
WordList
Curated collection of custom wordlists for fuzzing, DNS enumeration, parameter discovery, and default credentials, plus a Go generator for nuclei…

Curated collection of custom wordlists for fuzzing, DNS enumeration, parameter discovery, and default credentials, plus a Go generator for nuclei…

Go tool that passively discovers the real origin IP behind a WAF/CDN using multiple OSINT sources, then verifies candidates via HTML similarity, SSL…

Automated CDN origin-IP discovery skill for Claude Code that runs 40+ prioritized OSINT methods, cross-validates candidates via SSL and HTTP…

The Ultimate Information Gathering Toolkit

Python DNS toolkit supporting queries, zone transfers, dynamic updates, TSIG, EDNS0, DNSSEC, DNS-over-HTTPS, and DNS-over-QUIC with high- and…

Deliberately vulnerable Docker lab with a routable DNS estate and machine-readable answer keys per target, scoring scanner precision, recall and…

Multi-module offensive security toolkit for SOCKS5 proxy chaining, port scanning, DNS enumeration, hash cracking, reverse shell generation,…

Another tool for subdomain enumeration with some magics 🧙🏻♂️

Rust-based DNS enumeration and subdomain discovery tool for reconnaissance and penetration testing security assessments.

Secure, modular MCP server wrapping nmap, nuclei, gobuster, subfinder, httpx, nikto, sqlmap for AI-powered pentesting

Take a list of domains and probe for working HTTP and HTTPS servers

A Lightning-Fast DNS Resolver written in Rust 🦀

OSINT tool that finds domains, subdomains, directories, endpoints and files for a given seed URL.

Fast subdomain enumeration tool written in python.

A BASH Script to automate the installation of the most popular bug bounty tools

Network, recon and offensive-security tool for Linux.

Recon, Subdomain Bruting, Zone Transfers

This tool uses a combination of dictionary-based wordlists (brute-force) and DNS resolution checks to verify the existence of subdomains.