All Categories → Security → recon

Top 127 recon open source projects

Bigbountyrecon
BigBountyRecon tool utilises 58 different techniques using various Google dorks and open source tools to expedite the process of initial reconnaissance on the target organisation.
Reconpi
ReconPi - A lightweight recon tool that performs extensive scanning with the latest tools.
Odin
Automated network asset, email, and social media profile discovery and cataloguing.
Nullinux
Internal penetration testing tool for Linux that can be used to enumerate OS information, domain information, shares, directories, and users through SMB.
Shotlooter
a recon tool that finds sensitive data inside the screenshots uploaded to prnt.sc
Censys Subdomain Finder
⚡ Perform subdomain enumeration using the certificate transparency logs from Censys.
Dnsgen
Generates combination of domain names from the provided input.
Buster
An advanced tool for email reconnaissance
Osint team links
Links for the OSINT Team
Maryam
Maryam: Open-source Intelligence(OSINT) Framework
Docker Onion Nmap
Scan .onion hidden services with nmap using Tor, proxychains and dnsmasq in a minimal alpine Docker container.
Zen
Find emails of Github users
Natlas
Scaling Network Scanning. Changes prior to 1.0 may cause difficult to avoid backwards incompatibilities. You've been warned.
Reconnote
Web Application Security Automation Framework which recons the target for various assets to maximize the attack surface for security professionals & bug-hunters
Vajra
Vajra is a highly customizable target and scope based automated web hacking framework to automate boring recon tasks and same scans for multiple target during web applications penetration testing.
Pulsar
Network footprint scanner platform. Discover domains and run your custom checks periodically.
Meerkat
A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.
Lazyrecon
An automated approach to performing recon for bug bounty hunting and penetration testing.
Recon Pipeline
An automated target reconnaissance pipeline.
Recon My Way
This repository created for personal use and added tools from my latest blog post.
Megplus
Automated reconnaissance wrapper — TomNomNom's meg on steroids. [DEPRECATED]
Priest
Extract server and IP address information from Browser SSRF
fransRecon
Script will enumerate domain name using horizontal enumeration, reverse lookup. Each horziontal domain will then be vertically enumerated using Sublist3r.
leaky-paths
A collection of special paths linked to major web CVEs, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to scan passively for high-quality endpoints and quick-wins.
targets
A collection of over 5.1 million sub-domains and assets belonging to public bug bounty programs, compiled into a repo, for performing bulk operations.
querytool
Querytool is an OSINT framework based on Google Spreadsheets. With this tool you can perform complex search of terms, people, email addresses, files and many more.
nuubi
Nuubi Tools (Information-ghatering|Scanner|Recon.)
osmedeus-workflow
Community Workflow for the Osmedeus Engine that describes basic reconnaissance methodology for you to build your own
SubWalker
Simultaneously execute various subdomain enumeration tools and aggregate results.
OffensiveCloudDistribution
Leverage the ability of Terraform and AWS or GCP to distribute large security scans across numerous cloud instances.
Reconky-Automated Bash Script
Reconky is an great Content Discovery bash script for bug bounty hunters which automate lot of task and organized in the well mannered form which help them to look forward.
burp-ntlm-challenge-decoder
Burp extension to decode NTLM SSP headers and extract domain/host information
asnap
asnap aims to render recon phase easier by providing updated data about which companies owns which ipv4 or ipv6 addresses and allows the user to automate initial port and service scanning.
cero
Scrape domain names from SSL certificates of arbitrary hosts
mailcat
Find existing email addresses by nickname using API/SMTP checking methods without user notification. Please, don't hesitate to improve cat's job! 🐱🔎 📬
learn
RECON learn: a free, open platform for training material on epidemics analysis
Sub-Drill
A very (very) FAST and simple subdomain finder based on online & free services. Without any configuration requirements.
recon ex
Elixir wrapper for Recon, tools to diagnose Erlang VM safely in production
WhoEnum
Mass querying whois records
apkizer
apkizer is a mass downloader for android applications for all available versions.
s3recon
Amazon S3 bucket finder and crawler.
XposedOrNot
XposedOrNot (XoN) tool is to search an aggregated repository of xposed passwords comprising of ~850 million real time passwords. Usage of such compromised passwords is detrimental to individual account security.
sharingan
Offensive Security recon tool
ICU
An Extended, Modulair, Host Discovery Framework
o365chk
Simple Python tool to check if there is an Office 365 instance linked to a domain.
61-120 of 127 recon projects