{"id":13844790,"url":"https://github.com/0xspade/Automated-Scanner","last_synced_at":"2025-07-12T00:31:41.685Z","repository":{"id":91949552,"uuid":"175115697","full_name":"0xspade/Automated-Scanner","owner":"0xspade","description":"Trying to make automated recon for bug bounties","archived":false,"fork":false,"pushed_at":"2021-05-03T09:25:06.000Z","size":1267,"stargazers_count":251,"open_issues_count":6,"forks_count":53,"subscribers_count":15,"default_branch":"master","last_synced_at":"2024-08-05T17:43:05.279Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/0xspade.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null}},"created_at":"2019-03-12T01:59:18.000Z","updated_at":"2024-06-30T12:41:05.000Z","dependencies_parsed_at":"2024-02-16T16:24:18.472Z","dependency_job_id":"aac52491-a759-489b-976e-887ea80d1dde","html_url":"https://github.com/0xspade/Automated-Scanner","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xspade%2FAutomated-Scanner","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xspade%2FAutomated-Scanner/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xspade%2FAutomated-Scanner/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xspade%2FAutomated-Scanner/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/0xspade","download_url":"https://codeload.github.com/0xspade/Automated-Scanner/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":225772752,"owners_count":17521882,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T17:02:56.981Z","updated_at":"2024-11-21T17:30:48.134Z","avatar_url":"https://github.com/0xspade.png","language":"Shell","funding_links":[],"categories":["Shell (473)","Shell"],"sub_categories":[],"readme":"[![Follow on Twitter](https://img.shields.io/twitter/follow/0xspade.svg?logo=twitter)](https://twitter.com/0xpsade)\n[![Follow on Twitter](https://img.shields.io/twitter/follow/sumgr0.svg?logo=twitter)](https://twitter.com/sumgr0)\n\n# Installation \nFor the installation of all the tools below. I linked all the github links, just make sure that its in the right directory PATH and your good to go. feel free to modify and feel free not to use it if you don't like it :)\n\n**ALL CREDIT GOES TO AMAZING CREATORS OF THIS WONDERFUL TOOLS :)**\n\n\u003csup\u003ecannot make to mention y'all co'z i'm too lazy to do that though :D (i'm being honest here)\u003c/sup\u003e\n## List of tools to be installed\n\ngolang\n- amass\n- subfinder\n- assetfinder\n- zcat\n- goaltdns\n- shuffledns\n- dnsprobe\n- ffuf\n- httprobe\n- tko-subs\n- subjack\n- zdns\n- aquatone\n- webanalyze\n- gau\n- getching\n- kxss\n- dalfox\n\nAPT-GET\n- jq\n- grepcidr\n- nmap\n- masscan\n- brutespray\n\nDownload Only\n- findomain\n- github-endpoints\n- github-secrets\n- smuggler\n\nGIT\n- massdns\n- S3Scanner\n- LinkFinder\n- defparam smuggler\n\nPIP\n- shodan\n\n# How to use\n\nUsage: `~$ bash scanner.sh example.com`\n\nRunning in background in VPS using nohup\n\nUsage: `~$ nohup bash scanner.sh example.com \u0026\u003e example.out\u0026`\n\n\n### Need a Digitalocean?\n\nFree $100 in DigitalOcean, just click the link below :D\n\n[![DigitalOcean Referral Badge](https://web-platforms.sfo2.cdn.digitaloceanspaces.com/WWW/Badge%201.svg)](https://www.digitalocean.com/?refcode=9d633afb889b\u0026utm_campaign=Referral_Invite\u0026utm_medium=Referral_Program\u0026utm_source=badge)\n\n## Contributor\n\nBig thanks to [@sumgr0](https://twitter.com/sumgr0) :)\n\n## Links \n\n----\n**Subdomain Enumeration**\n* [Amass](https://github.com/OWASP/Amass) brute with [wordlist](https://github.com/ZephrFish/Wordlists/blob/master/HugeDNS.7z)\n* [Findomain](https://github.com/Edu4rdSHL/findomain)\n* [Subfinder](https://github.com/subfinder/subfinder)\n* [Assetfinder](https://github.com/tomnomnom/assetfinder)\n* [Rapid7's Project Sonar](https://opendata.rapid7.com/sonar.fdns_v2/)\n\u003ehttps://github.com/phspade/Project_Sonar_R7\n* [goaltdns](https://github.com/subfinder/goaltdns) + [massdns](https://github.com/blechschmidt/massdns)\n\n**Scan All Alive Hosts with [Httprobe](https://github.com/tomnomnom/httprobe)**\n\n* Getting All IP from the subdomains collected with [DNSProbe](https://github.com/projectdiscovery/dnsprobe)\n\n**Separating Cloudflare, Incapsula, Sucuri, and Akamai IPs from collected IPs**\n\u003eIt's useless to scan Cloudflare, Incapsula, Sucuri, and Akamai IPs. *(Just like talking to a wall)*\n\u003e\n\u003eFYI, Install grepcidr first `apt-get install grepcidr`\n\n* S3 Bucket scanner with [s3scanner](https://github.com/sa7mon/S3Scanner)\n\n**Subdomain TakeOver**\n* [tko-subs](https://github.com/anshumanbh/tko-subs)\n* [Subjack](https://github.com/haccer/subjack)\n\n**Collecting Endpoints thru [Linkfinder](https://github.com/GerbenJavado/LinkFinder/)**\n\n**Collecting [Endpoints](https://github.com/gwen001/github-search/blob/master/github-endpoints.py) and [Secrets](https://github.com/gwen001/github-search/blob/master/github-secrets.py) in Github**\n\u003emake sure to create `.tokens` file *(containing your github token)* together with `github-endpoints.py` and `github-secrets.py` *(probably in ~/tools folder)*.\n\n**[HTTP Request Smuggler](https://github.com/gwen001/pentest-tools/blob/master/smuggler.py)**\n\n**[ZDNS](https://github.com/zmap/zdns)**\n\n**[Shodan](https://cli.shodan.io/)**\n\n**[Aquatone](https://github.com/michenriksen/aquatone)**\n\n**Port Scanning**\n* NMAP\n* masscan\n\n**[Webanalyze](https://github.com/rverton/webanalyze) for Fingerprinting assets**\n\n**File/Dir Discovery**\n* [gau](https://github.com/lc/gau) + [getching](https://github.com/phspade/getching)\n\n**Potential XSS**\n* [kxss](https://github.com/tomnomnom/hacks/tree/master/kxss)\n\n* [dalfox](https://github.com/hahwul/dalfox)\n\n**[Virtual Hosts](https://github.com/ffuf/ffuf) Scan**\n\n* 401 Basic Authorization Bruteforce with FFUF\n\u003eSome subdomains has 401 authentication basic, so we need to bruteforce it with base64 credentials :)\n\n* [FFUF](https://github.com/ffuf/ffuf)\n\n\u003eAdded **X-Forwarded-For Header** *(you should [setup your own dns server](https://medium.com/@spade.com/a-noob-guide-to-setup-your-own-oob-dns-server-870d9e05b54a))* to check for IP Spoofing Attack.\n\nFeel free to modify it on your own if you don't feel about on how it works :)\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2F0xspade%2FAutomated-Scanner","html_url":"https://awesome.ecosyste.ms/projects/github.com%2F0xspade%2FAutomated-Scanner","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2F0xspade%2FAutomated-Scanner/lists"}