
Batch asset collection and vulnerability scanning tool for red teams. Pulls targets from Hunter, Fofa, and Quake, performs fingerprinting, subdomain enumeration, and Nuclei v3 PoC checks.
Automatically identifies input type, no manual classification required
Extensible active/passive fingerprint recognition
Fingerprints support complex AND/OR/NOT/parentheses logical operations. Human-friendly.
Nuclei v3 support
Extensible fingerprint-to-vulnerability mapping database, minimizing invalid requests
Efficient subdomain enumeration/brute-forcing, precise wildcard resolution filtering
Hunter, Fofa, Quake support
Hunter low-perception mode
Low dependencies, ready to use out of the box on multiple systems
Efficient HTML reports, including vulnerability request and response
Audit logs, essential for sensitive environments
Download config.zip and the binary file corresponding to your operating system from Releases. Run it directly from the command line.
PS: Starting from dddd v2.0, it can run independently of the config folder.
Scan an IP
dddd -t 192.168.0.1
Scan a subnet
dddd -t 192.168.0.1/24
dddd -t 192.168.0.0-192.168.0.12
Scan a website
dddd -t http://test.com
dddd has three types of file output
All results are output to result.txt by default. You can change the output file with the -o parameter, and change the output format with the -ot parameter (json), defaulting to text.
The default HTML vulnerability output is current timestamp.html, and you can change the output file with the -ho parameter.
The -a parameter enables the audit log feature. Logs are saved in audit.log, recording detailed scanning behavior.
Scanning can be terminated at any time. When there are outputs such as fingerprint recognition or vulnerability scan results, they will be saved to the file in real time.
Red team external network (Hunter)
dddd -t 'icp.name="xxxx有限公司"' -hunter -oip
Red team external network (Hunter for ICP filing lookup, Fofa to supplement ports) for efficient asset mapping
dddd -t 'icp.name="xxxx有限公司"' -hunter -fofa -oip
Red team external network (local subdomain enumeration)
dddd -t xxx.com -sd
Red team internal network
./dddd -t 172.16.100.0/24
Security service testing/sensitive environments (enable audit logs , convenient for shifting blame afterwards)
./dddd -t 172.16.100.1 -a
Fingerprint recognition only
./dddd -t http://www.xxx.com -npoc
./dddd -t 172.16.100.11 -npoc
./dddd -t 172.16.120.11:3307 -npoc
If you want to know how to add fingerprints, add Pocs, more usage, or vulnerability report screenshots. Please click the link below.
This tool is intended only for legally authorized enterprise security construction activities. If you need to test the availability of this tool, please set up your own target environment.
When using this tool for detection, you should ensure that the behavior complies with local laws and regulations and that you have obtained sufficient authorization. Do not scan unauthorized targets.
If you engage in any illegal behavior during the use of this tool, you shall bear the corresponding consequences yourself, and we will not assume any legal or joint liability.
Before installing and using this tool, please be sure to carefully read and fully understand the content of all terms. Restrictions, disclaimers, or other terms involving your major rights and interests may be highlighted in bold, underlined, or other forms to draw your attention. Unless you have fully read, completely understood, and accepted all terms of this agreement, please do not install and use this tool. Your use or any other express or implied indication of acceptance of this agreement shall be deemed that you have read and agreed to be bound by this agreement.
https://github.com/shadow1ng/fscan
https://github.com/lcvvvv/kscan
https://github.com/lcvvvv/gonmap
https://github.com/projectdiscovery/nuclei
https://github.com/projectdiscovery/subfinder
https://github.com/projectdiscovery/httpx
https://github.com/projectdiscovery/naabu
https://github.com/chainreactors/gogo
https://github.com/zan8in/afrog