
AgrusScanner
Windows network reconnaissance scanner with ping sweeps, TCP port scanning, and deep AI/ML service detection for finding shadow AI, rogue LLM…

Windows network reconnaissance scanner with ping sweeps, TCP port scanning, and deep AI/ML service detection for finding shadow AI, rogue LLM…

Automated OSINT framework for reconnaissance, data harvesting, and threat intelligence gathering with modular crawlers, scanners, and extraction…

Serverless task distribution framework that parallelizes CLI tools across thousands of cloud functions for rapid reconnaissance and data processing.

Parses AD Explorer snapshots into BloodHound-compatible JSON or NDJSON for Active Directory reconnaissance and attack path mapping.

Web-based scanner that discovers fast, low-latency CDN IP addresses from Cloudflare, Fastly and other providers using multi-threaded 5-attempt…

Stealthy LDAP query BOF for Active Directory reconnaissance via AD WS, enabling attribute enumeration and data collection for red team operations.

Offline LDAP directory dump search tool with LDIF parsing, entity filtering, UAC flag translation, and ldapsearch command generation for Active…

Unauthenticated NTLM endpoint reconnaissance tool that decodes Type-2 challenges across HTTP, SMB, MSSQL, SMTP, IMAP, POP3, NNTP, LDAP, and RDP to…

io_uring based network scanner written in Rust

Scanner CDN Detection, Real Bandwidth Test, Throttle Detection

Rust CLI for bounded network reconnaissance: TCP/UDP port discovery, service identification, DNS/TLS/HTTP evidence collection, and public-source…

A powerful target reconnaissance framework powered by graph theory.

Semi-automatic OSINT framework and package manager

Local Area Network discovery tool with an interactive Terminal User Interface (TUI) written in Go. Discover, explore, and understand your LAN in an…


Fast DNS Lookup Library and CLI Tool

Scan only once by IP address and reduce scan times with Nmap for large amounts of data.

Scans domains to identify which Content Delivery Network (CDN) they use by fingerprinting HTTPS headers, CNAME records, and WHOIS data, with JSON…