
domainim
A fast and comprehensive tool for organizational network scanning

A fast and comprehensive tool for organizational network scanning

Passive subdomain enumeration tool that extracts valid subdomains from certificate transparency logs using Python, ideal for reconnaissance and bug…

Takeover subdomains using AWS dangling elastic ips and have a working POC for Subdomain Takeover.

Unofficial API & Client for dnsdumpster.com and hackertarget.com

Graphical DNS enumeration tool for Kali Linux that scans standard records (A, NS, SOA, MX) and visualizes results in mind maps for reconnaissance and…

Scripts and results for finding domain frontable CloudFront domains

async mass DNS resolver

Chrome extension tool for OSINT & Recon

XCTR Hacking Tools

DNS Enumeration with Asynchronicity

Subdomain Scan With Ping Method.

Hermes — an ephemeral, Docker-powered OSINT framework for testing, tinkering, and secure investigative automation.

Command-line tool for discovering SaaS platforms a company uses via DNS enumeration

Locally-hosted, air-gapped VAPT platform that runs 8 parallel scanning modules, deterministically scores findings with CVSS v3.1, and generates PDF…

SSL certificate-based reconnaissance engine for discovering AWS cloud assets, including IPs, subdomains, and domains, with active port scanning for…

Multi theaded DNS bruteforcing


An OSINT tool for collecting public information.