Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
KUMO-Domain-Recon-Tool — Domain OSINT and security reconnaissance framework running 26 parallel modules for DNS, ports, subdomains, leaked credentials, exposed endpoints, CVEs, and technology fingerprinting. | Kitploit
Tools/GitHubGitHub/karim852/kumo-domain-recon-tool
OSINT (Open Source Intelligence)ReconnaissanceVulnerability ScannersWeb Vulnerability ScannersPort ScanningInformation GatheringSecret DetectionThreat IntelligenceSubdomain Enumeration

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Red Teaming
DNS Analysis
GitHubkarim852/kumo-domain-recon-tool

KUMO-Domain-Recon-Tool

Domain OSINT and security reconnaissance framework running 26 parallel modules for DNS, ports, subdomains, leaked credentials, exposed endpoints, CVEs, and technology fingerprinting.

View RepositoryWebsite
391364 days agoReviewed by Kitploit

Kumo Web UI

Python Modules Vuln Checks No API Key License

One domain. One command. Everything.


Kumo is a domain OSINT & security reconnaissance framework. Drop a domain — get everything back in real time across 26 parallel modules: DNS, open ports, leaked credentials, infostealer infections, vulnerable endpoints, subdomains, CVEs, malware families, and more.

root@kitploit:~
pip install requests flask

python3 kumo.py target.com          # full CLI scan
python3 kumo.py target.com --fast   # fast mode (skips slow modules)
python3 kumo.py --web               # web UI → http://localhost:8888

Screenshots

Web UI — 26 modules streaming in real time, results on the right, Google Dorks panel on the side:

Kumo Web UI

Kumo Web UI 2 CLI — the KUMO banner on launch:

Kumo CLI

Modules


🖼️ Screenshot — Website overview

Takes a live screenshot of the target and runs it against the ransomware.live feed. Pulls the page title, meta description, favicon, CMS fingerprint, and checks whether the domain appears in any ransomware gang's leak posts.

root@kitploit:~
  URL         https://corp.com
  Title       Corp — Enterprise Solutions
  CMS         WordPress 6.4
  Favicon     ✓ found

  ☠ RANSOMWARE FEED
  ✓ No mentions found on ransomware.live

📡 DNS — Records + email security

Full DNS enumeration with a security grade on email protection. Detects missing DMARC, weak SPF policies, absent DKIM, and open zone transfers.

root@kitploit:~
  A         203.0.113.10
  MX        mail.corp.com  (priority 10)
  NS        ns1.corp.com · ns2.corp.com
  TXT       v=spf1 include:_spf.google.com ~all

  EMAIL SECURITY
  DMARC     ✗ Missing — anyone can spoof @corp.com
  SPF       ⚠ Soft fail (~all) — not enforced
  DKIM      ✗ No selector found

📍 Geolocation — IP + ASN

Resolves the domain to IPv4/IPv6, geolocates each IP, and pulls ASN, ISP, and organization data.

root@kitploit:~
  IP         203.0.113.10
  Country    🇺🇸 United States
  City       Ashburn, Virginia
  ASN        AS14618 — Amazon.com Inc.
  ISP        Amazon Web Services

🌐 WHOIS / RDAP — Registration data

Full registrar record including creation date, expiry, registrant info, and nameservers. Detects domains expiring soon and privacy-protected registrations.

root@kitploit:~
  Registrar    GoDaddy LLC
  Created      2010-03-14
  Expires      2026-03-14  ← 337 days left
  Updated      2024-11-01
  Status       clientTransferProhibited
  Name servers ns1.corp.com · ns2.corp.com

🔒 SSL/TLS — Certificate analysis

Inspects the full certificate chain — issuer, expiry, Subject Alternative Names, cipher suite, and protocol version. Flags expired, self-signed, or misconfigured certificates.

root@kitploit:~
  Subject     corp.com
  Issuer      Let's Encrypt — R11
  Valid from  2025-01-10
  Expires     2025-04-10  ← 89 days left
  SANs        corp.com · www.corp.com · api.corp.com · mail.corp.com
  Protocol    TLSv1.3  ✓
  Cipher      TLS_AES_256_GCM_SHA384  ✓

