
theHarvester
E-mails, subdomains and names Harvester - OSINT

E-mails, subdomains and names Harvester - OSINT

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface…


🔐 A CLI tool to extract server certificates

Free web-application vulnerability and version scanner


A flexible internet crawler used for scanning technologies, instances and vulnerabilities worldwide across the internet.

Fast HTTP enumerator

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

These templates are suggestions of how the Obsidian notetaking tool can be used during an OSINT investigation. The example data in those files should…

The VMWare Horizon Connection Server is often used as an internet-facing gateway to an organization’s virtual desktop environment (VDI). Until…

This tool is used to perform reverse IP lookups— searching for all domains hosted on one IP address.

Simple scanner to detect vulnerable Livewire installations.


Shodan Dorks

Port of Wappalyzer (uncovers technologies used on websites) to automate mass scanning.

A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could…