Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
metabigor — OSINT reconnaissance tool for network discovery, subdomain enumeration, IP enrichment, and secret detection via certificate logs, Shodan, and GitHub code search—all without API keys. | Kitploit
Tools/GitHubGitHub/j3ssie/metabigor
OSINT (Open Source Intelligence)ReconnaissanceNetwork MappingVulnerability AnalysisDNS & Subdomain EnumerationInformation GatheringPenetration TestingSecret DetectionSubdomain Enumeration
GitHubj3ssie/metabigor

metabigor

OSINT reconnaissance tool for network discovery, subdomain enumeration, IP enrichment, and secret detection via certificate logs, Shodan, and GitHub code search—all without API keys.

View Repository
1.7k201261 month agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Metabigor
Metabigor - OSINT power without API key hassle


What is Metabigor?

Metabigor maps a target's infrastructure without asking you to register for a single API key. Network ranges, certificates, related domains, exposed ports, CDN vendors, and code leaks - all from free sources, all pipeable into each other.

Features

  • Network Discovery - find IP ranges (CIDRs) from an ASN, organization, domain, or IP
  • Certificate Transparency - discover subdomains via crt.sh
  • IP Enrichment - ports, hostnames, and CVEs via Shodan InternetDB (free, no key)
  • GitHub Code Search - find secrets, credentials, and subdomains in public repos via grep.app
  • IP Clustering - group IPs by ASN to map infrastructure
  • Related Domains - pivot via certificate logs, reverse WHOIS, and analytics IDs
  • CDN/WAF Detection - separate protected addresses from candidate origins
  • URL Collection - every URL the web archives have seen, including endpoints mined from WARCs

Installation

npm install -g @j3ssie/metabigor      # macOS, Linux, Windows
brew install j3ssie/tap/metabigor     # macOS, Linux

Both ship the same prebuilt binary for your platform - no Go toolchain needed.

Or build from source:

git clone https://github.com/j3ssie/metabigor.git
cd metabigor
make build          # binary at ./bin/metabigor

Or download a binary from the releases page.

The 30-second tour

metabigor net AS13335                  # network ranges behind an ASN
metabigor cert hackerone.com           # subdomains from certificate logs
metabigor ip 1.1.1.1                   # open ports and CVEs for an IP
metabigor related tesla.com            # other domains the target owns
metabigor cdn --exclude -I ips.txt     # candidate origin servers

How every command works

The same conventions apply everywhere, so once you learn one command you know them all.

Four ways to pass targets

metabigor cert example.com                  # as an argument
metabigor cert example.com tesla.com        # several arguments
metabigor cert -i example.com               # with -i
metabigor cert -I domains.txt               # from a file, one per line (# comments are ignored)
cat domains.txt | metabigor cert            # on stdin

They combine, and the merged list is deduplicated:

metabigor cluster 1.1.1.1 -i 8.8.8.8 -I more-ips.txt

Arguments are the shortest path and work on every command. Reach for -i when the target would otherwise look like a flag, or when a script builds the command for you:

metabigor github -i "--endpoint-url"
metabigor net --input "$TARGET" -f json

Stdin is only read when no target was given any other way, so metabigor net AS13335 never blocks waiting on input inside a script or CI job.

One flag for output shape

-f/--format works on every command:

FormatWhat you getUse it for
text (default)Readable columnsReading in a terminal
flatThe bare primary valuePiping into other tools
jsonOne JSON object per linejq, automation
csvRows behind one headerSpreadsheets, reports
metabigor ip 1.1.1.0/28                # 1.1.1.1 | 80,443 | one.one.one.one
metabigor ip 1.1.1.0/28 -f flat        # 1.1.1.1:80
metabigor ip 1.1.1.0/28 -f json        # {"ip":"1.1.1.1","ports":[80,443],...}
metabigor ip 1.1.1.0/28 -f csv -o ports.csv

Results always go to stdout and logs always go to stderr, so pipes stay clean at any log level. -o writes results to a file as well, overwriting it unless you pass --append. The file is only rewritten once there is a result to write, so a run that fails or finds nothing leaves the previous results intact.

Commands chain together

metabigor net AS13335 -f flat | metabigor ip -f flat
metabigor related tesla.com -f flat | metabigor cert
cat domains.txt | dnsx -silent -resp-only | metabigor cdn --exclude

Commands

net - Network Discovery

Find the CIDRs behind an ASN, IP, domain, or organization. Uses the bundled offline database.

metabigor net AS13335                       # every CIDR announced by an ASN
metabigor net 1.1.1.1 --detail              # which ASN owns this IP
metabigor net --org Cloudflare              # search by company name
metabigor net --live tesla.com              # query live sources instead of the local DB
metabigor net -I asn-list.txt -f csv -o ranges.csv

The target type is auto-detected. Override it with --asn, --ip, --domain, or --org (mutually exclusive). --detail adds ASN, organization, and country columns.

cert - Certificate Transparency

metabigor cert hackerone.com                # one domain per line
metabigor cert "HackerOne Inc"              # search by organization
metabigor cert example.com --clean          # strip the *. from wildcards
metabigor cert example.com --wildcard       # only wildcard entries
metabigor cert example.com --detail         # cert IDs, issuers, validity dates
metabigor cert tesla.com | dnsx -silent

ip - IP Enrichment (Shodan InternetDB)

metabigor ip 1.1.1.1                        # ports, hostnames, CVEs
metabigor ip 1.1.1.0/28                     # CIDRs expand to hosts
metabigor ip 1.1.1.0/28 -f flat             # IP:PORT pairs
metabigor ip -I ips.txt -c 30 -f csv -o ports.csv

IPs InternetDB knows nothing about are skipped; pass --all to keep them.

github - Code Search (grep.app)

metabigor github hackerone.com              # repo and path per match
metabigor github tesla.com --subs           # only subdomains found in matches
metabigor github "api_key=" --detail        # show the matching code
metabigor github AKIA --pages 3 --detail

Requires Chrome or Chromium - grep.app answers plain HTTP clients with a bot challenge. Searches run one at a time regardless of -c, to respect grep.app's rate limit.

cluster - IP Clustering

Group IPs by the ASN that owns them, largest cluster first. Accepts IPs or CIDRs. Works offline.

cat ips.txt | metabigor cluster
metabigor cluster -I ips.txt -f csv -o clusters.csv
cat domains.txt | dnsx -silent -resp-only | metabigor cluster

related - Related Domain Discovery

metabigor related hackerone.com             # all sources
metabigor related tesla.com --sources crt
metabigor related tesla.com --sources crt,whois

Sources: crt (crt.sh), whois (viewdns.info reverse WHOIS), analytics (shared Google Analytics / Tag Manager IDs), or all. Results are deduplicated across sources and tagged with the source that found them first.

url - URL Collection from Web Archives

Download Tool