
3klCon
Automation Recon tool which works with Large & Medium scopes. It performs a lot of tasks and gets back all the results in separated files.

A OSINT tool which helps you to quickly find information effectively. All you need is to input and it will take take care of rest.

:new: The Multi-Tool Web Vulnerability Scanner.

Automated reconnaissance tool that expands attack surface via OSINT and active techniques, enumerating subdomains, mapping network blocks, and…

Automated reconnaissance tool that discovers organization domains by querying trademark databases via Google, Bing, Yahoo, and trademark registries.

Subdomain reconnaissance platform with HTTPX live-host probing, MongoDB-backed storage, searchable UI, and Nuclei vulnerability scanning with Discord…

HOCig- Automatic HOC Information Gathering Tool V 1.2

An OSINT tool that discovers sub-domains by searching Certificate Transparency logs

DNSProb is a tool built on top of retryabledns that allows you to perform multiple dns queries of your choice with a list of user supplied resolvers.

Curated framework of free OSINT tools and resources for gathering intelligence from public sources, organized by category with structured metadata…

Authorized WAF bypass proxy that rotates TCP/TLS/HTTP2 fingerprints, hunts origin IPs behind firewalls, and scans WAF defenses across 10 layers for…

Multi-phase recon and vulnerability scanner that discovers subdomains, scans ports, detects CMS/technologies, and checks for misconfigured headers…

Fetches archived URLs from the Wayback Machine, extracts unique paths and subdomains, and checks for exposed directory listings for web recon and bug…

Python-based web domain scanner integrating Sublist3r, Dirble, Nmap, and WhatWeb for subdomain discovery, directory enumeration, network scanning,…

Bash script that enumerates subdomains via Subfinder, resolves IPs, and identifies live web applications hosted on a domain for reconnaissance and…

Automates DNS zone transfer testing by discovering nameservers and checking for misconfigurations, printing exposed subdomains when vulnerable.

A Bash script and Docker image for Bug Bounty reconnaissance. Intended for headless use.

Python API wrapper and command-line client for the tools hosted on spyse.com.