🛡️ HTTP Headers — Security grade

Checks every security-relevant response header and grades the configuration. Flags missing headers that leave the site open to XSS, clickjacking, MIME sniffing, and information disclosure.

root@kitploit:~
  Grade   C

  ✗ Content-Security-Policy    missing — XSS risk
  ✗ X-Frame-Options            missing — clickjacking risk
  ✓ X-Content-Type-Options     nosniff
  ✗ Strict-Transport-Security  missing — HSTS not enforced
  ✗ Permissions-Policy         missing
  ✓ Referrer-Policy            no-referrer-when-downgrade
  ℹ Server                     nginx/1.24.0  ← version exposed
  ℹ X-Powered-By               PHP/8.1.2    ← stack disclosed

🧱 WAF Detection

Fingerprints the WAF or CDN sitting in front of the target using 40+ signatures — headers, cookies, server banners, and active probe responses. If nothing is detected, it says so clearly.

root@kitploit:~
  Source   Python fingerprinter (40+ signatures)

  ✓ Probably no WAF/CDN detected
  Based on header, cookie and active probe analysis.
  Note: absence of WAF signatures does not guarantee no protection.

Or when detected:

root@kitploit:~
  [HIGH]   Cloudflare
           cf-ray header · __cfduid cookie · CF-Cache-Status

  [LOW]    Akamai
           X-Check-Cacheable header

🚪 Port Scan — 70+ ports + banners

Scans 70+ common ports and grabs service banners for each open one. Enriched with data from Shodan and Censys when available.

root@kitploit:~
  PORT     STATE    SERVICE     BANNER
  22/tcp   open     SSH         OpenSSH 8.9p1 Ubuntu
  80/tcp   open     HTTP        nginx/1.24.0
  443/tcp  open     HTTPS       nginx/1.24.0
  3306/tcp open     MySQL       5.7.42-log ← exposed to internet
  6379/tcp open     Redis       PONG       ← no auth required
  8080/tcp open     HTTP        Apache Tomcat/9.0.80

🕵️ WhatWeb — Technology fingerprinting

Identifies the full tech stack — CMS, frameworks, JavaScript libraries, analytics, CDN, server, and more. Runs 80+ signature checks without sending a single intrusive request.

root@kitploit:~
  CMS           WordPress 6.4.3
  Server        nginx 1.24.0
  PHP           8.1.2
  Framework     jQuery 3.6.0
  Analytics     Google Analytics · Hotjar
  CDN           Cloudflare
  Fonts         Google Fonts
  SSL           Let's Encrypt

🤖 Robots / Security — Crawl rules + disclosure

Parses robots.txt for disallowed and allowed paths, highlights sensitive ones, and checks for a security.txt vulnerability disclosure contact. Also discovers sitemaps.

root@kitploit:~
  ✓ robots.txt found (23 rules)

  ⚠ SENSITIVE DISALLOWED PATHS
  /admin/
  /wp-admin/
  /config/
  /backup/
  /.git/

  ✓ ALLOWED PATHS
  /api/public/
  /sitemap.xml
  /Darklord

  ✗ No security.txt — no vulnerability disclosure contact

🔓 Sensitive Endpoint Discovery — 80+ known paths

Probes 80+ paths that are commonly left exposed: admin panels, backup files, config files, debug interfaces, API docs, source control, and infrastructure files. Every hit is severity-graded. A 403 Forbidden response still confirms the path exists and is automatically downgraded one severity level.

root@kitploit:~
  12 found / 80 probed   CRITICAL: 2  HIGH: 4  MEDIUM: 5  LOW: 1

  CRITICAL  /.env                      200  ← credentials exposed
  CRITICAL  /WEB-INF/web.xml           200  ← Java config leak
  HIGH      /wp-admin/                 200
  HIGH      /phpmyadmin/               200
  HIGH      /docker-compose.yml        200
  HIGH      /.git/HEAD                 200
  MEDIUM    /api/swagger.json          200
  MEDIUM    /actuator/env              200
  MEDIUM    /.git/config [403]         403  ← exists, access denied
  LOW       /.htaccess [403]           403

