Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Kunyu — Kunyu, more efficient corporate asset collection | Kitploit
Tools/GitHubGitHub/knownsec/kunyu
OSINT (Open Source Intelligence)ReconnaissanceNetwork MappingVulnerability AnalysisInformation GatheringPenetration TestingSubdomain EnumerationRed Teaming
GitHubknownsec/kunyu

Kunyu

Kunyu, more efficient corporate asset collection

View Repository
1.1k145181 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Kunyu(坤舆) - More efficient corporate asset collection

GitHub stars GitHub issues GitHub release


English | 中文文档

0x00 Introduce

Tool introduction

Kunyu (kunyu), whose name is taken from , is actually a professional subject related to geographic information, which counts the geographic information of the sea, land, and sky. The same applies to cyberspace. The same is true for discovering unknown and fragile assets. It is more like a cyberspace map, which is used to comprehensively describe and display cyberspace assets, various elements of cyberspace and the relationship between elements, as well as cyberspace and real space. The mapping relationship. So I think "Kun Yu" still fits this concept.

Kunyu aims to make corporate asset collection more efficient and enable more security-related practitioners to understand and use cyberspace surveying and mapping technology.

Application scenario

For the use of kunyu, there can be many application scenarios, such as:

  • Forgotten and isolated assets in the enterprise are identified and added to security management.
  • Perform quick investigation and statistics on externally exposed assets of the enterprise.
  • Red and blue are used against related requirements, and batch inspections of captured IPs are performed.
  • Collect vulnerable assets in batches (0day/1day) for equipment and terminals within the impact.
  • Information on sites involved in new-type cybercrime cases is quickly collected and merged for more efficient research, judgment, and analysis.
  • Statistic and reproduce the fragile assets on the Internet that are affected by related vulnerabilities.
  • .......

0x01 Install

Need Python3 or higher support

git clone https://github.com/knownsec/Kunyu.git
cd Kunyu
pip3 install -r requirements.txt

Linux:
	python3 setup.py install
	kunyu console

Windows:
	cd kunyu
	python3 console.py

PYPI:
	pip3 install kunyu
	
P.S. Windows also supports python3 setup.py install.

0x02 Configuration instructions

When you run the program for the first time, enter the following command to initialize the operation. Other login methods are provided, and the API method is recommended (username/password login is deprecated).

kunyu init --apikey <your zoomeye key> --seebug <your seebug key>

The first time you use it, you need to use ZoomEye login credentials to use the tool to collect information. Currently, ZoomEye API requires payment.

ZoomEye access address: https://www.zoomeye.org/

Seebug access address: https://www.seebug.org/

The output file path can be customized by the following command,The default output path is: C:/Users/active user/kunyu/output/ or /active user/kunyu/output

kunyu init --output C:\Users\风起\kunyu\output

0x03 Tool instructions

Detailed command

kunyu console

ZoomEye

Global commands:
        info                                      Print User Info
        Search <Query>                            Comprehensive Information Search
        SearchIcon <File>/<URL>                   Query Based On Icon Image
        SearchBatch <File>                        Batch Query Assets In Files
        SearchCert <Domain>                       SSL Certificate Search
        SearchDomain <Domain>                     Domain Name Associated/Subdomain Search
        EncodeHash <Encryption> <Query>           Encryption Method Interface (Base64/HEX/MD5/mmh3)
        HostCrash <IP> <Domain>                   Host Header Scan Hidden Assets
        show <config>/<rule>                      Show Can Set Options Or Kunyu Config
        Seebug <Query>                            Search Seebug Vulnerability Information
        set <Option>                              Set Global Arguments Values
        view/views <ID>                           Look Over Banner Row Data Information
        Cscan <IP>/<Port>                         Scans Port Information About CobaltStrike
        PupilSearch <URL>/<ID>                    Example Query Sensitive Interfaces And Information
        CDNAnalysis <Domain>                      Identify Whether The Domain Name Is a CDN Asset
        Pocsuite3                                 Invoke The Pocsuite Component
        ExportPath                                Returns The Path Of The Output File
        CreateMap                                 Generate An IP Distribution Heat Map
        AliveScan                                 The Viability Of The Last Retrieval
        clear                                     Clear The Console Screen
        help                                      Print Help Info
        exit                                      Exit KunYu & 

OPTIONS

ZoomEye:
        page <Number>       		The number of pages returned by the query (default:1)
        size <Number>      		Set the number of searches per page (default:10)
        fields <fields>     		Set the response field information
        dtype <0/1>         		Query associated domain name/subdomain name
        stype <v4/v6>       		stype <v4/v6> Set to get data type IPV4 or IPV6
        btype <host/web>    		Set the API interface for batch query
        timeout <num>       		Set the timeout period of Kunyu HTTP request
        thread              		Set PupilSearch Thread Number(default is 10)
        deep                		Set PupilSearch Search Deep(default is 2)
        all                 		PupilSearch Add All Url To Check List
        fuzz                		PupilSearch Add Api To Check List
        proxy               		PupilSearch HTTP Proxy
	

Use case introduction

*Kunyu usage tutorial is as follows *

User information query

Comprehensive search(NEW)

Custom output fields(NEW)

For specific supported output custom fields, please refer to the following:

Field NameTypeDescriptionPermission
ipstringIP address (used when the web asset is incomplete)All users
domainstringDomainAll users
Download Tool