recon
31 resources across 3 kinds
Tools
- Open ↗assetfinderpassive
Fast passive subdomain discovery drawing on crt.sh, certspotter, hackertarget, threatcrowd and wayback.
- Open ↗SpiderFootopt-in
Deep OSINT automation (200+ modules) for subdomains, hosts, leaks and exposure.
- Open ↗ShadowHoundactivedual-use
A PowerShell-based alternative to SharpHound for Active Directory enumeration, offering an AD-module path (ADWS) and a direct-LDAP DirectorySearcher path to collect users, groups, computers, and certificates. Output converts to BloodHound via BofHound; designed to reduce detection by avoiding known-malicious binaries.
- Open ↗Fast Google Dorks Scanpassivedual-use
An automated bash tool that runs a large set of Google dork search queries against a target domain to surface admin panels, widely-exposed file types and locations, and potential path-traversal exposures. Runs directly on Linux/Kali or via Docker, takes only a domain name as input, and supports an optional request proxy.
- Open ↗GraphRunneractivehigh-riskdual-use
A PowerShell post-exploitation toolset for interacting with the Microsoft Graph API after obtaining authenticated access to an Azure AD / M365 account. Provides reconnaissance, persistence, and pillaging modules: email/SharePoint/OneDrive/Teams search and export, malicious app deployment, consent-grant OAuth attacks, security-group cloning, and token refresh, with a browser-based GUI and no third-party dependencies.
- Open ↗h1statspassiveopt-in
A Python3 scraper that pulls data from HackerOne's GraphQL API to compile bug-bounty program statistics into a sortable CSV, extracting 23+ data points per program (bounty ranges, response/resolution times, total payouts, report volume, program age). Scrapes public programs by default and supports authenticated access to private programs via session cookie, aiding target selection.
- Open ↗ROADtoolsactive
A Python framework for exploring and attacking Azure AD / Entra ID. Comprises ROADlib (auth/DB library auto-generated from Azure AD API metadata), ROADrecon (async dump of the full Azure AD graph into a queryable database with an Angular web UI), and roadtx (token exchange supporting authentication flows, device registration, and PRT operations).
- Open ↗github-searchactivedual-use
Collection of Bash/Python/PHP scripts for reconnaissance against GitHub: credential/secret discovery, user and employee enumeration, dorking, subdomain enumeration, and repository/endpoint extraction. Authored by bug-bounty researcher gwen001.
- Open ↗pentest-tools (gwen001)activedual-use
Collection of ~60 custom Bash/Python/PHP utilities for quick pentest tasks: DNS enumeration and zone transfers, port scanning and ping sweeps, subdomain discovery via certificate transparency, web vulnerability checks (XSS, CORS, CRLF, SSRF, open redirect), and OSINT (Shodan, dorking). ~3.3k stars.
- Open ↗Phoenix Scopepassive
A microservice application that aggregates bug bounty program scope data across HackerOne, Bugcrowd, Intigriti and YesWeHack, exposing APIs and dashboards with scope-change alerts and asset enumeration to help researchers track in-scope targets.
- Open ↗waymorepassive
A reconnaissance tool that discovers archived URLs and content for a target domain by aggregating seven historical sources (Wayback Machine, Common Crawl, AlienVault OTX, URLScan, VirusTotal, GhostArchive, Intelligence X). It can also download the archived responses so they can be searched for additional links, developer comments, and hidden parameters, with filtering by status code, MIME type, keyword, and date range.
Frameworks & agents
- Open ↗BugHunteractivedual-usehigh-risk
An AI-powered bug bounty toolkit (standalone CLI and Claude Code plugin) that runs an autonomous scope-to-report loop: recon, hunting across 26+ web vulnerability classes and smart-contract bug categories, a validation gate, and submission-ready reports for HackerOne, Bugcrowd, Intigriti, and Immunefi. Orchestrates ~35 external scanners and supports Ollama/Groq or paid AI providers.
References
- Open ↗Awesome Bug Bounty Builderdual-uselicence
A security-specific collection: a bash installer that deploys 40+ recon and exploitation tools (Amass, Sublist3r, SQLmap, Nikto, FFUF) plus curated usage examples and one-liners for testing XSS, SQLi, SSRF, LFI and auth-bypass. GPL-3.0.
- Open ↗Google Dork Listdual-use
A maintained collection of roughly 13,760 Google search queries (dorks) in a single text file for locating publicly indexed sites and exposed files/vulnerabilities via search-engine syntax.
- Open ↗Google Dorks for Bug Bountydual-usepassive
A categorized collection of 40+ Google search queries (dorks) for bug-bounty and pentest reconnaissance, targeting exposed config/log files, XSS/SQLi/SSRF/LFI-prone parameters, API endpoints, login/test environments, cloud storage misconfigurations, and leaked credentials. It also includes an interactive dork tool and links to related dork collections.
- Open ↗
Large curated index of open-source-intelligence tools and resources across search engines (incl. dark web), social-media intelligence, domain/IP research, email verification, people investigation, data-breach search, and geospatial tooling. ~28k stars.
- Open ↗Awesome Bug Bounty Toolsdual-use
A curated, security-specific directory of ~200+ open-source bug-bounty and pentest tools organized by phase and vulnerability class: reconnaissance (subdomain enum, port scanning, content discovery), exploitation (SQLi, XSS, XXE, SSRF, CSRF, command injection), and specialized scanning (JWT, S3 buckets, CMS, WAF evasion). CC0-licensed.