🔓 Vulnerability Scanner — 150+ built-in checks

Pure Python, zero external tools. 150+ HTTP-based checks inspired by real Nuclei templates — covering known CVEs, CMS vulnerabilities, exposed admin panels, cloud metadata endpoints, CI/CD dashboards, CORS misconfigurations, and more. Every check is catch-all / WAF aware: a baseline is fingerprinted first, so the generic 403/404 page a host returns for every path is never reported as a finding. Raw-file checks (.git, .env, backups) require the actual file content, and 403 responses are downgraded — never reported as "exposed".

root@kitploit:~
  CRITICAL: 2   HIGH: 5   MEDIUM: 7

  CRITICAL  Log4Shell RCE (CVE-2021-44228)          200 — Confirmed
  CRITICAL  Laravel .env Exposed                    200 — Plaintext secrets
  HIGH      Git Repository Accessible               200
  HIGH      phpMyAdmin Public Access                200
  HIGH      Jenkins Dashboard (Unauthenticated)     200
  HIGH      AWS Keys in HTTP Response               200
  MEDIUM    Spring Boot Actuator /env               200
  MEDIUM    Grafana Default Credentials             200

Checks include: Log4Shell · Spring4Shell · Drupalgeddon2 · Confluence OGNL · Oracle WebLogic · 15 WordPress plugin CVEs · CORS misconfiguration · Host header injection · Clickjacking and many more.

Recent CVE detection (2024–2026) — a dedicated set of detection-only templates fingerprints exposure/version for the newest, actively-exploited CVEs (no exploitation, just correlation):

root@kitploit:~
  RECENT CVE  cPanel / WHM Login Panel Exposed     CVE-2026-41940
  RECENT CVE  Next.js Middleware Auth Bypass       CVE-2025-29927
  RECENT CVE  SharePoint "ToolShell" RCE           CVE-2025-53770
  RECENT CVE  SAP NetWeaver Visual Composer        CVE-2025-31324
  RECENT CVE  Ivanti EPMM / Connect Secure         CVE-2025-4427
  RECENT CVE  CrushFTP Auth Bypass                 CVE-2025-31161
  ... 15 more (Fortinet · Palo Alto · Oracle EBS · Craft CMS · Vite · Langflow · Wazuh)

🔌 API Endpoint Fuzzer

Smart API discovery. Probes a random baseline first to detect catch-all servers, confirms a base API path actually exists before fuzzing, then discovers live endpoints and checks for GraphQL introspection. Every hit shows its HTTP status and response byte size.

root@kitploit:~
  Base found   /api/v1
  GraphQL      /graphql — introspection enabled   [200]  1.2 KB

  API ENDPOINTS
  HIGH      /api/v1/users            200   8.9 KB
  HIGH      /api/v1/admin            401   512 B
  MEDIUM    /api/v1/config           200   2.1 KB
  MEDIUM    /api/swagger.json        200   14 KB

🔑 JS Secret Scanner

Pulls and scans first-party JavaScript for hardcoded secrets — API keys, tokens, cloud credentials, and private keys — with clear-text output and the exact source line for each hit.

root@kitploit:~
  ⚠ Secrets Detected (clear text)

  CRITICAL  AWS Access Key      AKIA................   app.min.js
  HIGH      Google API Key      AIza................   main.js
  HIGH      Stripe Live Key     sk_live_.............  checkout.js
  MEDIUM    JWT Token           eyJhbGciOiJ.........   auth.js

🧠 Content Intelligence — JS/HTML extraction

Scrapes the homepage HTML, inline scripts, and every first-party JS file, then extracts the valuable signal — not just secrets. Endpoints, internal/external URLs, API routes, database connection URIs, cloud storage (S3 / GCS / Azure / Firebase), emails, internal hosts, JWTs, private keys, source maps, and risky code comments. Static assets (.css, .js, images, fonts) and documentation domains (MDN, W3C) are filtered out; external URLs are collapsed to unique third-party hosts.

