All resources
Topic

recon

31 resources across 3 kinds

Tools

  1. Deep passive subdomain enumeration across many public sources.

    Open ↗
  2. Fast passive subdomain discovery drawing on crt.sh, certspotter, hackertarget, threatcrowd and wayback.

    Open ↗
  3. cdncheckpassive

    Classifies a host as CDN, WAF or cloud and names the provider.

    Open ↗
  4. dnsxopt-in

    Fast DNS resolution and record enumeration from ProjectDiscovery.

    Open ↗
  5. Gotatoractiveopt-in

    Subdomain permutation generator that emits candidate names to resolve, closing the active-permutation gap passive enumeration misses.

    Open ↗
  6. HTTP prober for live-host, status, title and technology detection.

    Open ↗
  7. masscanactive

    Mass, high-speed port scanner (typically requires root).

    Open ↗
  8. naabuactive

    Fast SYN/CONNECT port discovery from ProjectDiscovery.

    Open ↗
  9. Nmapactive

    Port, service and TLS scanning of a target host.

    Open ↗
  10. Deep OSINT automation (200+ modules) for subdomains, hosts, leaks and exposure.

    Open ↗
  11. subfinderpassive

    Passive subdomain enumeration across 40+ sources.

    Open ↗
  12. Subdomain-takeover checker matching dangling records against takeover fingerprints.

    Open ↗
  13. tlsxpassive

    Fast TLS/certificate data gathering (SANs, versions, ciphers) for host expansion and recon.

    Open ↗
  14. uncoveropt-in

    Discovers exposed hosts and assets across Shodan, Censys, FOFA and Quake.

    Open ↗
  15. Fingerprints and identifies web application firewalls.

    Open ↗
  16. Technology-stack fingerprinting for web applications.

    Open ↗
  17. ShadowHoundactivedual-use

    A PowerShell-based alternative to SharpHound for Active Directory enumeration, offering an AD-module path (ADWS) and a direct-LDAP DirectorySearcher path to collect users, groups, computers, and certificates. Output converts to BloodHound via BofHound; designed to reduce detection by avoiding known-malicious binaries.

    Open ↗
  18. Fast Google Dorks Scanpassivedual-use

    An automated bash tool that runs a large set of Google dork search queries against a target domain to surface admin panels, widely-exposed file types and locations, and potential path-traversal exposures. Runs directly on Linux/Kali or via Docker, takes only a domain name as input, and supports an optional request proxy.

    Open ↗
  19. GraphRunneractivehigh-riskdual-use

    A PowerShell post-exploitation toolset for interacting with the Microsoft Graph API after obtaining authenticated access to an Azure AD / M365 account. Provides reconnaissance, persistence, and pillaging modules: email/SharePoint/OneDrive/Teams search and export, malicious app deployment, consent-grant OAuth attacks, security-group cloning, and token refresh, with a browser-based GUI and no third-party dependencies.

    Open ↗
  20. h1statspassiveopt-in

    A Python3 scraper that pulls data from HackerOne's GraphQL API to compile bug-bounty program statistics into a sortable CSV, extracting 23+ data points per program (bounty ranges, response/resolution times, total payouts, report volume, program age). Scrapes public programs by default and supports authenticated access to private programs via session cookie, aiding target selection.

    Open ↗
  21. ROADtoolsactive

    A Python framework for exploring and attacking Azure AD / Entra ID. Comprises ROADlib (auth/DB library auto-generated from Azure AD API metadata), ROADrecon (async dump of the full Azure AD graph into a queryable database with an Angular web UI), and roadtx (token exchange supporting authentication flows, device registration, and PRT operations).

    Open ↗
  22. github-searchactivedual-use

    Collection of Bash/Python/PHP scripts for reconnaissance against GitHub: credential/secret discovery, user and employee enumeration, dorking, subdomain enumeration, and repository/endpoint extraction. Authored by bug-bounty researcher gwen001.

    Open ↗
  23. Collection of ~60 custom Bash/Python/PHP utilities for quick pentest tasks: DNS enumeration and zone transfers, port scanning and ping sweeps, subdomain discovery via certificate transparency, web vulnerability checks (XSS, CORS, CRLF, SSRF, open redirect), and OSINT (Shodan, dorking). ~3.3k stars.

    Open ↗
  24. A microservice application that aggregates bug bounty program scope data across HackerOne, Bugcrowd, Intigriti and YesWeHack, exposing APIs and dashboards with scope-change alerts and asset enumeration to help researchers track in-scope targets.

    Open ↗
  25. waymorepassive

    A reconnaissance tool that discovers archived URLs and content for a target domain by aggregating seven historical sources (Wayback Machine, Common Crawl, AlienVault OTX, URLScan, VirusTotal, GhostArchive, Intelligence X). It can also download the archived responses so they can be searched for additional links, developer comments, and hidden parameters, with filtering by status code, MIME type, keyword, and date range.

    Open ↗

Frameworks & agents

  1. BugHunteractivedual-usehigh-risk

    An AI-powered bug bounty toolkit (standalone CLI and Claude Code plugin) that runs an autonomous scope-to-report loop: recon, hunting across 26+ web vulnerability classes and smart-contract bug categories, a validation gate, and submission-ready reports for HackerOne, Bugcrowd, Intigriti, and Immunefi. Orchestrates ~35 external scanners and supports Ollama/Groq or paid AI providers.

    Open ↗

References

  1. A security-specific collection: a bash installer that deploys 40+ recon and exploitation tools (Amass, Sublist3r, SQLmap, Nikto, FFUF) plus curated usage examples and one-liners for testing XSS, SQLi, SSRF, LFI and auth-bypass. GPL-3.0.

    Open ↗
  2. A maintained collection of roughly 13,760 Google search queries (dorks) in a single text file for locating publicly indexed sites and exposed files/vulnerabilities via search-engine syntax.

    Open ↗
  3. A categorized collection of 40+ Google search queries (dorks) for bug-bounty and pentest reconnaissance, targeting exposed config/log files, XSS/SQLi/SSRF/LFI-prone parameters, API endpoints, login/test environments, cloud storage misconfigurations, and leaked credentials. It also includes an interactive dork tool and links to related dork collections.

    Open ↗
  4. Large curated index of open-source-intelligence tools and resources across search engines (incl. dark web), social-media intelligence, domain/IP research, email verification, people investigation, data-breach search, and geospatial tooling. ~28k stars.

    Open ↗
  5. A curated, security-specific directory of ~200+ open-source bug-bounty and pentest tools organized by phase and vulnerability class: reconnaissance (subdomain enum, port scanning, content discovery), exploitation (SQLi, XSS, XXE, SSRF, CSRF, command injection), and specialized scanning (JWT, S3 buckets, CMS, WAF evasion). CC0-licensed.

    Open ↗