
research
Published security research repository featuring academic papers on domain hijacking, 2FA bypass, and large-scale spoofing techniques, authored by…

Published security research repository featuring academic papers on domain hijacking, 2FA bypass, and large-scale spoofing techniques, authored by…

🕵️♂️ Collect a dossier on a person by username from 3000+ sites

Curated framework of free OSINT tools and resources for gathering intelligence from public sources, organized by category with structured metadata…

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines,…

🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.

Sublert is a security and reconnaissance tool which leverages certificate transparency to automatically monitor new subdomains deployed by specific…

Open-source security research tool for identifying origin IP exposure of websites protected by Cloudflare and similar reverse proxy services.

Shodan-powered tool to discover real IP addresses behind Cloudflare by hashing favicon icons using MurmurHash3, enabling origin server identification…

Performs OSINT scan on email/domain/ip_address/organization using OSINT-SPY. It can be used by Data Miners, Infosec Researchers, Penetration Testers…

Project Eyes On is a high-speed, multi-threaded surveillance tool by Y0oshi (@rde0) for locating open IP cameras worldwide. Unifies Google Dorking…

Get related domains / subdomains by looking at Google Analytics IDs

Next Generation DorX. Built by Dorks, for Dorks. 🤓

Concurrent virtual host scanner that brute-forces subdomains across multiple IPs on common web ports, filtering results by status codes and content…

This script will try to find a domains subdomains by using google dorking. It will never connect to the site it is researching.

Get subdomain list and check whether they are active or not by each response code. Using API by c99.nl

OSINT tool abusing SecurityTrails domain suggestion API to find potentially related domains by keyword and brute force.