root@kitploit:~
  166 items extracted   ·   14 JS files   ·   3 inline

  🗄️ DATABASE URIS
     mongodb+srv://svc:****@cluster0.abcd.mongodb.net/prod
  ☁️ CLOUD STORAGE
     [AWS S3]  assets-prod.s3.amazonaws.com
  🔌 API ENDPOINTS (12)
     /api/v1/users   ·   /api/internal/config   ·   /graphql
  🔐 SENSITIVE INFO (21)
     [Credential-like assignment]  api_key = 7f3c9a12de...
     [JWT token]                   eyJhbGciOiJIUzI1NiIs...
     [Risky code comment]          // TODO: remove hardcoded admin creds
  🌐 EXTERNAL SOURCES (19 unique hosts)
     cdn.thirdparty.com · api.stripe.com · fonts.googleapis.com ...

🎯 Favicon Hash — tech fingerprint

Fetches the favicon (HTML-declared first, then common paths in parallel — bounded so it never hangs), computes the MMH3 hash used by Shodan/Censys, and maps known hashes to technologies. Handy for fingerprinting the stack and pivoting to other hosts running the same favicon.

root@kitploit:~
  Favicon     https://corp.com/favicon.ico   (33.2 KB)
  MMH3 hash   -1319625119
  Shodan      http.favicon.hash:-1319625119
  Match       GitLab

☁️ Cloud Storage Buckets

Enumerates likely AWS S3 / GCP / Azure bucket names derived from the domain and checks for public exposure. Only a confirmed HTTP 200 (publicly readable) is reported — unreliable 403 responses are never flagged as findings.

root@kitploit:~
  Checked   42 candidate buckets

  PUBLIC   corp-backups.s3.amazonaws.com          200  ← readable
  PUBLIC   corp-assets.storage.googleapis.com     200

🔭 Shodan — InternetDB + CVE enrichment

Queries Shodan InternetDB (free, no key) for open ports, CPEs, hostnames, and CVEs. Every CVE is enriched with CVSS score, severity, KEV flag, and description via Shodan's free CVEDB API.

root@kitploit:~
  Source   InternetDB (free, no key)
  Ports    22, 80, 443, 3306, 6379, 8080
  CVEs     4

  CVE-2021-44228   CVSS 10.0   CRITICAL   [KEV]   EPSS 0.9741
  Remote code execution via JNDI lookup in Log4j 2.x

  CVE-2022-26134   CVSS 9.8    CRITICAL   [KEV]   EPSS 0.9689
  Confluence Server OGNL injection — unauthenticated RCE

  CVE-2021-26084   CVSS 9.8    CRITICAL   [KEV]
  Confluence Server pre-auth remote code execution

🔬 Censys — Hosts + certificates

Pulls host data and certificate intelligence from Censys. Enriched with optional API key for full results.

root@kitploit:~
  IPs      203.0.113.10 · 203.0.113.11
  Certs    14 certificates found in CT logs

  CERT     corp.com  (valid)      → Let's Encrypt  exp. 2025-04-10
  CERT     dev.corp.com  (valid)  → Let's Encrypt  exp. 2025-03-22
  CERT     old.corp.com  (expired)→ DigiCert       exp. 2022-08-01 ⚠

🗺️ Subdomain Discovery — 4 passive sources + CT logs

Queries crt.sh, HackerTarget, RapidDNS, and AlienVault OTX simultaneously, cross-references with Certificate Transparency logs, resolves every result, checks if it's alive, and flags anything that looks sensitive.

root@kitploit:~
  Total found   52    Alive   34    ⚠ Sensitive   8

  SUBDOMAIN               IP                FLAG
  admin.corp.com          203.0.113.10      ⚠ SENSITIVE
  dev.corp.com            203.0.113.24      ⚠ SENSITIVE
  staging.corp.com        203.0.113.31      ⚠ SENSITIVE
  intranet.corp.com       203.0.113.45      ⚠ SENSITIVE
  vpn.corp.com            203.0.113.88      ⚠ SENSITIVE
  api.corp.com            203.0.113.55
  mail.corp.com           203.0.113.12
  shop.corp.com           203.0.113.78
  cdn.corp.com            203.0.113.92
  ...

