Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
discover — Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload creation using Metasploit. For use with Ubuntu. Limited support for Kali Linux. | Kitploit
उपकरण/GitHubGitHub/leebaird/discover
OSINT (Open Source Intelligence)ReconnaissanceVulnerability ScannersContainer SecurityExploit FrameworksPayload GenerationScripting & AutomationAPI Security TestingInformation GatheringWeb SecurityPenetration Testing
3.9k870911 दिन पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
Cloud Security
GitHubleebaird/discover

discover

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload creation using Metasploit. For use with Ubuntu. Limited support for Kali Linux.

रिपॉजिटरी देखें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

Discover

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload creation using Metasploit. For use with Ubuntu. Limited support for Kali Linux.

License: MIT

  • Twitter Follow Lee Baird @discoverscripts
  • Twitter Follow Jay "L1ghtn1ng" Townsend @jay_townsend1

Setup and usage

  • Download to your home directory.
cd ~
git clone https://github.com/leebaird/discover
cd discover/
./discover.sh
  • On first run, Discover asks for your first name (max 10 letters) and saves it to ~/.discover/operator-name. That name is written on every engagement audit log line. To change it later, edit or delete that file and restart Discover.
  • Select main menu option 18 Update to update the operating system and install dependencies.
  • Some options require root credentials to run.

Optional shell helpers (config/zshrc)

cd ~/discover/config/
./install.sh
HostWhat install.sh does
Ubuntu / other (incl. macOS)Copies zshrc to ~/.bash_aliases and sources it
Kali (detected via /etc/os-release)Appends zshrc to ~/.zshrc

Also installs tmux.conf to ~/.tmux.conf and vimrc to ~/.vimrc.

Useful commands (after install / new shell):

CommandPurpose
nNetwork summary (external/internal IP, DNS, MAC, iface; ss without TIME-WAIT; ping 8.8.8.8)
scd ~/discover and short git status (no pull)
m / msStart MSF DB + console / stop MSF DB
web / web2HTTP server on port 80 (sudo) / 8000
nowFormatted date/time (does not override date)
updateGrok update + full apt upgrade chain
bh, th, smb, sipBloodHound, theHarvester, smbserver, IP sort

Network identity (IPs, DNS, MAC) is computed when you run n / web / upload — not at shell startup — so new shells stay fast and values stay current after VPN/wifi changes.

Notes

  • On Ubuntu and other non-Kali hosts, re-running overwrites ~/.bash_aliases with the repo copy.
  • On Kali, re-running install.sh appends again and can duplicate the block; edit ~/.zshrc or install only once.
  • Default zsh on macOS/Kali does not load ~/.bash_aliases unless you source it from ~/.zshrc.

Main menu

RECON
1.  Domain
2.  Person

SCANNING
3.  Generate target list
4.  CIDR
5.  List
6.  IP, range, or URL
7.  Rerun Nmap scripts and MSF aux

WEB
8.  Insecure direct object reference
9.  Open multiple tabs in Firefox
10. Nikto
11. SSL

MISC
12. Generate a malicious payload
13. Start a Metasploit listener
14. CVE lookup
15. Parse XML
16. Dev
17. Notes
18. Update
19. Exit

RECON

Domain

RECON

1.  Passive
2.  Breaches
3.  Find registered domains
4.  Google dorks
5.  Web search

6.  Active
7.  Open report
8.  Previous menu

Note: Passive and Active cannot be run as root.


Engagement workflow

  1. Passive — build $HOME/data/<domain>/ HTML report.
  2. Open report (or finish Active) so the engagement is on statusd.
  3. Audit > Import — names, names/titles/emails, subdomains, or another operator’s package into the current report.
  4. Active — httpx / whatweb / gowitness; Active and Subdomains pages; optional NVD CVSS.
  5. Shodan (optional) — Active page Enrich (Shodan checkbox).
  6. Software filter on Active, then filtered Subdomains, then host scans in operator mode.
  7. Export — on Report > Audit (Discover-hosted only): Client, Defender, or Operator package.

Passive recon

Uses Amass, ARIN, DNSRecon, dnstwist, Metasploit, subfinder, sublist3r, Shodan CTL (free CT hostnames; no API key), theHarvester, Whois, and multiple websites.

  • Acquire free API keys for maximum results with theHarvester ($HOME/.theHarvester/api-keys.yaml).
  • Passive builds an HTML report at $HOME/data/<domain>/.
  • Find registered domains updates pages/registered-domains.htm in an existing report.
  • HTML Reports menu: Passive, Active, and Audit.
  • Names: US public companies pull DEF 14A / Form 4 from SEC EDGAR.
  • Summary: HQ from 10-K then website footer (tools/company-manual.tsv override); social profile links when found.

Import

On Reports > Audit, Import (Discover-hosted only) targets the current engagement.

ChoiceWhat it does
Operator scansMerge another operator’s unpacked report (host-scans, screenshots, Active data, their audit lines)
NamesMerge tools/names-manual.tsv (Name, Title, Phone; # comments; filled title/phone win)
Names, titles, and emailsMerge an external names dump into Names and Emails
SubdomainsExisting sources (Firefox / Pentest-Tools / TSV) or CSV subdomain,ip,category; optional Active on new public hosts

CLI (same backends):

bash recon/import-names.sh --report /home/user/data/example.com --json
bash recon/import-names-titles-emails.sh --report /home/user/data/example.com --source /path/to/dump --json
bash recon/import-subdomains.sh --report /home/user/data/example.com \
  --mode team-csv --import /home/user/team-hosts.csv --json
# existing: --mode existing --import firefox|/path/to/export
# optional CSV: --run-active

CSV list skips hosts already in tools/subdomains. Empty IP then dig. Category: Discover rules first, else CSV. Never writes recon/subdomain-categories.tsv.


Active

Domain menu option 6. Run after Passive (and optionally Import subdomains).

Enter the location of a previous Discover scan:
/home/user/data/example.com
  • Reads public hostnames from tools/subdomains (stored RFC1918 skipped).
  • dig A @1.1.1.1 before httpx. A private, loopback, link-local, or 0.0.0.0 answer is left out of httpx and added to tools/private-subs (tools/dns-private.tsv). The stored public IP is not changed. VPN DNS is not used.
  • httpx (tools/httpx.jsonl); alive = 200–399, 401, 403, or 405.
  • whatweb + gowitness on alive URLs; merge with recon/active-tech.py.
  • Re-run Active to replace those artifacts and rebuild Active / Subdomains.

Artifacts live under tools/ (httpx.jsonl, whatweb.json, gowitness/, software-cves-cache.json).

Software filter and host scans

In operator mode only (report opened via Open report / Active at http://127.0.0.1:17322/…), Subdomains public rows with an HTTP status get a host-scan expand control (also on ?software= / ?cve= filtered views). Manual file:// open never shows chevrons. Expandable rows show host-scan boxes (quietest to loudest):

टूल डाउनलोड करें