์—…๋ฐ์ดํŠธ๋กœ ๋Œ์•„๊ฐ€๊ธฐ
New releaseJul 21, 2026

bbot v3.0.1

ํ•ด์ปค๋ฅผ ์œ„ํ•œ ์žฌ๊ท€์  ์ธํ„ฐ๋„ท ์Šค์บ๋„ˆ. ๐Ÿงก

๊ณต์œ 

bbot_banner

Python Version License PyPi Downloads Ruff Tests Codecov Discord

BEEยทbot์€ Spiderfoot์—์„œ ์˜๊ฐ์„ ๋ฐ›์€ ๋‹ค๋ชฉ์  ์Šค์บ๋„ˆ๋กœ, Recon(๋ฆฌ์ฝ˜), Bug Bounties(๋ฒ„๊ทธ ๋ฐ”์šดํ‹ฐ), ASM์„ ์ž๋™ํ™”ํ•˜๋„๋ก ์ œ์ž‘๋˜์—ˆ์Šต๋‹ˆ๋‹ค!

https://github.com/blacklanternsecurity/bbot/assets/20261699/e539e89b-92ea-46fa-b893-9cde94eebf81

VivaGraphJS๋กœ ์‹œ๊ฐํ™”ํ•œ ์‹ค์‹œ๊ฐ„ BBOT ์Šค์บ”

์„ค์น˜

# stable version
pipx install bbot

# bleeding edge (dev branch)
pipx install --pip-args '\--pre' bbot

Docker๋ฅผ ํฌํ•จํ•œ ๋” ๋งŽ์€ ์„ค์น˜ ๋ฐฉ๋ฒ•์€ Getting Started๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”

2.x์—์„œ ์—…๊ทธ๋ ˆ์ด๋“œํ•˜์‹œ๋‚˜์š”? BBOT 3.0์—๋Š” CLI, ํ”„๋ฆฌ์…‹, ๋ชจ๋“ˆ, ์ด๋ฒคํŠธ ๋ฐ Python API์— ๋Œ€ํ•œ ์ฃผ์š” ๋ณ€๊ฒฝ ์‚ฌํ•ญ์ด ํฌํ•จ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. ์—…๊ทธ๋ ˆ์ด๋“œ ์ „์— 2.x โ†’ 3.0 ๋งˆ์ด๊ทธ๋ ˆ์ด์…˜ ๊ฐ€์ด๋“œ(์†Œ์Šค)๋ฅผ ํ™•์ธํ•˜์„ธ์š”.

์†๋„ ํŒ: BBOT์˜ DNS ๋ฆฌ์กธ๋ฒ„(blastdns)๋Š” /etc/resolv.conf์˜ ๋ฆฌ์กธ๋ฒ„๋งˆ๋‹ค ์—ฌ๋Ÿฌ ์Šค๋ ˆ๋“œ๋ฅผ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค. ํ•„ํ„ฐ๋ง๋˜์ง€ ์•Š์€ ๋ฆฌ์กธ๋ฒ„๋ฅผ ๋” ์ถ”๊ฐ€ํ•˜๋ฉด ์Šค์บ” ์†๋„๊ฐ€ ํฌ๊ฒŒ ๋นจ๋ผ์ง‘๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์ƒ˜ํ”Œ resolv.conf์™€ ํŒ๊ณผ ์š”๋ น์„ ์ฐธ์กฐํ•˜์„ธ์š”.

์˜ˆ์ œ ๋ช…๋ น์–ด

1) ์„œ๋ธŒ๋„๋ฉ”์ธ ํŒŒ์ธ๋”

ํŒจ์‹œ๋ธŒ API ์†Œ์Šค์™€ ํƒ€๊ฒŸ๋ณ„ ์„œ๋ธŒ๋„๋ฉ”์ธ ๋ณ€ํ˜•์„ ์ด์šฉํ•œ ์žฌ๊ท€์  DNS ๋ฌด์ฐจ๋ณ„ ๋Œ€์ž…(brute-force).

