
nmap
High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

Search Google/Bing/Ecosia/DuckDuckGo/Yandex/Yahoo for a search term (dork) with a default set of websites, bug bounty programs or custom collection.

Local static query builder for precise search across web engines, Shodan, crt.sh, and Wayback Machine. Supports Google dorks, filetype filters, date…

Just a silly recon tool that uses data from SSL Certificates to find potential host names

Open-source security research tool for identifying origin IP exposure of websites protected by Cloudflare and similar reverse proxy services.

An #OSINT Framework to perform various recon techniques on Companies, People, Phone Number, Bitcoin Addresses, etc., aggregate all the raw data, and…

Bash-based domain availability checker that scans WHOIS records across multiple TLDs to find unregistered domains for red teaming and phishing…

Subdomains analysis and generation tool. Reveal the hidden!

🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.

⡷⠂𝚔𝚊𝚛𝚖𝚊 𝚟𝟸⠐⢾ is a Passive Open Source Intelligence (OSINT) Automated Reconnaissance (framework)

Find subdomains with GPT, for free

The fastest dork scanner written in Go.

Search for documents in a domain through Search Engines (Google, Bing and Baidu). The objective is to extract metadata

Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network

🥀 Search Engine Tookit,URL采集、Favicon哈希值查找真实IP、子域名查找

Deep scan domain and find all possible domain to takeover

OSINT tool abusing SecurityTrails domain suggestion API to find potentially related domains by keyword and brute force.

Find Microsoft Exchange instance for a given domain and identify the exact version