🔨 Subdomain Brute Force

Tests thousands of common subdomain names via DNS with wildcard detection — eliminates false positives automatically. Finds subdomains that passive sources miss entirely.

root@kitploit:~
  Wordlist     5000 names
  Threads      50
  Wildcard     ✓ detected and filtered

  NEW (not in passive)
  backup.corp.com         203.0.113.101   ⚠ SENSITIVE
  jenkins.corp.com        203.0.113.102   ⚠ SENSITIVE
  vault.corp.com          203.0.113.103   ⚠ SENSITIVE

📚 Wayback Machine — Archive mining

Queries the Wayback Machine for archived snapshots of the target — mining old endpoints, forgotten login pages, exposed config files, and paths that no longer exist on the live site but reveal the attack surface history.

root@kitploit:~
  Snapshots    2,847
  Date range   2011-03-14 → 2025-01-09

  INTERESTING ARCHIVED PATHS
  /admin/old-login.php           (2019-08-22)
  /config/database.yml           (2021-03-10)
  /api/v1/debug/                 (2022-06-18)
  /backup/db_export_2020.sql     (2020-11-05)  ← backup exposed
  /.env.backup                   (2023-01-14)  ← secrets

💀 Breach & Credential Intelligence — 5 sources

Aggregates from 5 free sources and runs an automatic per-email stealer check against Hudson Rock's database — showing which employee machines were infected, what malware ran, what passwords were stolen, and which services were compromised.

root@kitploit:~
  ┌────────────────┬──────────────┬──────────────┬─────────────┐
  │     8024       │      12      │     183      │      6      │
  │  INFOSTEALER   │  EMPLOYEES   │   CLIENTS    │   EMAILS    │
  └────────────────┴──────────────┴──────────────┴─────────────┘

⚠ CRITICAL FINDINGS
  [hudsonrock] employees_infected_infostealer
               3 employee machines infected — last: 2025-03-14
  [hudsonrock] stealer_family_identified
               Primary malware: RedLine (3100 infections)
  [chiasmodon] employee_plaintext_password
               [email protected] — pass: S3cr*** (2024-08-11)
  [proxynova]  comb_credentials_found
               183 unique emails with plaintext passwords

HUDSON ROCK CAVALIER
  Employees 3 · Clients 8017 · 3rd Parties 21 · Records 8041
  Malware: RedLine: 3100 · Lumma: 1540 · Raccoon: 892 · StealC: 401
  Last employee hit: 2025-03-14

CHIASMODON (pages 1+2)
  EMAIL                PASSWORD     DATE
  [email protected]        S3c•••••    2024-08-11
  [email protected]       adm•••••    2024-11-02
  [email protected]         d3v•••••    2024-07-28

PROXYNOVA COMB (3.2B credentials)
  Records 247 · Emails 38
  [email protected]    bil*****   (len 11)
  [email protected]       inf****    (len 8)

HAVEIBEENPWNED
  ✓ No domain breaches found (972 indexed)

☠ STEALER CHECK  (per-email · 9 infected / 20 checked)
  [email protected]                                  ☠ INFECTED
  📅 2025-01-12   💻 JOHN-PC   🖥 Windows 10 Pro x64
  🦠 C:\Users\john\AppData\Roaming\update\svc.exe
  🔑 Passwords: S3cr***0 · c0rp***y · J0hn***!
  🏢 4 corp services stolen · 👤 89 personal

📧 Email Harvester

Discovers @domain employee email addresses across multiple open sources, then merges in every confirmed email found during the breach intelligence scan.

root@kitploit:~
  Confirmed   7    Patterns   20
  Sources: crt.sh · web scraping · whois · DNS SOA · wayback

  📧 CONFIRMED EMAILS
  [email protected]
  [email protected]
  [email protected]
  [email protected]
  [email protected]

  💡 COMMON PATTERNS (may exist)
  [email protected]  [email protected]  [email protected]  [email protected] ...

