
recon-skills
Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Passive DNS server that detects exposed cloud storage buckets (AWS S3, GCP, Azure) by resolving DNS requests, tracing CNAME chains, and flagging…

Network footprint scanner platform. Discover domains and run your custom checks periodically.

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

Serverless task distribution framework that parallelizes CLI tools across thousands of cloud functions for rapid reconnaissance and data processing.

Fast subdomain takeover scanner with 50+ signatures, supporting cloud provider integrations (AWS, Azure, Cloudflare) and CI/CD pipeline mode for…

Reconnaissance Real IP address for Cloudflare Bypass

Python reconnaissance tool for discovering Azure services and attributing tenant ownership via DNS validation, multi-service probing, and response…

Modular GCP attack toolkit for offensive research, enabling reconnaissance, authentication manipulation, and exploitation of cloud functions,…

SSL certificate-based reconnaissance engine for discovering AWS cloud assets, including IPs, subdomains, and domains, with active port scanning for…

Spider and scrape web targets to discover exposed cloud resources including S3 buckets, Azure Blobs, and DigitalOcean Spaces using regex-based…

Automated network asset, email, and social media profile discovery and cataloguing.

Monitoring the Cloud Landscape

A tool to hunt for publicly accessible DigitalOcean Spaces

Find unreferenced AWS S3 buckets which have CloudFront CNAME records pointing to them

Extend your recon with cloud power

Directory/File, DNS and VHost busting tool written in Go