
CloakQuest3r
Open-source security research tool for identifying origin IP exposure of websites protected by Cloudflare and similar reverse proxy services.
Tools for discovering subdomains and DNS records associated with target domains.

Open-source security research tool for identifying origin IP exposure of websites protected by Cloudflare and similar reverse proxy services.

A BASH Script to automate the installation of the most popular bug bounty tools

Bash-based fuzzing tool that leverages Google Dorking for stealthy enumeration of directories, files, subdomains, and parameters without direct…

AlienTec-Recon-Tool

OSINT Graph Investigation Application

An #OSINT Framework to perform various recon techniques on Companies, People, Phone Number, Bitcoin Addresses, etc., aggregate all the raw data, and…

Passive subdomain discovery tool that aggregates results from multiple online sources via CLI, supporting stdin/stdout, JSONL output, and API key…

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines,…

A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and…

Stuff that doesn't deserves its own repository.

MCP server exposing multiple OSINT tools for AI assistants like Claude

Bash-based domain availability checker that scans WHOIS records across multiple TLDs to find unregistered domains for red teaming and phishing…

Command-line tool for discovering SaaS platforms a company uses via DNS enumeration

Command-line tool for discovering SaaS platforms a company uses via DNS enumeration

Takeover subdomains using AWS dangling elastic ips and have a working POC for Subdomain Takeover.


Subdomains analysis and generation tool. Reveal the hidden!