Sources: Hunter.io · crt.sh certificate logs · web page scraping (contact / about / team) · DNS SOA record · WHOIS contact · Wayback Machine archive · common business prefixes.


🔍 Google Dorks — 61 queries

Generates 61 targeted Google dork queries pre-built for the domain — one click opens them in Google. Covers exposed files, login pages, sensitive directories, subdomains, cached pages, code repositories, and more.

root@kitploit:~
  FILE EXPOSURE
  site:corp.com filetype:pdf
  site:corp.com filetype:xlsx OR filetype:csv
  site:corp.com filetype:sql OR filetype:bak
  site:corp.com ext:env OR ext:config OR ext:yaml

  LOGIN & ADMIN
  site:corp.com inurl:login OR inurl:admin OR inurl:dashboard
  site:corp.com inurl:wp-admin

  SENSITIVE CONTENT
  site:corp.com intext:"password" OR intext:"api_key"
  site:corp.com intext:"BEGIN RSA PRIVATE KEY"

  SUBDOMAINS & INFRA
  site:*.corp.com -www
  site:corp.com inurl:dev OR inurl:staging OR inurl:test

  ... 51 more queries across 8 categories

🔗 OSINT Platform Links — 26 sources

Pre-generates 26 investigation links for the target across the most useful OSINT platforms — one click and you're there.

root@kitploit:~
  THREAT INTEL
  VirusTotal          https://virustotal.com/gui/domain/corp.com
  URLhaus             https://urlhaus.abuse.ch/browse/?search=corp.com
  Shodan              https://shodan.io/search?query=hostname:corp.com

  BREACH & LEAKS
  HaveIBeenPwned      https://haveibeenpwned.com/DomainSearch
  ProxyNova COMB      https://proxynova.com/tools/[email protected]
  IntelX              https://intelx.io/?s=corp.com
  DeHashed            https://dehashed.com/search?query=corp.com
  LeakRadar           https://leakradar.io/search?q=corp.com
  HudsonRock          https://cavalier.hudsonrock.com/...

  RECON & MAPPING
  Shodan Maps         https://maps.shodan.io/#corp.com
  Censys              https://search.censys.io/search?q=corp.com
  Fofa                https://en.fofa.info/result?qbase64=...
  ZoomEye             https://zoomeye.org/searchResult?q=corp.com

  ... 13 more across threat intel, archive, and code search

⚙️ Optional API keys

Everything works without any key. These unlock richer data:

root@kitploit:~
export SHODAN_API_KEY="your_key_here"
export HIBP_API_KEY="your_key_here"
# loaded at runtime — never hardcoded

📟 CLI reference

root@kitploit:~
python3 kumo.py target.com                    full scan
python3 kumo.py target.com --fast             skip slow modules
python3 kumo.py target.com -m dns ssl ports   specific modules only
python3 kumo.py target.com -o report.json     export to JSON
python3 kumo.py --web                         web UI (port 8888)
python3 kumo.py --web -p 9000                 custom port
python3 kumo.py target.com --no-color         pipe-friendly output

fast mode skips: wayback · brute · subdomains · email_harvest

🌐 Ecosystem

ToolDomain
☁️Kumo 蜘蛛domain OSINT & reconnaissance
🌑Kage 影DFIR host triage

⚠️ For authorized security testing only.
Only scan domains you own or have explicit written permission to test. You are free to use, modify, and share this code for educational and personal purposes. Please give proper credit when using or referencing this work. Commercial use is not allowed without explicit permission from the author.


Built for those who move fast. 蜘蛛.
Download Tool
VariableUnlocks
SHODAN_API_KEYFull Shodan host data — banners, services, full history
CENSYS_API_ID + CENSYS_API_SECRETFull Censys host & certificate search
HIBP_API_KEYPer-email HaveIBeenPwned lookup
CHIASMODON_API_KEYChiasmodon pro tier — more results
RANSOMWARE_LIVE_API_KEYRansomware.live pro feed
GOOGLE_CSE_KEY + GOOGLE_CSE_IDExecute Google dorks live