
probable_subdomains
Subdomains analysis and generation tool. Reveal the hidden!

Subdomains analysis and generation tool. Reveal the hidden!

Bash-based Google and Bing dorking tool for mass link harvesting, vulnerability analysis (SQLi, LFI), recon (subdomain, whois, nmap), and admin page…

Automated reconnaissance tool that performs subdomain enumeration, vulnerability scanning, OSINT, port scanning, and web analysis to map attack…

A fast and comprehensive tool for organizational network scanning

OSINT-driven hostname discovery tool that maps IP addresses to virtual hostnames using SSL certificates, HTTP headers, and service banners for attack…

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

Fast passive subdomain enumeration tool.

Fast subdomains enumeration tool for penetration testers

DNS enumeration tool for querying record types, performing zone transfers, brute-forcing subdomains, and resolving PTR records across IP ranges…

Async subdomain enumeration tool combining passive reconnaissance and bruteforce with DNS resolution, HTTP/TLS validation, wildcard detection, and…

Open-source security research tool for identifying origin IP exposure of websites protected by Cloudflare and similar reverse proxy services.

OSINT reconnaissance tool for network discovery, subdomain enumeration, IP enrichment, and secret detection via certificate logs, Shodan, and GitHub…

A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with…

Automated subdomain monitoring tool leveraging certificate transparency logs to detect new subdomains and issued TLS/SSL certificates, with Slack…

Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration

A DNS reconnaissance tool for locating non-contiguous IP space.

A high-speed tool for passively gathering URLs, optimized for efficient and comprehensive web asset discovery without active scanning.

Automated reconnaissance tool leveraging 58 Google dork and OSINT techniques for rapid information gathering, subdomain enumeration, and…