Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Nuke.sh — Bash-based passive reconnaissance + attack surface mapping script using only public APIs + stock Linux tools (curl, dig, openssl, nmap, python3). | Kitploit
Tools/GitHubGitHub/ankhcorp/nuke.sh
OSINT (Open Source Intelligence)ReconnaissanceNetwork MappingPort ScanningVulnerability AnalysisDNS & Subdomain EnumerationInformation GatheringWeb SecurityPenetration TestingSubdomain EnumerationDNS Analysis
410h 36m agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
ankhcorp/nuke.sh

Nuke.sh

Bash-based passive reconnaissance + attack surface mapping script using only public APIs + stock Linux tools (curl, dig, openssl, nmap, python3).

View Repository

NUKE - Recon & Attack Surface Mapper

 _   _ _   _ _  _______
| \ | | | | | |/ / ____|
|  \| | | | | ' /|  _|
| |\  | |_| | . \| |___
|_| \_|\___/|_|\_\_____|

      N U K E  //  recon & attack surface mapper
      -----------------------------------------

Bash-based passive reconnaissance + attack surface mapping script using only public APIs + stock Linux tools (curl, dig, openssl, nmap, python3).

All output goes to a single .txt file: nuke_<domain>.txt.

No dependency on subfinder, ffuf, gobuster, subjs, getJS, jshunter, or js_snitch.


✨ What it does

#ModuleSource / Technique
1Subdomains via CTcrt.sh
2Subdomains via alternate CTcrt.name
3Subdomains (optional, requires key)SecurityTrails API
4Subdomains + URLs + IPsOTX AlienVault
5Domains + IPs + ASN/Serverurlscan.io
6Subdomains + siblings + IPs (requires key)VirusTotal v2
7Consolidated subdomainsUnion + dedupe across all sources
8DNS (TXT/SPF, A, AAAA, NS, MX, SOA + AXFR)dns.google (DoH) + dig/host — equivalent to dnsrecon -d
9WHOISRDAP via rdap.org
10IPs / Reverse DNS / RDAP-IP / HTTP statusdns.google PTR + rdap.org/ip + curl -I
11Favicon hash (Shodan hunting) + IP SSL verificationLocal Shodan-standard murmur3 (http.favicon.hash) + openssl + nmap --script ssl-cert
12JS files + extracted endpoints<script src> parsing + path/URL regex (replaces subjs/getJS/jshunter)
13Historical URLsWayback Machine CDX
14Origin IP discovery (CDN/WAF bypass)Correlates DNS + OTX + urlscan + VT + SPF + Shodan, filters via RDAP org + Host: header test
15Built-in dirscanHigh-signal curated wordlist, parallel (no ffuf/gobuster needed)

Highlights:

  • 🔍 Real-IP discovery behind Cloudflare/Akamai/WAF via SPF, VT siblings, OTX, urlscan, favicon hash, and SSL cert.
  • 🍕 Shodan-standard favicon hash computed locally in pure Python (no pip install), with ready-to-use dorks: http.favicon.hash:X.
  • 📜 SPF breakdown (ip4:/include:/a/mx) — leaks infra / origin IP.
  • 🕸️ Wayback with bug-bounty filter (?api=, admin, token, .bak, .sql, .env, .git).
  • 📁 Focused dirscan: .git/HEAD, .env, backup.zip, phpinfo.php, actuator/env, swagger/, graphql, jenkins/, etc.

⚙️ Requirements

  • bash, curl, grep, sed, awk, sort, tr
  • Optional (auto-detected):
    • dig or host → for AXFR
    • python3 → for favicon murmur3 hash (Shodan standard)
    • nmap → for nmap --script ssl-cert -p 443 <IP>
    • openssl → for cert CN/SAN inspection

Works on Kali, Ubuntu, Debian, WSL2.

