Tool · reconactivedual-use
ShadowHound
A PowerShell-based alternative to SharpHound for Active Directory enumeration, offering an AD-module path (ADWS) and a direct-LDAP DirectorySearcher path to collect users, groups, computers, and certificates. Output converts to BloodHound via BofHound; designed to reduce detection by avoiding known-malicious binaries.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
Dual-use security content. We link to the upstream project rather than re-hosting ready-to-fire files. Use only in authorized security testing.
More tools
- AmassreconDeep passive subdomain enumeration across many public sources.
- assetfinderreconFast passive subdomain discovery drawing on crt.sh, certspotter, hackertarget, threatcrowd and wayback.
- cdncheckreconClassifies a host as CDN, WAF or cloud and names the provider.
- dnsxreconFast DNS resolution and record enumeration from ProjectDiscovery.
- Fast Google Dorks ScanreconAn automated bash tool that runs a large set of Google dork search queries against a target domain to surface admin panels, widely-exposed file types and locations, and potential path-traversal exposures. Runs directly on Linux/Kali or via Docker, takes only a domain name as input, and supports an optional request proxy.
- github-searchreconCollection of Bash/Python/PHP scripts for reconnaissance against GitHub: credential/secret discovery, user and employee enumeration, dorking, subdomain enumeration, and repository/endpoint extraction. Authored by bug-bounty researcher gwen001.