
discover — Updated!
Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload creation using Metasploit. For use with Kali Linux and Ubuntu.
Discover
Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload creation using Metasploit. For use with Ubuntu. Limited support for Kali Linux.
Setup and usage
- Download to your home directory.
cd ~
git clone https://github.com/leebaird/discover
cd discover/
./discover.sh
- On first run, Discover asks for your first name (max 10 letters) and saves it to
~/.discover/operator-name. That name is written on every engagement audit log line. To change it later, edit or delete that file and restart Discover. - Select main menu option 18 Update to update the operating system and install dependencies.
- Some options require root credentials to run.
Optional shell helpers (config/zshrc)
cd ~/discover/config/
./install.sh
| Host | What install.sh does |
|---|---|
| Ubuntu / other (incl. macOS) | Copies zshrc to ~/.bash_aliases and sources it |
Kali (detected via /etc/os-release) | Appends zshrc to ~/.zshrc |
Also installs tmux.conf to ~/.tmux.conf and vimrc to ~/.vimrc.
Useful commands (after install / new shell):
| Command | Purpose |
|---|---|
n | Network summary (external/internal IP, DNS, MAC, iface; ss without TIME-WAIT; ping 8.8.8.8) |
s | cd ~/discover and short git status (no pull) |
m / ms | Start MSF DB + console / stop MSF DB |
web / web2 | HTTP server on port 80 (sudo) / 8000 |
now | Formatted date/time (does not override date) |
update | Grok update + full apt upgrade chain |
bh, th, smb, sip | BloodHound, theHarvester, smbserver, IP sort |
Network identity (IPs, DNS, MAC) is computed when you run n / web / upload — not at shell startup — so new shells stay fast and values stay current after VPN/wifi changes.
Notes
- On Ubuntu and other non-Kali hosts, re-running overwrites
~/.bash_aliaseswith the repo copy. - On Kali, re-running
install.shappends again and can duplicate the block; edit~/.zshrcor install only once. - Default zsh on macOS/Kali does not load
~/.bash_aliasesunless you source it from~/.zshrc.
Main menu
RECON
1. Domain
2. Person
SCANNING
3. Generate target list
4. CIDR
5. List
6. IP, range, or URL
7. Rerun Nmap scripts and MSF aux
WEB
8. Insecure direct object reference
9. Open multiple tabs in Firefox
10. Nikto
11. SSL
MISC
12. Generate a malicious payload
13. Start a Metasploit listener
14. CVE lookup
15. Parse XML
16. Dev
17. Notes
18. Update
19. Exit
RECON
Domain
RECON
1. Passive
2. Breaches
3. Find registered domains
4. Google dorks
5. Web search
6. Active
7. Open report
8. Previous menu
Note: Passive and Active cannot be run as root.
Engagement workflow
- Passive — build
$HOME/data/<domain>/HTML report. - Open report (or finish Active) so the engagement is on statusd.
- Audit > Import — names, names/titles/emails, subdomains, or another operator’s package into the current report.
- Active — httpx / whatweb / gowitness; Active and Subdomains pages; optional NVD CVSS.
- Shodan (optional) — Active page Enrich (Shodan checkbox).
- Software filter on Active, then filtered Subdomains, then host scans in operator mode.
- Export — on Report > Audit (Discover-hosted only): Client, Defender, or Operator package.
Passive recon
Uses Amass, ARIN, DNSRecon, dnstwist, Metasploit, subfinder, sublist3r, Shodan CTL (free CT hostnames; no API key), theHarvester, Whois, and multiple websites.
- Acquire free API keys for maximum results with theHarvester (
$HOME/.theHarvester/api-keys.yaml). - Passive builds an HTML report at
$HOME/data/<domain>/. - Find registered domains updates
pages/registered-domains.htmin an existing report. - HTML Reports menu: Passive, Active, and Audit.
- Names: US public companies pull DEF 14A / Form 4 from SEC EDGAR.
- Summary: HQ from 10-K then website footer (
tools/company-manual.tsvoverride); social profile links when found.
Import
On Reports > Audit, Import (Discover-hosted only) targets the current engagement.
| Choice | What it does |
|---|---|
| Operator scans | Merge another operator’s unpacked report (host-scans, screenshots, Active data, their audit lines) |
| Names | Merge tools/names-manual.tsv (Name, Title, Phone; # comments; filled title/phone win) |
| Names, titles, and emails | Merge an external names dump into Names and Emails |
| Subdomains | Existing sources (Firefox / Pentest-Tools / TSV) or CSV subdomain,ip,category; optional Active on new public hosts |
CLI (same backends):
bash recon/import-names.sh --report /home/user/data/example.com --json
bash recon/import-names-titles-emails.sh --report /home/user/data/example.com --source /path/to/dump --json
bash recon/import-subdomains.sh --report /home/user/data/example.com \
--mode team-csv --import /home/user/team-hosts.csv --json
# existing: --mode existing --import firefox|/path/to/export
# optional CSV: --run-active
CSV list skips hosts already in tools/subdomains. Empty IP then dig. Category: Discover rules first, else CSV. Never writes recon/subdomain-categories.tsv.
Active
Domain menu option 6. Run after Passive (and optionally Import subdomains).
Enter the location of a previous Discover scan:
/home/user/data/example.com
- Reads public hostnames from
tools/subdomains(stored RFC1918 skipped). dig A @1.1.1.1before httpx. A private, loopback, link-local, or0.0.0.0answer is left out of httpx and added totools/private-subs(tools/dns-private.tsv). The stored public IP is not changed. VPN DNS is not used.- httpx (
tools/httpx.jsonl); alive = 200–399, 401, 403, or 405. - whatweb + gowitness on alive URLs; merge with
recon/active-tech.py. - Re-run Active to replace those artifacts and rebuild Active / Subdomains.
Artifacts live under tools/ (httpx.jsonl, whatweb.json, gowitness/, software-cves-cache.json).
Software filter and host scans
In operator mode only (report opened via Open report / Active at http://127.0.0.1:17322/…), Subdomains public rows with an HTTP status get a host-scan expand control (also on ?software= / ?cve= filtered views). Manual file:// open never shows chevrons. Expandable rows show host-scan boxes (quietest to loudest):