Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
discover — Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload creation using Metasploit. For use with Ubuntu. Limited support for Kali Linux. | Kitploit
도구/GitHubGitHub/leebaird/discover
OSINT (Open Source Intelligence)ReconnaissanceVulnerability ScannersContainer SecurityExploit FrameworksPayload GenerationScripting & AutomationAPI Security TestingInformation GatheringWeb SecurityPenetration Testing
3.9k870921일 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
Cloud Security
GitHubleebaird/discover

discover

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload creation using Metasploit. For use with Ubuntu. Limited support for Kali Linux.

저장소 보기
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

Discover

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload creation using Metasploit. For use with Ubuntu. Limited support for Kali Linux.

License: MIT

  • Twitter Follow Lee Baird @discoverscripts
  • Twitter Follow Jay "L1ghtn1ng" Townsend @jay_townsend1

Setup and usage

  • Download to your home directory.
cd ~
git clone https://github.com/leebaird/discover
cd discover/
./discover.sh
  • On first run, Discover asks for your first name (max 10 letters) and saves it to ~/.discover/operator-name. That name is written on every engagement audit log line. To change it later, edit or delete that file and restart Discover.
  • Select main menu option 18 Update to update the operating system and install dependencies.
  • Some options require root credentials to run.

Optional shell helpers (config/zshrc)

cd ~/discover/config/
./install.sh
HostWhat install.sh does
Ubuntu / other (incl. macOS)Copies zshrc to ~/.bash_aliases and sources it
Kali (detected via /etc/os-release)Appends zshrc to ~/.zshrc

Also installs tmux.conf to ~/.tmux.conf and vimrc to ~/.vimrc.

Useful commands (after install / new shell):

CommandPurpose
nNetwork summary (external/internal IP, DNS, MAC, iface; ss without TIME-WAIT; ping 8.8.8.8)
scd ~/discover and short git status (no pull)
m / msStart MSF DB + console / stop MSF DB
web / web2HTTP server on port 80 (sudo) / 8000
nowFormatted date/time (does not override date)
updateGrok update + full apt upgrade chain
bh, th, smb, sipBloodHound, theHarvester, smbserver, IP sort

Network identity (IPs, DNS, MAC) is computed when you run n / web / upload — not at shell startup — so new shells stay fast and values stay current after VPN/wifi changes.

Notes

  • On Ubuntu and other non-Kali hosts, re-running overwrites ~/.bash_aliases with the repo copy.
  • On Kali, re-running install.sh appends again and can duplicate the block; edit ~/.zshrc or install only once.
  • Default zsh on macOS/Kali does not load ~/.bash_aliases unless you source it from ~/.zshrc.

Main menu

RECON
1.  Domain
2.  Person

SCANNING
3.  Generate target list
4.  CIDR
5.  List
6.  IP, range, or URL
7.  Rerun Nmap scripts and MSF aux

WEB
8.  Insecure direct object reference
9.  Open multiple tabs in Firefox
10. Nikto
11. SSL

MISC
12. Generate a malicious payload
13. Start a Metasploit listener
14. CVE lookup
15. Parse XML
16. Dev
17. Notes
18. Update
19. Exit

RECON

Domain

RECON

1.  Passive
2.  Breaches
3.  Find registered domains
4.  Google dorks
5.  Web search

6.  Active
7.  Open report
8.  Previous menu

Note: Passive and Active cannot be run as root.


Engagement workflow

  1. Passive — build $HOME/data/<domain>/ HTML report.
  2. Open report (or finish Active) so the engagement is on statusd.
  3. Audit > Import — names, names/titles/emails, subdomains, or another operator’s package into the current report.
  4. Active — httpx / whatweb / gowitness; Active and Subdomains pages; optional NVD CVSS.
  5. Shodan (optional) — Active page Enrich (Shodan checkbox).
  6. Software filter on Active, then filtered Subdomains, then host scans in operator mode.
  7. Export — on Report > Audit (Discover-hosted only): Client, Defender, or Operator package.

Passive recon

Uses Amass, ARIN, DNSRecon, dnstwist, Metasploit, subfinder, sublist3r, Shodan CTL (free CT hostnames; no API key), theHarvester, Whois, and multiple websites.

  • Acquire free API keys for maximum results with theHarvester ($HOME/.theHarvester/api-keys.yaml).
  • Passive builds an HTML report at $HOME/data/<domain>/.
  • Find registered domains updates pages/registered-domains.htm in an existing report.
  • HTML Reports menu: Passive, Active, and Audit.
  • Names: US public companies pull DEF 14A / Form 4 from SEC EDGAR.
  • Summary: HQ from 10-K then website footer (tools/company-manual.tsv override); social profile links when found.

Import

On Reports > Audit, Import (Discover-hosted only) targets the current engagement.

ChoiceWhat it does
Operator scansMerge another operator’s unpacked report (host-scans, screenshots, Active data, their audit lines)
NamesMerge tools/names-manual.tsv (Name, Title, Phone; # comments; filled title/phone win)
Names, titles, and emailsMerge an external names dump into Names and Emails
SubdomainsExisting sources (Firefox / Pentest-Tools / TSV) or CSV subdomain,ip,category; optional Active on new public hosts

CLI (same backends):

bash recon/import-names.sh --report /home/user/data/example.com --json
bash recon/import-names-titles-emails.sh --report /home/user/data/example.com --source /path/to/dump --json
bash recon/import-subdomains.sh --report /home/user/data/example.com \
  --mode team-csv --import /home/user/team-hosts.csv --json
# existing: --mode existing --import firefox|/path/to/export
# optional CSV: --run-active

CSV list skips hosts already in tools/subdomains. Empty IP then dig. Category: Discover rules first, else CSV. Never writes recon/subdomain-categories.tsv.


Active

Domain menu option 6. Run after Passive (and optionally Import subdomains).

Enter the location of a previous Discover scan:
/home/user/data/example.com
  • Reads public hostnames from tools/subdomains (stored RFC1918 skipped).
  • dig A @1.1.1.1 before httpx. A private, loopback, link-local, or 0.0.0.0 answer is left out of httpx and added to tools/private-subs (tools/dns-private.tsv). The stored public IP is not changed. VPN DNS is not used.
  • httpx (tools/httpx.jsonl); alive = 200–399, 401, 403, or 405.
  • whatweb + gowitness on alive URLs; merge with recon/active-tech.py.
  • Re-run Active to replace those artifacts and rebuild Active / Subdomains.

Artifacts live under tools/ (httpx.jsonl, whatweb.json, gowitness/, software-cves-cache.json).

Software filter and host scans

In operator mode only (report opened via Open report / Active at http://127.0.0.1:17322/…), Subdomains public rows with an HTTP status get a host-scan expand control (also on ?software= / ?cve= filtered views). Manual file:// open never shows chevrons. Expandable rows show host-scan boxes (quietest to loudest):

도구 다운로드