
OSINT-Framework
Curated framework of free OSINT tools and resources for gathering intelligence from public sources, organized by category with structured metadata…

Curated framework of free OSINT tools and resources for gathering intelligence from public sources, organized by category with structured metadata…

🕵️♂️ Collect a dossier on a person by username from 3000+ sites

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are…

AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.

The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain…

Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X!

Omnisci3nt is an open-source web reconnaissance and intelligence tool for extracting deep technical insights from domains, including subdomains, SSL…

Extract subdomains from SSL certificates in HTTPS sites.

⚡ Perform subdomain enumeration using the certificate transparency logs from Censys.

SSLScrape | A scanning tool for scaping hostnames from SSL certificates.

This tool extract domains from IP address based in the information saved in virustotal.

A script to extract domain names from Content Security Policy(CSP) headers

Modular web application reconnaissance framework for automated subdomain enumeration, directory brute-forcing, and extraction of endpoints, JS URLs,…

Passive subdomain enumeration tool that extracts valid subdomains from certificate transparency logs using Python, ideal for reconnaissance and bug…

Passive subdomain discovery tool that aggregates results from multiple online sources via CLI, supporting stdin/stdout, JSONL output, and API key…

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

XRay is a tool for recon, mapping and OSINT gathering from public networks.

The recursive internet scanner for hackers. 🧡