
InfoHound
InfoHound is an OSINT to extract a large amount of data given a web domain name.

InfoHound is an OSINT to extract a large amount of data given a web domain name.

A script to extract domain names from Content Security Policy(CSP) headers

Passive subdomain enumeration tool that extracts valid subdomains from certificate transparency logs using Python, ideal for reconnaissance and bug…

PAVELOW Exploit Toolbox is a BASH script that corresponds with your KALI distro to better help your vulnerability hunting and exploiting proccess…

Takeover subdomains using AWS dangling elastic ips and have a working POC for Subdomain Takeover.

bingip2hosts is a Bing.com web scraper that discovers websites by IP address

Nuubi Tools (Information-ghatering|Scanner|Recon.)

Searching for virtual hosts among non-resolvable domains

Domain OSINT and security reconnaissance framework running 26 parallel modules for DNS, ports, subdomains, leaked credentials, exposed endpoints,…

Listing subdomains about a main domain

Windows-based reconnaissance tool combining subdomain enumeration, port scanning, banner grabbing, whois lookups, and web path enumeration for…

A really simple utility to concate wordlists to a domain name - to pipe into your favourite resolver!

Passive subdomain discovery tool that aggregates results from multiple online sources via CLI, supporting stdin/stdout, JSONL output, and API key…

A wrapper around tools used for subdomain enumeration, to automate the workflow, on a given domain, written in bash.

DNS-based subdomain enumeration tool for Azure services, probing App Services, Storage Accounts, Databases, Key Vaults, and CDN endpoints via…

Automated reconnaissance tool that discovers organization domains by querying trademark databases via Google, Bing, Yahoo, and trademark registries.

Multithreaded Python tool for brute-forcing hidden directories and subdomains on target web servers to aid in reconnaissance and information…

nginx CVE scanner + RCE exploit framework (CVE-2026-42945 + 16 others)