Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
inquisitor — Reconocimiento OSINT centrado en la organización y opinado, inspirado en recon-ng y Maltego | Kitploit
Herramientas/GitHubGitHub/penafieljlm/inquisitor
OSINT (Inteligencia de Fuentes Abiertas)ReconocimientoEnumeración de DNS y SubdominiosRecopilación de InformaciónInteligencia de AmenazasRecolección de Correos
GitHubpenafieljlm/inquisitor

inquisitor

Reconocimiento OSINT centrado en la organización y opinado, inspirado en recon-ng y Maltego

Ver Repositorio
1805718hace 9 añosRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

Inquisitor

Aviso

Este proyecto está solo parcialmente completo y aún tengo que implementar muchas de las características descritas en la siguiente publicación de blog que hice: https://penafieljlm.com/2017/07/14/inquisitor/.

Inquisitor es una herramienta simple para recolectar información sobre empresas y organizaciones mediante el uso de fuentes de Inteligencia de Fuentes Abiertas (OSINT). Está fuertemente inspirada en cómo operan Maltego y recon-ng, y la herramienta básicamente reimplementa algunas de las características de esas herramientas pero agrega una capa adicional de semántica basada en opiniones sobre los tipos de activos para crear un flujo de trabajo fácil de usar.

Las características clave de Inquisitor incluyen:

  1. La capacidad de propagar la etiqueta de propiedad de un activo (p. ej., si se sabe que un Nombre de Registrante pertenece a la organización objetivo, entonces los hosts y redes registrados con ese nombre se marcarán como pertenecientes a la organización objetivo)
  2. La capacidad de transformar activos en otros activos potencialmente relacionados mediante consultas a fuentes abiertas como Google y Shodan
  3. La capacidad de visualizar las relaciones de esos activos a través de un diseño de paquete ampliable

Concepto

Todo el concepto de Inquisitor gira en torno a la idea de extraer información de fuentes abiertas basándose en lo que ya se conoce sobre una organización objetivo. En el contexto de Inquisitor, esto se llama "transformaciones". También se puede recuperar información relacionada inmediatamente de un activo conocido basándose en metadatos también recuperables de fuentes abiertas como whois y registros de internet.

Los conceptos se discuten en mayor detalle en este artículo del blog: https://penafieljlm.com/2017/07/14/inquisitor/

Instalación

Para instalar Inquisitor, simplemente clone el repositorio, ingrese a él y ejecute el script de instalación.``` pip install Cython click git clone [email protected]:penafieljlm/inquisitor.git cd inquisitor python setup.py install

## Uso

Inquisitor tiene cinco comandos básicos que incluyen `scan`, `status`, `classify`, `dump`, y `visualize`.```
usage: inq [-h] {scan,status,classify,dump,visualize} ...

optional arguments:
  -h, --help            show this help message and exit

command:
  {scan,status,classify,dump,visualize}
                        The action to perform.
    scan                Search OSINT sources for intelligence based on known
                        assets belonging to the target.
    status              Prints out the current status of the specified
                        intelligence database.
    classify            Classifies an existing asset as either belonging or
                        not belonging to the target. Adds a new asset with the
                        specified classification if none is present.
    dump                Dumps the contents of the database into a JSON file
    visualize           Create a D3.js visualization based on the contents of
                        the specified intelligence database.

Escaneo

En el modo de escaneo, la herramienta ejecuta todas las transformaciones disponibles para todos los activos que tengas en tu Base de Datos de Inteligencia. Asegúrate de crear Claves API para las diversas fuentes OSINT indicadas a continuación y proporcionarlas al script para que no se omitan las transformaciones que utilizan esas fuentes. Además, asegúrate de sembrar tu Base de Datos de Inteligencia con algunos activos objetivo conocidos y propios usando el comando classify primero, porque si la base de datos no contiene ningún activo propio, no habrá nada que transformar.``` usage: inq scan [-h] [--google-dev-key GOOGLE_DEV_KEY] [--google-cse-id GOOGLE_CSE_ID] [--google-limit GOOGLE_LIMIT] [--shodan-api-key SHODAN_API_KEY] [--shodan-limit SHODAN_LIMIT] DATABASE

positional arguments: DATABASE The path to the intelligence database to use. If specified file does not exist, a new one will be created.

optional arguments: -h, --help show this help message and exit --google-dev-key GOOGLE_DEV_KEY Specifies the developer key to use to query Google Custom Search. Visit the Google APIs Console (http://code.google.com/apis/console) to get an API key. If notspecified, the script will simply skip asset transforms that involve Google Search. --google-cse-id GOOGLE_CSE_ID Specifies the custom search engine to query. Visit the Google Custom Search Console (https://cse.google.com/cse/all) to create your own Google Custom Search Engine. If not specified, the script will simply skip asset transforms that involve Google Search. --google-limit GOOGLE_LIMIT The number of pages to limit Google Search to. This is to avoid exhausting your daily quota. --shodan-api-key SHODAN_API_KEY Specifies the API key to use to query Shodan. Log into your Shodan account (https://www.shodan.io/) and look at the top right corner of the page in order to view your API key. If not specified, the script will simply skip asset transforms that involve Shodan. --shodan-limit SHODAN_LIMIT The number of pages to limit Shodan Search to. This is to avoid exhausting your daily quota.

### Estado

En el modo de estado, la herramienta simplemente imprime un resumen rápido del estado de su base de datos de escaneo.```
usage: inq status [-h] [-s] DATABASE

positional arguments:
  DATABASE      The path to the intelligence database to use. If specified
                file does not exist, a new one will be created.

optional arguments:
  -h, --help    show this help message and exit
  -s, --strong  Indicates if the status will be based on the strong ownership
                classification.

Classify

En el modo classify, podrás añadir manualmente assets y reclasificar assets ya existentes en la Intelligence Database. Debes usar este comando para poblar tu Intelligence Database con activos objetivo conocidos y poseídos.``` usage: inq classify [-h] [-ar REGISTRANT [REGISTRANT ...]] [-ur REGISTRANT [REGISTRANT ...]] [-rr REGISTRANT [REGISTRANT ...]] [-ab BLOCK [BLOCK ...]] [-ub BLOCK [BLOCK ...]] [-rb BLOCK [BLOCK ...]] [-ah HOST [HOST ...]] [-uh HOST [HOST ...]] [-rh HOST [HOST ...]] [-ae EMAIL [EMAIL ...]] [-ue EMAIL [EMAIL ...]] [-re EMAIL [EMAIL ...]] [-al LINKEDIN [LINKEDIN ...]] [-ul LINKEDIN [LINKEDIN ...]] [-rl LINKEDIN [LINKEDIN ...]] DATABASE

positional arguments: DATABASE The path to the intelligence database to use. If specified file does not exist, a new one will be created.

Descargar herramienta