Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
inquisitor — 有主见的以组织为中心的OSINT足迹搜集工具,灵感来自recon-ng和Maltego | Kitploit
工具/GitHubGitHub/penafieljlm/inquisitor
OSINT (开源情报)侦察DNS和子域名枚举信息收集威胁情报电子邮件收集
GitHubpenafieljlm/inquisitor

inquisitor

有主见的以组织为中心的OSINT足迹搜集工具,灵感来自recon-ng和Maltego

查看仓库
18057189年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Inquisitor

注意

该项目仅部分完成,我尚未实现我撰写的以下博文中描述的许多功能:https://penafieljlm.com/2017/07/14/inquisitor/。

Inquisitor 是一个通过使用开源情报(OSINT)来源来收集公司和组织信息的简单工具。它深受 Maltego 和 recon-ng 操作方式的启发,该工具很大程度上重新实现了这些工具的一些功能,但在资产类型之上增加了一层基于观点的语义,以创建易于使用的工作流程。

Inquisitor 的关键特性包括:

  1. 级联资产所有权标签的能力(例如,如果已知注册人姓名属于目标组织,则使用该名称注册的主机和网络将被标记为属于目标组织)
  2. 通过查询 Google 和 Shodan 等开放来源,将资产转化为其他可能相关资产的能力
  3. 通过可缩放打包布局可视化这些资产之间关系的能力

概念

Inquisitor 的整个概念围绕根据已知目标组织的信息从开放来源提取信息的思想。在 Inquisitor 的上下文中,这些被称为“transforms”。相关信息也可以基于可从 whois 和互联网注册机构等开放来源检索的元数据,立即从已知资产中检索。

这些概念在这篇博文中进一步详细讨论:https://penafieljlm.com/2017/07/14/inquisitor/

安装

要安装 Inquisitor,只需克隆仓库,进入目录,然后执行安装脚本。``` pip install Cython click git clone [email protected]:penafieljlm/inquisitor.git cd inquisitor python setup.py install

## 使用

Inquisitor 有五个基本命令,包括 `scan`、`status`、`classify`、`dump` 和 `visualize`。```
usage: inq [-h] {scan,status,classify,dump,visualize} ...

optional arguments:
  -h, --help            show this help message and exit

command:
  {scan,status,classify,dump,visualize}
                        The action to perform.
    scan                Search OSINT sources for intelligence based on known
                        assets belonging to the target.
    status              Prints out the current status of the specified
                        intelligence database.
    classify            Classifies an existing asset as either belonging or
                        not belonging to the target. Adds a new asset with the
                        specified classification if none is present.
    dump                Dumps the contents of the database into a JSON file
    visualize           Create a D3.js visualization based on the contents of
                        the specified intelligence database.

扫描

在扫描模式下,该工具会对您情报数据库中的所有资产运行所有可用的转换。请确保为下面提到的各种OSINT来源创建API密钥,并将其提供给脚本,否则使用这些来源的转换将被跳过。同时,请确保您首先使用 classify 命令在情报数据库中植入一些已知拥有的目标资产,因为如果数据库中没有包含任何拥有的资产,则没有可供转换的内容。``` usage: inq scan [-h] [--google-dev-key GOOGLE_DEV_KEY] [--google-cse-id GOOGLE_CSE_ID] [--google-limit GOOGLE_LIMIT] [--shodan-api-key SHODAN_API_KEY] [--shodan-limit SHODAN_LIMIT] DATABASE

positional arguments: DATABASE The path to the intelligence database to use. If specified file does not exist, a new one will be created.

optional arguments: -h, --help show this help message and exit --google-dev-key GOOGLE_DEV_KEY Specifies the developer key to use to query Google Custom Search. Visit the Google APIs Console (http://code.google.com/apis/console) to get an API key. If notspecified, the script will simply skip asset transforms that involve Google Search. --google-cse-id GOOGLE_CSE_ID Specifies the custom search engine to query. Visit the Google Custom Search Console (https://cse.google.com/cse/all) to create your own Google Custom Search Engine. If not specified, the script will simply skip asset transforms that involve Google Search. --google-limit GOOGLE_LIMIT The number of pages to limit Google Search to. This is to avoid exhausting your daily quota. --shodan-api-key SHODAN_API_KEY Specifies the API key to use to query Shodan. Log into your Shodan account (https://www.shodan.io/) and look at the top right corner of the page in order to view your API key. If not specified, the script will simply skip asset transforms that involve Shodan. --shodan-limit SHODAN_LIMIT The number of pages to limit Shodan Search to. This is to avoid exhausting your daily quota.

