
subdomain-tko
Detects subdomain takeover vulnerabilities by analyzing DNS records and HTTP responses. Automatically identifies takeover-prone subdomains for…

Detects subdomain takeover vulnerabilities by analyzing DNS records and HTTP responses. Automatically identifies takeover-prone subdomains for…

Takeover script extracts CNAME record of all subdomains at once. TakeOver saves researcher time and increase the chance of finding subdomain takeover…

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

BigBountyRecon tool utilises 58 different techniques using various Google dorks and open source tools to expedite the process of initial…

Rock-On is a all in one Recon tool that will just get a single entry of the Domain name and do all of the work alone.

Open-source security research tool for identifying origin IP exposure of websites protected by Cloudflare and similar reverse proxy services.

Community curated list of search queries for various products across multiple search engines.

OSINT reconnaissance tool for network discovery, subdomain enumeration, IP enrichment, and secret detection via certificate logs, Shodan, and GitHub…

Advanced search in search engines, enables analysis provided to exploit GET / POST capturing emails & urls, with an internal custom validation…

A Windows application to help out with external infrastructure scans.

An #OSINT Framework to perform various recon techniques on Companies, People, Phone Number, Bitcoin Addresses, etc., aggregate all the raw data, and…

Uses ChatGPT API, Bard API, and Llama2, Python-Nmap, DNS Recon, PCAP and JWT recon modules and uses the GPT3 model to create vulnerability reports…

Network, recon and offensive-security tool for Linux.

Monitoring the Cloud Landscape

Curated collection of Google dork queries for advanced search engine reconnaissance, uncovering exposed databases, configuration files, admin panels,…

🔍 Recon notes organizer for bug bounty hunters and CTF players — subdomains, ports, endpoints, vulns, all in one place.

The modern, high-speed successor to nsec3walker. A specialized NSEC3 forensics engine built in Go for rapid zone harvesting and automated hash…

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.