Reconnaissance and OSINT
105 tools found
PywerView
Python re-implementation of PowerView functionalities for AD enumeration on Linux.
SonarSearch
Searches internet scan data using a custom API based on Rapid7 datasets.
Asnlookup
Searches for organization ASNs, finds IP space, with integrated port scanning.
NMAP Query XML
Query Nmap XML files in the terminal for quick review of scan results.
SHODAN
Shodan scans internet-connected devices, revealing services and vulnerabilities.
CloudFlair
CloudFlair finds real IPs of sites behind CloudFlare or CloudFront if exposed.
hardCIDR
Bash script to find target's netblocks and ASNs during penetration test recon phase.
AORT
Easy Python tool for DNS recon and subdomain enumeration in bug bounty and pentest workflows.
msldap
LDAP client with Windows auth support and built-in queries for AD enumeration.
Censys Enumeration
Extracts subdomains and emails using Censys TLS certificate data.