🚀 Installation

git clone https://github.com/AnkhCorp/Nuke.sh.git
cd Nuke.sh
chmod +x nuke.sh

▶️ Usage

# Basic (100% free, no keys)
bash nuke.sh example.com

# With keys (via arguments)
bash nuke.sh example.com SECURITYTRAILS_KEY VIRUSTOTAL_KEY

# With keys via env (recommended — never commit keys)
export SECURITYTRAILS_API_KEY="your_key"
export VT_APIKEY="your_key"
export SHODAN_API_KEY="your_key"    # optional
export ZOOMEYE_KEY="your_key"       # optional
bash nuke.sh example.com

Supported environment variables:

VariableRequired?Where to get it
SECURITYTRAILS_API_KEYNohttps://securitytrails.com/app/signup
VT_APIKEYNohttps://www.virustotal.com/gui/my-apikey
SHODAN_API_KEYNohttps://account.shodan.io
ZOOMEYE_KEYNohttps://www.zoomeye.hk
URLSCAN_SIZENo (default 1000)E.g. export URLSCAN_SIZE=10000 for max

Output:

nuke_example.com.txt

📄 Sample output

===================================================================
== 7. CONSOLIDATED SUBDOMAINS (all sources)
===================================================================

crt.sh=45 | crt.name=38 | securitytrails=52 | otx=20 | urlscan=15 | virustotal=30
[UNIQUE total]: https://raw.githubusercontent.com/ankhcorp/nuke.sh/main/87

admin.example.com
api.example.com
...
===================================================================
== 14. ORIGIN IP DISCOVERY (consolidated)
===================================================================

[All candidate IPs (current DNS + OTX + urlscan + VT + SPF + Shodan)]:
https://raw.githubusercontent.com/ankhcorp/nuke.sh/main/1.2.3.4
5.6.7.8
...
IP: 1.2.3.4 | RDAP_ORG: CLOUDFLARENET
IP: 5.6.7.8 | RDAP_ORG: LOCAWEB

🔎 Useful dorks & links (generated by the script)

# Shodan — certificate
shodan search 'Ssl.cert.subject.CN:"example.com" 200 --fields ip_str'

# Shodan — favicon
shodan search 'http.favicon.hash:123456789'

# ZoomEye
ssl:"example.com"   # at https://www.zoomeye.hk/

# Manual
https://crt.name/v1/search?apex=example.com
https://favicon-hash.kmsec.uk/
https://viewdns.info/iphistory/?domain=example.com
https://mxtoolbox.com/SuperTool.aspx
https://urlscan.io/search/#domain:example.com

Manual verification of an origin-IP candidate:

curl -sk -H 'Host: example.com' https://<CANDIDATE_IP>/ | head -n 20
echo | openssl s_client -connect <CANDIDATE_IP>:443 -servername example.com 2>/dev/null | openssl x509 -noout -subject -ext subjectAltName
nmap --script ssl-cert -p 443 <CANDIDATE_IP>

If the cert answers with CN/SAN=example.com (or title/Server matches the site), that's the real IP.

🧠 Why not subfinder / webanalyze / ffuf?

ToolReplacement reason
subfinderReplaced by crt.sh + crt.name + OTX + urlscan + VT + SecurityTrails (all via API, nothing to install)
webanalyzeReliable tech detection requires a paid API (Wappalyzer/BuiltWith) — out of scope
subjs / getJSReplaced by built-in <script src> extraction (section 12)
jshunterReplaced by built-in endpoint regex (section 12)
js_snitchNo public-API equivalent
dnsrecon -dEquivalent in section 8 (NS/MX/SOA/AXFR via DoH + dig)
httpx-toolkitPartial equivalent in section 10 (status/server per host)
ffuf / gobusterBuilt-in dirscan with curated wordlist + xargs -P (section 15) — for full fuzzing use SecLists: ffuf -u https://TARGET/FUZZ -w raft-medium-directories.txt

⚠️ Legal disclaimer

Use only against targets you are authorized to test (your own assets, in-scope bug bounty programs, contracted pentests).

The author is not responsible for misuse.

📝 License

MIT — use, modify, and share freely.

🤝 Contributing

PRs are welcome! Roadmap ideas:

  • Chaos ProjectDiscovery API support
  • JSON export in addition to TXT
  • --only-ips / --only-subs flags
  • Passive amass / anubis integration
Download Tool