Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
opensquat — OSINT tool that detects domain squatting, typosquatting, and phishing look-alikes by monitoring newly registered domains against brand keywords with DNS and VT validation. | Kitploit
Tools/GitHubGitHub/atenreiro/opensquat
OSINT (Open Source Intelligence)Information GatheringPhishingThreat IntelligenceDNS Analysis
GitHubatenreiro/opensquat

opensquat

OSINT tool that detects domain squatting, typosquatting, and phishing look-alikes by monitoring newly registered domains against brand keywords with DNS and VT validation.

View Repository
980160632 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

openSquat Logo

openSquat Core

Python 3.10+ License: GPL v3 GitHub issues GitHub stars


📑 Table of Contents

  • What is openSquat?
  • Featured In
  • Open-Core Model
  • Key Features
  • Quick Start
  • Requirements
  • Usage
  • Premium and API Modes
  • Configuration
  • Automation
  • CLI Reference
  • Contributing
  • Author
  • License

🎯 What is openSquat?

openSquat is an Open Source Intelligence (OSINT) security tool that identifies cyber squatting threats targeting your brand or domains:

Threat TypeDescription
🎣 PhishingFraudulent domains mimicking your brand
🔤 TyposquattingDomains with common typos (e.g., gooogle.com)
🌐 IDN HomographLook-alike characters from other alphabets
👥 DoppelgängerDomains containing your brand name
🔀 BitsquattingSingle-bit errors in domain names

🌟 Featured In

"A powerful swiss army knife for brand protection" — WhoisXML API Blog, August 2022

"A tool with insane power to fight typosquatting and all related types of cyber mischief." — WhoisXML API Blog, August 2022

"A handy tool for collecting information on newly registered domains." — ranked Top 5 phishing detection tool — SOCRadar Blog, July 2022

"openSquat provides essential protection against domain squatting and phishing attacks through automated monitoring and detection." — Prince Yadav, TutorialsPoint, March 2026

Academic Citation

"OpenSquat identified 103 squatting domains, 960 active phishing websites, and 53 domains with suspicious certificates." — Sharma et al., Journal of Information Security and Cybercrimes Research (JISCR), Vol. 7, Issue 1, June 2024


🔓 Open-Core Model

openSquat follows an open-core model:

  • Core detection engine — Open source and community-driven
  • Advanced capabilities — Delivered through commercial intelligence services

This model enables transparency and community collaboration while supporting the scale, reliability, and operational requirements of enterprise use.


✨ Key Features

  • 📅 Daily NRD feeds — Automatic newly registered domain updates
  • 🔍 Similarity detection — Levenshtein distance algorithm
  • 🔓 Three operating modes — Community (free feed), Premium Feed (paid feed, same local pipeline), or Premium API (hosted lookalike service). The two Premium modes share a single openSquat API key — see Premium and API Modes.
  • 🛡️ VirusTotal integration — Check domain reputation
  • 🌐 Quad9 DNS validation — Identify malicious domains
  • 📜 Certificate Transparency — Monitor SSL/TLS certificates
  • 📊 Multiple output formats — TXT, JSON, CSV

🚀 Quick Start

Install via pip (recommended)

pip install opensquat
opensquat -k keywords.txt

Or clone the repository

git clone https://github.com/atenreiro/opensquat
cd opensquat
pip install -r requirements.txt
python3 opensquat.py -k keywords.txt

Repo users: in all the examples below, replace opensquat with python3 opensquat.py to run from a cloned checkout.


📦 Requirements

  • Python 3.10+
  • Dependencies: confusable_homoglyphs, homoglyphs, colorama, requests, dnspython, beautifulsoup4

📖 Usage

Basic Commands

# Default run
opensquat

# Show all options
opensquat -h

# Use custom keywords file
opensquat -k my_keywords.txt

Validation Options

# DNS validation via Quad9
opensquat --dns

# Check Certificate Transparency logs
opensquat --ct

# Scan for open ports (80/443)
opensquat --portcheck

# Cross-reference phishing databases
opensquat --phishing results.txt

Output Formats

# Save as JSON
opensquat -o results.json -t json

# Save as CSV
opensquat -o results.csv -t csv

Confidence Levels

LevelFlagDescription
0-c 0Very high (fewer results, high accuracy)
1-c 1High (default)
2-c 2Medium
3-c 3Low
4-c 4Very low (more results, more false positives)

Note: On the API side (--api), the five confidence levels map to four fuzziness values (exact, low, auto, high) — -c 3 and -c 4 both map to high. See Premium and API Modes for the full mapping and how to override with --api-fuzziness.


💎 Premium and API Modes

openSquat supports three modes. The default (Community) is unchanged — existing users need no flags. The two Premium modes share a single openSquat API key; pick Premium Feed if you want the same local detection pipeline with a larger feed, or Premium API if you want server-side detection with no local feed download.

ModeFlagWhat it does
Community (default)(none)Downloads the free NRD feed (~100k domains/day) and runs local Levenshtein detection.
Premium Feed--premiumDownloads the paid NRD feed (nrd-lite, much larger) using your openSquat API key, then runs the same local Levenshtein detection.
Premium API--apiSkips local feed download. Queries the openSquat lookalike REST API per keyword and returns server-side matches.

Get an API key

Sign up at opensquat.com to get a key. The same key works for both Premium Feed (--premium) and Premium API (--api).

Provide the API key (priority order)

  1. --api-key YOUR_KEY on the command line
  2. OPENSQUAT_API_KEY environment variable
  3. api_key.txt in the current directory (one key per file, # comments allowed)

The CLI flag is visible in ps output. Prefer the env var or key file in shared environments.

Examples

# Premium Feed mode — same local pipeline, larger feed
export OPENSQUAT_API_KEY=os_xxxxxxxxxxxx
opensquat -k keywords.txt --premium

# Premium API mode — server-side detection per keyword
opensquat -k keywords.txt --api

# Premium API + DNS reputation check on each returned domain
opensquat -k keywords.txt --api --dns

# Premium API with JSON output grouped by keyword
opensquat -k keywords.txt --api -t json -o results.json

# Tune the Premium API search
opensquat -k keywords.txt --api --api-fuzziness high --api-history-days 7 --api-max-results 200
Download Tool