osint
9 resources across 3 kinds
Tools
- Open ↗Fast Google Dorks Scanpassivedual-use
An automated bash tool that runs a large set of Google dork search queries against a target domain to surface admin panels, widely-exposed file types and locations, and potential path-traversal exposures. Runs directly on Linux/Kali or via Docker, takes only a domain name as input, and supports an optional request proxy.
- Open ↗github-searchactivedual-use
Collection of Bash/Python/PHP scripts for reconnaissance against GitHub: credential/secret discovery, user and employee enumeration, dorking, subdomain enumeration, and repository/endpoint extraction. Authored by bug-bounty researcher gwen001.
- Open ↗pentest-tools (gwen001)activedual-use
Collection of ~60 custom Bash/Python/PHP utilities for quick pentest tasks: DNS enumeration and zone transfers, port scanning and ping sweeps, subdomain discovery via certificate transparency, web vulnerability checks (XSS, CORS, CRLF, SSRF, open redirect), and OSINT (Shodan, dorking). ~3.3k stars.
- Open ↗waymorepassive
A reconnaissance tool that discovers archived URLs and content for a target domain by aggregating seven historical sources (Wayback Machine, Common Crawl, AlienVault OTX, URLScan, VirusTotal, GhostArchive, Intelligence X). It can also download the archived responses so they can be searched for additional links, developer comments, and hidden parameters, with filtering by status code, MIME type, keyword, and date range.
Frameworks & agents
- Open ↗DorkAgentpassiveopt-in
An LLM-powered agent (built on CrewAI) that automates Google Dorking for reconnaissance in penetration testing and bug bounty. It generates and refines dork queries with an LLM (OpenAI, Anthropic, or Gemini), analyzes results, and produces structured vulnerability reports to surface information disclosure, misconfigurations, and exposed sensitive data.
References
- Open ↗Google Dork Listdual-use
A maintained collection of roughly 13,760 Google search queries (dorks) in a single text file for locating publicly indexed sites and exposed files/vulnerabilities via search-engine syntax.
- Open ↗Awesome Hackingdual-use
A large, widely-used index of curated security awesome-lists for hackers, pentesters, and researchers, spanning 50+ domains including web hacking, bug bounty, malware analysis, OSINT, Android, IoT, forensics, and cryptography.
- Open ↗Google Dorks for Bug Bountydual-usepassive
A categorized collection of 40+ Google search queries (dorks) for bug-bounty and pentest reconnaissance, targeting exposed config/log files, XSS/SQLi/SSRF/LFI-prone parameters, API endpoints, login/test environments, cloud storage misconfigurations, and leaked credentials. It also includes an interactive dork tool and links to related dork collections.
- Open ↗
Large curated index of open-source-intelligence tools and resources across search engines (incl. dark web), social-media intelligence, domain/IP research, email verification, people investigation, data-breach search, and geospatial tooling. ~28k stars.