
ghostbuster
Eliminate dangling elastic IPs by performing analysis on your resources within all your AWS accounts.

Eliminate dangling elastic IPs by performing analysis on your resources within all your AWS accounts.

Extend your recon with cloud power

AI-powered bug bounty hunting toolkit that works with or without subscription.

Orbis is an full spectrum automated external attack surface intelligent toolkit.

Open-source security research tool for identifying origin IP exposure of websites protected by Cloudflare and similar reverse proxy services.

Python reconnaissance tool for discovering Azure services and attributing tenant ownership via DNS validation, multi-service probing, and response…

DNS-based subdomain enumeration tool for Azure services, probing App Services, Storage Accounts, Databases, Key Vaults, and CDN endpoints via…

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

Omnisci3nt is an open-source web reconnaissance and intelligence tool for extracting deep technical insights from domains, including subdomains, SSL…

A collection of scripts for assessing Microsoft Azure security

A high performance offensive security tool for reconnaissance and vulnerability scanning

Tool to discover external and internal network attack surface

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

A Modern Orchestration Engine for Security

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

A tool that can help detect and takeover subdomains with dead DNS records