
reconftw
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

Abusing Certificate Transparency logs for getting HTTPS websites subdomains.

Passive domain monitoring tool leveraging Certificate Transparency logs to discover and track newly issued domains for an organization, with Slack…

E-mails, subdomains and names Harvester - OSINT

Fast subdomains enumeration tool for penetration testers

Knock Subdomain Scan

Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network

Generates permutations, alterations and mutations of subdomains and then resolves them

Passive wireless OSINT platform that detects and maps Wi-Fi, Bluetooth, CCTV, IoT devices, and cell towers using radio signal intelligence for…

A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with…

OSINT reconnaissance tool for network discovery, subdomain enumeration, IP enrichment, and secret detection via certificate logs, Shodan, and GitHub…

Bash-based fuzzing tool that leverages Google Dorking for stealthy enumeration of directories, files, subdomains, and parameters without direct…

BigBountyRecon tool utilises 58 different techniques using various Google dorks and open source tools to expedite the process of initial…

This Script will help you to gather information about your victim or friend.

Subdomain enumeration tool, asynchronous dns packets, use pcap to scan 1600,000 subdomains in 1 second

Shodan-powered tool to discover real IP addresses behind Cloudflare by hashing favicon icons using MurmurHash3, enabling origin server identification…

HostHunter a recon tool for discovering hostnames using OSINT techniques.

The most exhaustive list of reliable DNS resolvers.