# find subdomains of evilcorp.com
bbot -t evilcorp.com -p subdomain-enum

# passive sources only
bbot -t evilcorp.com -p subdomain-enum -rf passive
subdomain-enum.yml
description: Enumerate subdomains via APIs, brute-force

flags:
  # enable every module with the subdomain-enum flag
  - subdomain-enum

output_modules:
  # output unique subdomains to TXT file
  - subdomains

config:
  dns:
    threads: 25
    brute_threads: 1000
  # put your API keys here
  # modules:
  #   github:
  #     api_key: ""
  #   chaos:
  #     api_key: ""
  #   securitytrails:
  #     api_key: ""

BBOT์€ ๋‹ค๋ฅธ ๋„๊ตฌ๋ณด๋‹ค ์ง€์†์ ์œผ๋กœ 20-50% ๋” ๋งŽ์€ ์„œ๋ธŒ๋„๋ฉ”์ธ์„ ์ฐพ์•„๋ƒ…๋‹ˆ๋‹ค. ๋„๋ฉ”์ธ์ด ํด์ˆ˜๋ก ๊ทธ ์ฐจ์ด๋Š” ๋” ์ปค์ง‘๋‹ˆ๋‹ค. ์ด๊ฒƒ์ด ์–ด๋–ป๊ฒŒ ๊ฐ€๋Šฅํ•œ์ง€ ์•Œ์•„๋ณด๋ ค๋ฉด ์ž‘๋™ ๋ฐฉ์‹์„ ์ฐธ์กฐํ•˜์„ธ์š”.

subdomain-stats-ebay

2) ์›น ์ŠคํŒŒ์ด๋”

# crawl evilcorp.com, extracting emails and other goodies
bbot -t evilcorp.com -p spider
spider.yml
description: Recursive web spider

modules:
  - http

blacklist:
  # Prevent spider from invalidating sessions by logging out
  - "RE:/.*(sign|log)[_-]?out"

config:
  web:
    # how many links to follow in a row
    spider_distance: 2
    # don't follow links whose directory depth is higher than 4
    spider_depth: 4
    # maximum number of links to follow per page
    spider_links_per_page: 25

3) ์ด๋ฉ”์ผ ์ˆ˜์ง‘๊ธฐ

# quick email enum with free APIs + scraping
bbot -t evilcorp.com -p email-enum

# pair with subdomain enum + web spider for maximum yield
bbot -t evilcorp.com -p email-enum subdomain-enum spider
email-enum.yml
description: Enumerate email addresses from APIs, web crawling, etc.

flags:
  - email-enum

output_modules:
  - emails

4) ์›น ์Šค์บ๋„ˆ

# run a light web scan against www.evilcorp.com
bbot -t www.evilcorp.com -p web

# run a heavy web scan against www.evilcorp.com
bbot -t www.evilcorp.com -p web-heavy
web.yml
description: Quick web scan

include:
  - iis-shortnames

flags:
  - web

web-heavy.yml
description: Aggressive web scan

include:
  # include the web preset
  - web

flags:
  - web-heavy

5) ๋ชจ๋“  ๊ฒƒ์„ ํ•œ๊บผ๋ฒˆ์—

# everything everywhere all at once
bbot -t evilcorp.com -p kitchen-sink

# roughly equivalent to:
bbot -t evilcorp.com -p subdomain-enum cloud-enum code-enum email-enum spider web paramminer webbrute web-screenshots
kitchen-sink.yml
description: Everything everywhere all at once

include:
  - subdomain-enum
  - cloud-enum
  - code-enum
  - email-enum
  - spider
  - web
  - paramminer
  - webbrute
  - web-screenshots
  - baddns-heavy

config:
  modules:
    dnsbrute:
      recursive_mutations: true
    dnscommonsrv:
      recursive_mutations: true
    webbrute:
      avoid_wafs: False
    wayback:
      urls: True
      parameters: True
      archive: True

์ž‘๋™ ๋ฐฉ์‹

์•„๋ž˜ ๊ทธ๋ž˜ํ”„๋ฅผ ํด๋ฆญํ•˜์—ฌ BBOT์˜ ๋‚ด๋ถ€ ๋™์ž‘ ๋ฐฉ์‹์„ ์‚ดํŽด๋ณด์„ธ์š”.

image

์ถœ๋ ฅ ๋ชจ๋“ˆ

์นดํ…Œ๊ณ ๋ฆฌ