Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
wtfis — Passive hostname, domain and IP lookup tool for non-robots | Kitploit
Tools/GitHubGitHub/pirxthepilot/wtfis
OSINT (Open Source Intelligence)ReconnaissanceThreat Feeds & AggregatorsInformation GatheringThreat IntelligenceDNS Analysis
GitHubpirxthepilot/wtfis

wtfis

Passive hostname, domain and IP lookup tool for non-robots

View Repository
1.8k84255 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

wtfis

Tests PyPI

Passive hostname, domain and IP lookup tool for non-robots

WTF is it?

wtfis is a commandline tool that gathers information about a domain, FQDN or IP address using various OSINT services. Unlike other tools of its kind, it's built specifically for human consumption, providing results that are pretty (YMMV) and easy to read and understand.

This tool assumes that you are using free tier / community level accounts, and so makes as few API calls as possible to minimize hitting quotas and rate limits.

The project name is a play on "whois".

Data Sources

ServiceUsed in lookupRequiredFree Tier
VirustotalAllNoYes
AbuseIPDBIP addressNoYes
GreynoiseIP addressNoYes
IP2LocationIP addressNoYes
IP2WhoisDomain/FQDNNoYes
IPinfoIP AddressNoYes (no signup)
IPWhoisIP addressNoYes (no signup)
ShodanIP addressNoNo
URLhausAllNoYes

Virustotal

The primary source of information. Retrieves:

  • Hostname (FQDN), domain or IP
    • Latest analysis stats with vendor detail
    • Reputation score (based on VT community votes)
    • Popularity ranks (Alexa, Cisco Umbrella, etc.) (FQDN and domain only)
    • Categories (assigned by different vendors)
  • Resolutions (FQDN and domain only)
    • Last n IP addresses (default: 3, max: 10)
    • Latest analysis stats of each IP above
  • Whois
    • Fallback only: if IP2Whois creds are not available
    • Various whois data about the domain itself

AbuseIPDB

AbuseIPDB is a crowd-sourced database of reported malicious IP addresses. Through its API wtfis shows:

  • Abuse confidence score (0-100)
  • Number of reports

IP2Location

Alternative Geolocation and ASN lookup source for IP addresses (default is IPWhois). Retrieves:

  • Geolocation
  • ASN and Org
  • Proxy (True or False)

IP2Whois and IP2Location are different features from the same service, so you only need to sign up once. The API key can then be used for both lookups.

IP2Whois

Optionally used if creds are provided. Retrieves:

  • Whois
    • Various whois data about the domain itself

IP2Whois is recommended over Virustotal for whois data for a couple of reasons:

  • VT whois data format is less consistent
  • IP2Whois whois data tends to be of better quality than VT. Also, VT's registrant data is apparently anonymized.
  • You can save one VT API call by offloading to IP2Whois.

IPinfo

Another alternative Geolocation and ASN lookup source for IP addresses. Retrieves:

  • Geolocation
  • ASN and Org
  • Hostname
  • Anycast (true or false)

IPWhois

Default Geolocation and ASN lookup source for IP addresses. Retrieves:

  • Geolocation
  • ASN, Org and ISP
  • Domain

IPWhois should not be confused with IP2Whois, which provides domain Whois data.

Greynoise

Using Greynoise's community API, wtfis will show whether an IP is in one of Greynoise's datasets:

  • Noise: IP has been seen regularly scanning the Internet
  • RIOT: IP belongs to a common business application (e.g. Microsoft O365, Google Workspace, Slack)

More information about the datasets here.

In addition, the API also returns Greynoise's classification of an IP (if available). Possible values are benign, malicious, and unknown.

Shodan

GETs data from the /shodan/host/{ip} endpoint (see doc). For each IP, retrieves:

  • List of open ports and services
  • Operating system (if available)
  • Tags (assigned by Shodan)

URLhaus

URLhaus is a crowd-sourced database of reported malicious URLs. This enrichment provides insight on whether the queried hostname or IP is being or was used for malware distribution via HTTP or HTTPS. Data that is provided include:

  • Count of currently online and total malware URLs
  • Whether the hostname or IP is currently in the DNSBL and SURBL public blocklists
  • All tags that have been assigned to the URL throughout its history in the URLhaus database

Install

$ pip install wtfis

To install via conda (from conda-forge), see wtfis-feedstock.

To install via brew:

brew install wtfis

Setup

wtfis uses these environment variables (all optional):

  • VT_API_KEY - Virustotal API key
  • ABUSEIPDB_API_KEY - AbuseIPDB API key
  • IP2LOCATION_API_KEY - IP2Location API key
  • IP2WHOIS_API_KEY - IP2Whois API key
  • GREYNOISE_API_KEY - Greynoise API key
  • SHODAN_API_KEY - Shodan API key
  • URLHAUS_API_KEY - URLhaus API key
  • WTFIS_DEFAULTS - Default boolean arguments
  • GEOLOCATION_SERVICE - Geolocation / ASN lookup service to use

Set these using your own method.

Alternatively, create a file in your home directory ~/.env.wtfis with the above options. See .env.wtfis.example for a template. NOTE: Don't forget to chmod 400 the file!

Usage

usage: wtfis [-h] [-A] [-s] [-g] [-a] [-u] [-m N] [-n] [-1] [-V] [--geolocation-service {ip2location,ipinfo,ipwhois}] entity

positional arguments:
  entity                Hostname, domain or IP

options:
  -h, --help            show this help message and exit
  -A, --all             Enable all possible enrichments
  -s, --use-shodan      Use Shodan to enrich IPs
  -g, --use-greynoise   Enable Greynoise for IPs
  -a, --use-abuseipdb   Enable AbuseIPDB for IPs
  -u, --use-urlhaus     Enable URLhaus for IPs and domains
  -m N, --max-resolutions N
                        Maximum number of resolutions to show (default: 3)
  -n, --no-color        Show output without colors
  -1, --one-column      Display results in one column
  -V, --version         Print version number
  --geolocation-service {ip2location,ipinfo,ipwhois}
                        Geolocation service to use (default: ipwhois)

Basically:

$ wtfis FQDN_OR_DOMAIN_OR_IP

and you will get results organized by panel, similar to the image above.

Defanged input is accepted (e.g. api[.]google[.]com).

If the terminal supports it, certain fields and headings are clickable hyperlinks that point to the respective services' websites.

All enrichments

Download Tool