Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/edoverflow/contact.sh
OSINT (Open Source Intelligence)ReconnaissanceVulnerability AnalysisInformation Gathering
GitHubedoverflow/contact.sh

contact.sh

An OSINT tool to find contacts in order to report security vulnerabilities.

View Repository
268486 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
contact.sh — An OSINT tool to find contacts in order to report security vulnerabilities. | Kitploit

contact.sh

An OSINT tool to find contacts in order to report security vulnerabilities.

image

Buy Me A Coffee

Installation

🐧 GNU/Linux

Make sure you have installed the whois and jq packages.

root@kitploit:~
$ git clone https://github.com/EdOverflow/contact.sh.git
$ cd contact.sh/
$ chmod u+x contact.sh
$ ./contact.sh -d google.com -c google

🍎 OSX

root@kitploit:~
$ brew install gnu-sed --with-default-names
$ brew install jq
$ git clone https://github.com/EdOverflow/contact.sh.git
$ cd contact.sh/
$ chmod u+x contact.sh
$ ./contact.sh -d google.com -c google

Usage

root@kitploit:~
$ ./contact.sh


 _  _ __ _|_ _  _ _|_    _ |_ 
(_ (_)| | |_(_|(_  |_ o _> | |
            ---
        by EdOverflow


[i] Description: An OSINT tool to find contacts in order to report security vulnerabilities.
[i] Usage: ./contact.sh [Options] use -d for hostnames (-d example.com), -c for vendor name (-c example), and -f for a list of hostnames in a file (-f domains.txt) 
[i] Example: ./contact.sh -d google.com -c google

Use the -d flag when trying to find addresses linked to a domain. contact.sh will return a "Confidence level" based on the source of the information retrieved. A security.txt file located on the domain will have a higher priority than a Twitter account on the company's website.

root@kitploit:~
$ ./contact.sh -d google.com

The -c flag allows you to specify the company's name.

root@kitploit:~
$ ./contact.sh -c google

If the company's name contains spaces, make sure to place the name inside quotes.

root@kitploit:~
$ ./contact.sh -c "keeper security"

You can check a list of domains using the -f flag.

root@kitploit:~
$ ./contact.sh -f domains.txt

For the best results, combine both flags as follows:

root@kitploit:~
$ ./contact.sh -d google.com -c google

contact.sh abides by the target's robots.txt file.

root@kitploit:~
$ ./contact.sh -d linkedin.com


 _  _ __ _|_ _  _ _|_    _ |_ 
(_ (_)| | |_(_|(_  |_ o _> | |
            ---
        by EdOverflow


[+] Finding security.txt files 
 | Confidence level: ★ ★ ★ 
[!] The robots.txt file does not permit crawling this hostname.

[+] Checking HackerOne's directory for hostname 
 | Confidence level: ★ ★ ★ 
https://hackerone.com/linkedin

Contributing

I welcome contributions from the public.

Using the issue tracker 💡

The issue tracker is the preferred channel for bug reports and features requests.

Issues and labels 🏷

The bug tracker utilizes several labels to help organize and identify issues.

Guidelines for bug reports 🐛

Use the GitHub issue search — check if the issue has already been reported.

Download Tool