


Information gathering & website reconnaissance | https://phishstats.info/

Scans public GitHub repositories for accidentally uploaded sensitive data like credentials, secret keys, and tokens using a personal access token.

An Intelligent wordlist generator based on user profiling, permutations, and statistics. (Named after the same tool in Mr.Robot series S01E01)

Curated Intelligence is working with analysts from around the world to provide useful information to organisations in Ukraine looking for additional…

a privacy analysis tool designed to show exactly what information your browser exposes to websites

Maltego transform to detect the OpenSSL Heartbleed vulnerability (CVE-2014-0160)

This repository documents the process of identifying, analyzing, and gathering Open Source Intelligence (OSINT) on a specific security vulnerability…

⛏️ The extraction engine behind Maigret: turn any profile URL into a structured OSINT record across 150+ sites

SDK for querying the Intelligence X search engine and data archive, supporting selectors like email, domain, IP, and phone. Includes API wrappers in…

You can read the writeup on this script here

A Python script to collect campaign data from Gophish and generate a report

Bash script for passive reconnaissance that queries RIRs and BGP route servers to discover target organization netblocks, ASNs, and CIDR ranges…

A modular Python application to pull intelligence about malicious files

Python client for the WhatCMS.org API to detect 467+ Content Management Systems by domain query, returning name, version, and confidence score for…

Using google to scan sites for "ShellShock" (CVE-2014-6271)

Python2.7

Go client to communicate with Chaos DB API.