
Findomain
The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain…

The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain…

⛏️ The extraction engine behind Maigret: turn any profile URL into a structured OSINT record across 150+ sites

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Command-line tool to scan Google search results for vulnerabilities

A better whois and domain intelligence toolkit

Educational evercookie demo showing how browser storage and HTTP cache techniques can persistently re-identify a visitor.

Automated security intelligence collector that queries public feeds and APIs for threat data on IPs, domains, URLs, hashes, and SSL fingerprints,…

Detects and identifies content management systems (CMS) used by web applications through HTTP response analysis and known signatures, aiding in…

PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via Microsoft…

CPH:SEC WAES: Web Auto Enum & Scanner - Auto enums website(s) and dumps files as result

A curated collection of top-tier penetration testing tools and productivity utilities across multiple domains. Join us to explore, contribute, and…

Modular subdomain enumeration suite with certificate transparency, DNS brute-force, and API-based discovery. Includes post-enumeration modules for…

Burp Suite extension to discover assets from HTTP response.

domhttpx is a google search engine dorker with HTTP toolkit built with python, can make it easier for you to find many URLs/IPs at once with fast…

AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation

Python script that uses Shodan to discover Apache HTTP Server 2.4.49 instances vulnerable to CVE-2021-41773 path traversal and file disclosure.

Abusing Certificate Transparency logs for getting HTTPS websites subdomains.
