
Recon-Scan
Recon-Scan: open‑source passive reconnaissance with AI‑powered security analysis. Zero‑touch, developer‑first, and privacy‑focused.

Recon-Scan: open‑source passive reconnaissance with AI‑powered security analysis. Zero‑touch, developer‑first, and privacy‑focused.

A high-speed tool for passively gathering URLs, optimized for efficient and comprehensive web asset discovery without active scanning.

⡷⠂𝚔𝚊𝚛𝚖𝚊 𝚟𝟸⠐⢾ is a Passive Open Source Intelligence (OSINT) Automated Reconnaissance (framework)

a passive OSINT toolkit in python - usernames, emails, domains, ips, phones, hashes. no keys, no logins.

a passive OSINT toolkit in python usernames, emails, domains, ips, phones, hashes. no keys, no logins.

API-first subdomain discovery service using Certificate Transparency logs for fast, passive enumeration of subdomains via a REST API with JSON or…

Bash-based passive reconnaissance + attack surface mapping script using only public APIs + stock Linux tools (curl, dig, openssl, nmap, python3).

Knock Subdomain Scan

Recursive DNS Subdomain Enumerator with dead-end avoidance system (BETA)

Go tool that passively discovers the real origin IP behind a WAF/CDN using multiple OSINT sources, then verifies candidates via HTML similarity, SSL…

Rust-based DNS enumeration and subdomain discovery tool for reconnaissance and penetration testing security assessments.