
OSINT reconnaissance tool for network discovery, subdomain enumeration, IP enrichment, and secret detection via certificate logs, Shodan, and GitHub code search—all without API keys.
Metabigor - OSINT power without API key hassle
Metabigor maps a target's infrastructure without asking you to register for a single API key. Network ranges, certificates, related domains, exposed ports, CDN vendors, and code leaks - all from free sources, all pipeable into each other.
npm install -g @j3ssie/metabigor # macOS, Linux, Windows
brew install j3ssie/tap/metabigor # macOS, Linux
Both ship the same prebuilt binary for your platform - no Go toolchain needed.
Or build from source:
git clone https://github.com/j3ssie/metabigor.git
cd metabigor
make build # binary at ./bin/metabigor
Or download a binary from the releases page.
metabigor net AS13335 # network ranges behind an ASN
metabigor cert hackerone.com # subdomains from certificate logs
metabigor ip 1.1.1.1 # open ports and CVEs for an IP
metabigor related tesla.com # other domains the target owns
metabigor cdn --exclude -I ips.txt # candidate origin servers
The same conventions apply everywhere, so once you learn one command you know them all.
metabigor cert example.com # as an argument
metabigor cert example.com tesla.com # several arguments
metabigor cert -i example.com # with -i
metabigor cert -I domains.txt # from a file, one per line (# comments are ignored)
cat domains.txt | metabigor cert # on stdin
They combine, and the merged list is deduplicated:
metabigor cluster 1.1.1.1 -i 8.8.8.8 -I more-ips.txt
Arguments are the shortest path and work on every command. Reach for -i when the target would
otherwise look like a flag, or when a script builds the command for you:
metabigor github -i "--endpoint-url"
metabigor net --input "$TARGET" -f json
Stdin is only read when no target was given any other way, so metabigor net AS13335 never blocks
waiting on input inside a script or CI job.
-f/--format works on every command:
| Format | What you get | Use it for |
|---|---|---|
text (default) | Readable columns | Reading in a terminal |
flat | The bare primary value | Piping into other tools |
json | One JSON object per line | jq, automation |
csv | Rows behind one header | Spreadsheets, reports |
metabigor ip 1.1.1.0/28 # 1.1.1.1 | 80,443 | one.one.one.one
metabigor ip 1.1.1.0/28 -f flat # 1.1.1.1:80
metabigor ip 1.1.1.0/28 -f json # {"ip":"1.1.1.1","ports":[80,443],...}
metabigor ip 1.1.1.0/28 -f csv -o ports.csv
Results always go to stdout and logs always go to stderr, so pipes stay clean at any log level.
-o writes results to a file as well, overwriting it unless you pass --append. The file is
only rewritten once there is a result to write, so a run that fails or finds nothing leaves the
previous results intact.
metabigor net AS13335 -f flat | metabigor ip -f flat
metabigor related tesla.com -f flat | metabigor cert
cat domains.txt | dnsx -silent -resp-only | metabigor cdn --exclude
net - Network DiscoveryFind the CIDRs behind an ASN, IP, domain, or organization. Uses the bundled offline database.
metabigor net AS13335 # every CIDR announced by an ASN
metabigor net 1.1.1.1 --detail # which ASN owns this IP
metabigor net --org Cloudflare # search by company name
metabigor net --live tesla.com # query live sources instead of the local DB
metabigor net -I asn-list.txt -f csv -o ranges.csv
The target type is auto-detected. Override it with --asn, --ip, --domain, or --org
(mutually exclusive). --detail adds ASN, organization, and country columns.
cert - Certificate Transparencymetabigor cert hackerone.com # one domain per line
metabigor cert "HackerOne Inc" # search by organization
metabigor cert example.com --clean # strip the *. from wildcards
metabigor cert example.com --wildcard # only wildcard entries
metabigor cert example.com --detail # cert IDs, issuers, validity dates
metabigor cert tesla.com | dnsx -silent
ip - IP Enrichment (Shodan InternetDB)metabigor ip 1.1.1.1 # ports, hostnames, CVEs
metabigor ip 1.1.1.0/28 # CIDRs expand to hosts
metabigor ip 1.1.1.0/28 -f flat # IP:PORT pairs
metabigor ip -I ips.txt -c 30 -f csv -o ports.csv
IPs InternetDB knows nothing about are skipped; pass --all to keep them.
github - Code Search (grep.app)metabigor github hackerone.com # repo and path per match
metabigor github tesla.com --subs # only subdomains found in matches
metabigor github "api_key=" --detail # show the matching code
metabigor github AKIA --pages 3 --detail
Requires Chrome or Chromium - grep.app answers plain HTTP clients with a bot challenge.
Searches run one at a time regardless of -c, to respect grep.app's rate limit.
cluster - IP ClusteringGroup IPs by the ASN that owns them, largest cluster first. Accepts IPs or CIDRs. Works offline.
cat ips.txt | metabigor cluster
metabigor cluster -I ips.txt -f csv -o clusters.csv
cat domains.txt | dnsx -silent -resp-only | metabigor cluster
related - Related Domain Discoverymetabigor related hackerone.com # all sources
metabigor related tesla.com --sources crt
metabigor related tesla.com --sources crt,whois
Sources: crt (crt.sh), whois (viewdns.info reverse WHOIS), analytics (shared Google
Analytics / Tag Manager IDs), or all. Results are deduplicated across sources and tagged with
the source that found them first.
url - URL Collection from Web Archives