrute
Virtual hosts brute forcer.
vpnpivot
Explore the network using this tool.
waldo
A lightweight and multithreaded directory and subdomain bruteforcer implemented in Python.
waybackurls
Fetch all the URLs that the Wayback Machine knows about for a domain.
waymore
Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan & VirusTotal.
websearch
Search vhost names given a host range. Powered by Bing..
weebdns
DNS Enumeration with Asynchronicity.
whoxyrm
A reverse whois tool based on Whoxy API.
windapsearch
Script to enumerate users, groups and computers from a Windows domain through LDAP queries.
windows-exploit-suggester
This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential miss
xray
A tool for recon, mapping and OSINT gathering from public networks.
zeus-scanner
Advanced dork searching utility.
zgrab
Grab banners (optionally over TLS).