
awesome-hacker-search-engines — Updated!
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
Awesome Hacker Search Engines
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
General • Servers • Vulnerabilities • Exploits • Attack surface • Code • Email addresses • Domains • URLs • DNS • Certificates • WiFi networks • Device Info • Credentials • Leaks • Hidden Services • Social Networks • Phone numbers • Images • Threat Intelligence • Web History • Files • Surveillance cameras • Crypto • People • Vehicle
General Search Engines
- Bing
- Yahoo!
- Yandex
- Ask
- Baidu
- SearXNG
- EXALead
- DuckDuckGo
- Swisscows
- Naver
- AOL
- Brave
- Yep
- Gibiru
- Kagi
- Stract
Servers
- Shodan - Search Engine for the Internet of Everything
- Censys Search - Search Engine for every server on the Internet to reduce exposure and improve security
- Onyphe.io - Cyber Defense Search Engine for open-source and cyber threat intelligence data
- ZoomEye - Global cyberspace mapping
- GreyNoise - The source for understanding internet noise
- Natlas - Scaling Network Scanning
- Netlas.io - Discover, Research and Monitor any Assets Available Online
- FOFA - Cyberspace mapping
- Quake - Cyberspace surveying and mapping system
- Hunter - Internet Search Engines For Security Researchers
- ODIN - One of the most powerful search engines for Scanned Internet Assets
- Modat Magnify - The Largest Internet Device DNA Dataset Available
Vulnerabilities
- NIST NVD - US National Vulnerability Database
- MITRE CVE - Identify, define, and catalog publicly disclosed cybersecurity vulnerabilities
- GitHub Advisory Database - Security vulnerability database inclusive of CVEs and GitHub originated security advisories
- cloudvulndb.org - The Open Cloud Vulnerability & Security Issue Database
- osv.dev - Open Source Vulnerabilities
- Vulners.com - Your Search Engine for Security Intelligence
- opencve.io - Easiest way to track CVE updates and be alerted about new vulnerabilities
- security.snyk.io - Open Source Vulnerability Database
- Mend Vulnerability Database - The largest open source vulnerability DB
- Rapid7 - DB - Vulnerability & Exploit Database
- CVEDetails - The ultimate security vulnerability datasource
- VulnIQ - Vulnerability intelligence and management solution
- SynapsInt - The unified OSINT research tool
- Aqua Vulnerability Database - Vulnerabilities and weaknesses in open source applications and cloud native infrastructure
- Vulmon - Vulnerability and exploit search engine
- VulDB - Number one vulnerability database
- ScanFactory - Realtime Security Monitoring
- Trend Micro Zero Day Initiative - Publicly disclosed vulnerabilities discovered by Zero Day Initiative researchers
- Google Project Zero - Vulnerabilities including Zero Days
- Trickest CVE Repository - Gather and update all available and newest CVEs with their PoC
- cnvd.org.cn - Chinese National Vulnerability Database
- InTheWild.io - Check CVEs in our free, open source feed of exploited vulnerabilities
- Vulnerability Lab - Vulnerability research, bug bounties and vulnerability assessments
- Red Hat Security Advisories - Information about security flaws that affect Red Hat products and services in the form of security advisories
- Cisco Security Advisories - Security advisories and vulnerability information for Cisco products, including network equipment and software
- Microsoft Security Response Center - Reports of security vulnerabilities affecting Microsoft products and services
- VARIoT - VARIoT IoT Vulnerabilities Database
- Lambda Watchdog - Your CVE dashboard for AWS Lambda
- cvefeed.io - Comprehensive and up-to-date feed of the latest CVEs, security advisories, and other vulnerabilities
- CVE Crowd - Keep track of actively discussed CVEs and integrate them into your application or business
- Wiz Vulnerability Database - A comprehensive resource for monitoring high-profile vulnerabilities in cloud environments, tailored for security teams and cloud professionals
- Shodan CVEDB - The CVEDB API offers a quick way to check information about vulnerabilities in a service
- Vulert - Recent security issues found in open-source packages
- promptfoo.dev Language Model Security Database - A comprehensive collection of LLM vulnerabilities, curated from cutting-edge research papers and real-world discoveries
- opencryptography.com - Free public database of 10,000+ unique Docker image scans for hidden cryptographic assets and critical implementation flaws
- pathfinding.cloud - Comprehensive, community-maintained library documenting AWS IAM privilege escalation paths
- BaseFortify.eu - Monitor software vulnerabilities with CVE matching, exploit risk alerts, and mitigation guidance