Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

フィードお問い合わせプライバシー© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
inquisitor — recon-ng と Maltego に触発された、意見の強い組織中心の OSINT フットプリンティング | Kitploit
ツール/GitHubGitHub/penafieljlm/inquisitor
OSINT (オープンソースインテリジェンス)偵察DNSおよびサブドメイン列挙情報収集脅威インテリジェンスメール収集
GitHubpenafieljlm/inquisitor

inquisitor

recon-ng と Maltego に触発された、意見の強い組織中心の OSINT フットプリンティング

リポジトリを見る
18057189年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

Inquisitor

お知らせ

このプロジェクトは部分的にしか完成しておらず、以下のブログ記事で説明されている機能の多くはまだ実装されていません:https://penafieljlm.com/2017/07/14/inquisitor/

Inquisitorは、オープンソースインテリジェンス(OSINT)ソースを利用して企業や組織に関する情報を収集するためのシンプルなツールです。Maltegoやrecon-ngの動作から強くインスピレーションを受けており、それらのツールの機能の一部をほぼ再実装しつつ、アセットタイプに意見ベースの意味論の追加レイヤーを重ねることで、使いやすいワークフローを実現しています。

Inquisitorの主な機能は次のとおりです。

  1. アセットの所有権ラベルを連鎖的に適用する機能(例:登録者名がターゲット組織に属することがわかっている場合、その名前で登録されたホストやネットワークはターゲット組織に属するものとしてマークされる)
  2. GoogleやShodanなどのオープンソースに問い合わせることで、アセットを他の潜在的な関連アセットに変換する機能
  3. ズーム可能なパックレイアウトを通じてそれらのアセットの関係を可視化する機能

コンセプト

Inquisitorのコンセプト全体は、ターゲット組織について既にわかっている情報に基づいてオープンソースから情報を抽出するという考えに基づいています。Inquisitorの文脈では、これらは「トランスフォーム」と呼ばれます。また、whoisやインターネットレジストリなどのオープンソースからも取得可能なメタデータに基づいて、既知のアセットから関連情報を即座に取得することもできます。

これらのコンセプトについては、以下のブログ記事で詳しく説明されています:https://penafieljlm.com/2017/07/14/inquisitor/

インストール

Inquisitorをインストールするには、リポジトリをクローンし、そのディレクトリに入り、インストールスクリプトを実行します。``` pip install Cython click git clone [email protected]:penafieljlm/inquisitor.git cd inquisitor python setup.py install

## 使用法

Inquisitor には、`scan`、`status`、`classify`、`dump`、`visualize` の5つの基本コマンドがあります。```
usage: inq [-h] {scan,status,classify,dump,visualize} ...

optional arguments:
  -h, --help            show this help message and exit

command:
  {scan,status,classify,dump,visualize}
                        The action to perform.
    scan                Search OSINT sources for intelligence based on known
                        assets belonging to the target.
    status              Prints out the current status of the specified
                        intelligence database.
    classify            Classifies an existing asset as either belonging or
                        not belonging to the target. Adds a new asset with the
                        specified classification if none is present.
    dump                Dumps the contents of the database into a JSON file
    visualize           Create a D3.js visualization based on the contents of
                        the specified intelligence database.

Scan

スキャンモードでは、ツールはインテリジェンスデータベース内のすべてのアセットに対して利用可能なすべてのトランスフォームを実行します。以下に示すさまざまなOSINTソースのAPIキーを作成し、スクリプトに提供してください。そうしないと、それらのソースを使用するトランスフォームがスキップされます。また、データベースに所有アセットがないと変換するものが何もないため、最初にclassifyコマンドを使用していくつかの既知の所有ターゲットアセットをインテリジェンスデータベースにシードしてください。``` usage: inq scan [-h] [--google-dev-key GOOGLE_DEV_KEY] [--google-cse-id GOOGLE_CSE_ID] [--google-limit GOOGLE_LIMIT] [--shodan-api-key SHODAN_API_KEY] [--shodan-limit SHODAN_LIMIT] DATABASE

positional arguments: DATABASE The path to the intelligence database to use. If specified file does not exist, a new one will be created.

optional arguments: -h, --help show this help message and exit --google-dev-key GOOGLE_DEV_KEY Specifies the developer key to use to query Google Custom Search. Visit the Google APIs Console (http://code.google.com/apis/console) to get an API key. If notspecified, the script will simply skip asset transforms that involve Google Search. --google-cse-id GOOGLE_CSE_ID Specifies the custom search engine to query. Visit the Google Custom Search Console (https://cse.google.com/cse/all) to create your own Google Custom Search Engine. If not specified, the script will simply skip asset transforms that involve Google Search. --google-limit GOOGLE_LIMIT The number of pages to limit Google Search to. This is to avoid exhausting your daily quota. --shodan-api-key SHODAN_API_KEY Specifies the API key to use to query Shodan. Log into your Shodan account (https://www.shodan.io/) and look at the top right corner of the page in order to view your API key. If not specified, the script will simply skip asset transforms that involve Shodan. --shodan-limit SHODAN_LIMIT The number of pages to limit Shodan Search to. This is to avoid exhausting your daily quota.

### ステータス

ステータスモードでは、ツールはスキャンデータベースのステータスの簡単な要約を出力します。```
usage: inq status [-h] [-s] DATABASE

positional arguments:
  DATABASE      The path to the intelligence database to use. If specified
                file does not exist, a new one will be created.

optional arguments:
  -h, --help    show this help message and exit
  -s, --strong  Indicates if the status will be based on the strong ownership
                classification.

Classify

classify モードでは、手動でアセットを追加したり、Intelligence Database 内の既存のアセットを再分類することができます。このコマンドを使用して、既知の所有ターゲットアセットで Intelligence Database をシードする必要があります。``` usage: inq classify [-h] [-ar REGISTRANT [REGISTRANT ...]] [-ur REGISTRANT [REGISTRANT ...]] [-rr REGISTRANT [REGISTRANT ...]] [-ab BLOCK [BLOCK ...]] [-ub BLOCK [BLOCK ...]] [-rb BLOCK [BLOCK ...]] [-ah HOST [HOST ...]] [-uh HOST [HOST ...]] [-rh HOST [HOST ...]] [-ae EMAIL [EMAIL ...]] [-ue EMAIL [EMAIL ...]] [-re EMAIL [EMAIL ...]] [-al LINKEDIN [LINKEDIN ...]] [-ul LINKEDIN [LINKEDIN ...]] [-rl LINKEDIN [LINKEDIN ...]] DATABASE

positional arguments: DATABASE The path to the intelligence database to use. If specified file does not exist, a new one will be created.

ツールをダウンロード