### 状态

在状态模式下,该工具仅输出扫描数据库状态的快速摘要。```
usage: inq status [-h] [-s] DATABASE

positional arguments:
  DATABASE      The path to the intelligence database to use. If specified
                file does not exist, a new one will be created.

optional arguments:
  -h, --help    show this help message and exit
  -s, --strong  Indicates if the status will be based on the strong ownership
                classification.

分类

在分类模式下,您将能够手动添加资产,并对情报数据库中已有的资产进行重新分类。您应使用此命令,用已知拥有的目标资产来填充情报数据库。``` usage: inq classify [-h] [-ar REGISTRANT [REGISTRANT ...]] [-ur REGISTRANT [REGISTRANT ...]] [-rr REGISTRANT [REGISTRANT ...]] [-ab BLOCK [BLOCK ...]] [-ub BLOCK [BLOCK ...]] [-rb BLOCK [BLOCK ...]] [-ah HOST [HOST ...]] [-uh HOST [HOST ...]] [-rh HOST [HOST ...]] [-ae EMAIL [EMAIL ...]] [-ue EMAIL [EMAIL ...]] [-re EMAIL [EMAIL ...]] [-al LINKEDIN [LINKEDIN ...]] [-ul LINKEDIN [LINKEDIN ...]] [-rl LINKEDIN [LINKEDIN ...]] DATABASE

positional arguments: DATABASE The path to the intelligence database to use. If specified file does not exist, a new one will be created.

optional arguments: -h, --help show this help message and exit -ar REGISTRANT [REGISTRANT ...], --accept-registrant REGISTRANT [REGISTRANT ...] Specifies a registrant to classify as accepted. -ur REGISTRANT [REGISTRANT ...], --unmark-registrant REGISTRANT [REGISTRANT ...] Specifies a registrant to classify as unmarked. -rr REGISTRANT [REGISTRANT ...], --reject-registrant REGISTRANT [REGISTRANT ...] Specifies a registrant to classify as rejected. -ab BLOCK [BLOCK ...], --accept-block BLOCK [BLOCK ...] Specifies a block to classify as accepted. -ub BLOCK [BLOCK ...], --unmark-block BLOCK [BLOCK ...] Specifies a block to classify as unmarked. -rb BLOCK [BLOCK ...], --reject-block BLOCK [BLOCK ...] Specifies a block to classify as rejected. -ah HOST [HOST ...], --accept-host HOST [HOST ...] Specifies a host to classify as accepted. -uh HOST [HOST ...], --unmark-host HOST [HOST ...] Specifies a host to classify as unmarked. -rh HOST [HOST ...], --reject-host HOST [HOST ...] Specifies a host to classify as rejected. -ae EMAIL [EMAIL ...], --accept-email EMAIL [EMAIL ...] Specifies a email to classify as accepted. -ue EMAIL [EMAIL ...], --unmark-email EMAIL [EMAIL ...] Specifies a email to classify as unmarked. -re EMAIL [EMAIL ...], --reject-email EMAIL [EMAIL ...] Specifies a email to classify as rejected. -al LINKEDIN [LINKEDIN ...], --accept-linkedin LINKEDIN [LINKEDIN ...] Specifies a LinkedIn Account to classify as accepted. -ul LINKEDIN [LINKEDIN ...], --unmark-linkedin LINKEDIN [LINKEDIN ...] Specifies a LinkedIn Account to classify as unmarked. -rl LINKEDIN [LINKEDIN ...], --reject-linkedin LINKEDIN [LINKEDIN ...] Specifies a LinkedIn Account to classify as rejected.

### 转储

在转储模式下,您可以将情报数据库的内容转储为人类可读的JSON文件。```
usage: inq dump [-h] [-j FILE] [-a] DATABASE
下载工具