Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
KUMO-Domain-Recon-Tool β€” Domain OSINT and security reconnaissance framework running 26 parallel modules for DNS, ports, subdomains, leaked credentials, exposed endpoints, CVEs, and technology fingerprinting. | Kitploit
Tools/GitHubGitHub/karim852/kumo-domain-recon-tool
OSINT (Open Source Intelligence)ReconnaissanceVulnerability ScannersWeb Vulnerability ScannersPort ScanningInformation GatheringSecret DetectionThreat IntelligenceSubdomain Enumeration

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share
Red Teaming
DNS Analysis
GitHubkarim852/kumo-domain-recon-tool

KUMO-Domain-Recon-Tool

Domain OSINT and security reconnaissance framework running 26 parallel modules for DNS, ports, subdomains, leaked credentials, exposed endpoints, CVEs, and technology fingerprinting.

View RepositoryWebsite
62141711 day agoReviewed by Kitploit

KUMO θœ˜θ›› β€” Domain OSINT & Reconnaissance


Give Kumo a domain and it maps everything reachable about it in one pass: DNS and email security, certificates and subdomains from CT logs, open ports, technology fingerprints, leaked credentials and infostealer infections, cloud buckets, and 358 vulnerability checks against known exposures. Twenty-seven modules run in parallel, each one streaming its own card the moment it lands β€” in the terminal or in the browser.

No API key is required for any of it.

pip install flask requests dnspython urllib3

python3 kumo.py                    # home screen β€” pick modules by number
python3 kumo.py --web              # web dashboard β†’ http://127.0.0.1:8888
python3 kumo.py example.com        # straight to a full scan

Kumo web dashboard
The dashboard mid-scan: cards stream in as each module finishes, glowing by severity, with the vulnerability scanner leading on findings.


πŸ“‘ Table of contents

  • Installation
  • Running your first scan
  • The terminal
  • The dashboard
  • Themes
  • Vulnerability scanner
  • Modules
  • Optional API keys
  • CLI reference
  • Tests
  • Credits
  • Ecosystem

πŸ“¦ Installation

Requirements

OSLinux, macOS or Windows
Python3.8+
Rightsnone β€” Kumo never needs root
API keysnone required

Install

git clone https://github.com/karim852/KUMO-Domain-Recon-Tool
cd KUMO-Domain-Recon-Tool
pip install flask requests dnspython urllib3

Optional extras, each used by a single module and skipped cleanly when absent:

pip install brotli zstandard playwright

Nothing to configure. There is no config file, no key file and no database. Kumo reads what it needs from public sources at run time.


πŸš€ Running your first scan

Step 1 β€” Open the home screen

python3 kumo.py

With no target, Kumo opens its home screen: every module numbered and grouped, with the web interface on top.

Kumo CLI home screen

Step 2 β€” Choose what to run

InputRuns
1 4 12just those modules
aall 27
ffast scan β€” skips the slow modules
wthe web dashboard
qquit

Then enter the domain when prompted. Or skip the menu entirely:

python3 kumo.py example.com -m dns ssl

Step 3 β€” Watch the spider work

Modules run in parallel, so results do not arrive in order. A spider crawls the strand while they run, spinning silk behind it as each one lands, with the modules still in flight trailing the counter.

Kumo scanning

Step 4 β€” Export

python3 kumo.py example.com -o report.json

πŸ–₯️ The terminal

The terminal is not a fallback β€” every module renders in full, with its own layout, tables and severity colouring.

Home screenall modules numbered, grouped, sized to the terminal
Selectionby number, or a / f / w
Themesfour palettes in 24-bit colour, --theme or KUMO_THEME

🌐 The dashboard

python3 kumo.py --web             # β†’ http://127.0.0.1:8888
python3 kumo.py --web -p 9000     # custom port

Each module gets a card that appears immediately, shows a rotating edge while it is still running, then fills and takes on the colour of what it found β€” red for critical, amber for warnings, green for clean.

Streamingcards arrive as modules finish, no waiting for the slowest
Severity glowcard colour is derived from the badges it renders
Module pillsclick to enable or disable before scanning
ExportJSON, or a standalone HTML report
Themesfour, switchable live, remembered across reloads

🎨 Themes

Four palettes, in both the dashboard and the terminal. Click a dot in the header, or press Ctrl+Shift+T to cycle. The choice is saved and survives a reload.

Kumo themes

ThemeCharacter
Void (default)deepest navy, cyan bloom, flat surfaces
Void Glasslit card edges, under-glow, larger radius
Web θœ˜θ››violet accent, strongest glow
Carbonneutral surfaces, restrained glow β€” best for client screenshots

In the terminal:

python3 kumo.py --theme carbon example.com
export KUMO_THEME=web

Adding a fifth theme is one palette block plus one dot β€” every renderer reads its colours through the same token set.


πŸ”“ Vulnerability scanner

358 checks, no external tool and no template directory to sync. The engine mirrors nuclei's matcher model β€” status, word, regex, size and a small dsl, combined with matchers_condition.

Kumo vulnerability scanner card


🧩 Modules

27 modules, every one running in parallel. Click a module to see what it returns on a real scan.

Run them by number from the home screen, or by name: python3 kumo.py corp.demo -m dns ssl nuclei

Network & Infrastructure

πŸ“‘ DNS β€” Records + email security Β Β·Β  dns

Full DNS enumeration with a security grade on email protection. Detects missing DMARC, weak SPF policies, absent DKIM, and open zone transfers.

dns module

πŸ“ Geolocation β€” IP + ASN Β Β·Β  geo

Resolves the domain to IPv4/IPv6, geolocates each IP, and pulls ASN, ISP, and organization data.

geo module

🌐 WHOIS / RDAP β€” Registration data Β Β·Β  whois

Full registrar record including creation date, expiry, registrant info, and nameservers. Detects domains expiring soon and privacy-protected registrations.

Download Tool