{"id":34572029,"url":"https://github.com/djnnvx/yellow","last_synced_at":"2026-03-12T06:00:38.750Z","repository":{"id":320093368,"uuid":"1006403472","full_name":"djnnvx/yellow","owner":"djnnvx","description":"pentest companion on the CLI (project mirror)","archived":false,"fork":false,"pushed_at":"2026-02-01T08:33:25.000Z","size":406,"stargazers_count":1,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"current","last_synced_at":"2026-02-01T19:08:20.286Z","etag":null,"topics":["automation","osint","pentest","recon","scanner","web"],"latest_commit_sha":null,"homepage":"https://evil.djnn.sh/yellow/file/README.md.html","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/djnnvx.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.txt","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2025-06-22T07:27:27.000Z","updated_at":"2026-02-01T08:33:28.000Z","dependencies_parsed_at":null,"dependency_job_id":"c0f4d83e-30f6-4336-a782-b584b5a53124","html_url":"https://github.com/djnnvx/yellow","commit_stats":null,"previous_names":["djnnvx/yellow"],"tags_count":3,"template":false,"template_full_name":null,"purl":"pkg:github/djnnvx/yellow","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/djnnvx%2Fyellow","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/djnnvx%2Fyellow/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/djnnvx%2Fyellow/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/djnnvx%2Fyellow/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/djnnvx","download_url":"https://codeload.github.com/djnnvx/yellow/tar.gz/refs/heads/current","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/djnnvx%2Fyellow/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":30416724,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-03-12T04:41:02.746Z","status":"ssl_error","status_checked_at":"2026-03-12T04:40:12.571Z","response_time":114,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["automation","osint","pentest","recon","scanner","web"],"created_at":"2025-12-24T09:40:17.239Z","updated_at":"2026-03-12T06:00:38.745Z","avatar_url":"https://github.com/djnnvx.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"~ yellow\n\n```\n        ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣤⣤⣤⣤⣤⣤⣤⣄⣀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀\n    ⠀              ⠀⠀⠀⠀⠀⠀⠀⠀⠉⠉⠛⠻⠿⢿⣿⣿⣿⣿⣿⣶⣤⣀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀\n   Y E L L O W ⠀⠀⠀⢀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠙⠻⣿⣿⣿⣿⣿⣿⣶⣄⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀\n        ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⣿⣷⣤⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠙⢿⣿⣿⣿⣿⣿⣿⣦⡀⠀⠀⠀⠀⠀⠀⠀\n      --------  ⠀⠀⢸⣿⣿⣿⣿⣷⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣀⣀⣀⣀⣀⣙⢿⣿⣿⣿⣿⣿⣿⣦⡀⠀⠀⠀⠀⠀\n        ⠀⠀⠀⠀  ⠀⠀⠀⠀⠀⢿⣿⣿⣿⣿⣿⣿⣿⣿⣶⣶⣶⣶⣿⣿⣿⣿⣿⣿⣿⣿⣿⠀⠻⣿⣿⣿⣿⣿⣿⣿⣄⠀⠀⠀⠀\n        djnn.sh⠀⠀⠀⠀⠘⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠇⠀⠀⢹⣿⣿⣿⣿⣿⣿⣿⣆⠀⠀⠀\n        ⠀v0.0.5  ⠀⠀⢠⣿⣿⣿⣿⡟⠹⠿⠟⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡏⠀⠀⠀⠀⢿⣿⣿⣿⣿⣿⣿⣿⡆⠀⠀\n        ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⡿⠋⡬⢿⣿⣷⣤⣤⣴⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠟⠀⠀⠀⠀⠀⠸⣿⣿⣿⣿⣿⣿⣿⣿⡀⠀\n        ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠰⡇⢸⡇⢸⣿⣿⣿⠟⠁⢀⣬⢽⣿⣿⣿⣿⣿⣿⠋⠀⠀⠀⠀⠀⠀⠀⣿⣿⣿⣿⣿⣿⣿⣿⣧⠀\n        ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣼⣧⣈⣛⣿⣿⣿⡇⠀⠀⣾⠁⢀⢻⣿⣿⣿⣿⠇⠀⠀⠀⠀⠀⠀⠀⠀⣿⣿⣿⣿⣿⣿⣿⣿⣿⡀\n        ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢹⣿⣿⣿⣿⣿⣿⣧⣄⣀⠙⠷⢋⣼⣿⣿⣿⡟⠀⠀⠀⠀⠀⠀⠀⠀⢀⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇\n        ⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠻⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣿⣿⣿⣿⡟⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇\n        ⣿⡄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠙⠻⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡟⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠁\n        ⣿⣿⡄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠘⣿⣿⣿⣿⣿⣿⣿⣿⣿⣦⡀⠀⠀⠀⠀⠀⠀⢀⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠀\n        ⠸⣿⣿⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢰⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣦⡀⠀⠀⠀⢀⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠃⠀\n        ⠀⢹⣿⣿⣧⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣄⣴⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠏⠀⠀\n        ⠀⠀⠹⣿⣿⣿⣷⣄⠀⠀⠀⠀⠀⠀⠀⠀⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠏⠀⠀⠀\n        ⠀⠀⠀⠙⣿⣿⣿⣿⣿⣶⣤⣀⠀⠀⠀⠀⣿⣿⣿⣿⣿⣿s/o jenaye :)~⣿⣿⣿⣿⣿⣿⠋⠀⠀⠀⠀\n        ⠀⠀⠀⠀⠈⠻⣿⣿⣿⣿⣿⣿⣿⣷⣶⣶⣾⣿⣿⣿⣿⣿⣿⣿⣿matro7sh⣿⣿⣿⣿⣿⣿⣿⠟⠁⠀⠀⠀⠀⠀\n        ⠀⠀⠀⠀⠀⠀⠉⠻⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀\n        ⠀⠀⠀⠀⠀⠀⠀⠀⠈⠛⠿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠿⠋⠅⠀⠀⠀⠀⠀⠀⠀⠀⠀\n        ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠙⠻⠿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠿⠛⠉⠀⠀⠀⠀⠀⠀⠀⠀⠈⠂⠀⠀⠀\n        ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠉⠉⠛⠛⠛⠛⠛⠛⠛⠋⠉⠉⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀\n\n    \u003c=[ Pentest companion for scanning, OSINT, and quick wins ]=\u003e\n```\n\n**yellow** is a tiny golang CLI to quickly set up scanning at the beginning of a pentest. :)~\n\nBased on yelaa: https://github.com/matro7sh/Yelaa.\n\n# 1. Disclaimer\n\nThis software is provided as-is, at the discretion of professionals.\nDeveloppers assume no responsability for your lack of morals or overall stupidity.\nPlease use at your own risk, in a controlled environnement. Thanks\u003c3\n\n\n# 2. Roadmap\n\nFor next version, i want to take care of at least two items described here:\n\n* scan: integrate browser-dependant tools (katana, ...) (still TBD),\n* osint: add support for more dorks\n\n## 2.a Bugfixes\n\n* sitemap should be stored to a file \u0026 fetch robots.txt\n\nfeel free to suggest more ideas. :)~\nif you'd like to do so, reach me by mail or on social media: https://djnn.sh/pgp\n\n## 2.b Contributing\n\nThis software's code is public, but not open to contributions.\nThe reason for that is that if something is integrated, I want to make sure I\nam able to maintain it afterwards.\n\n# 3. Installing\n\nUsing go v1.25.\n\n```bash\ngit clone https://evil.djnn.sh/yellow.git\n\ncd yellow/\n\nmake\n```\n\n## 3.a Using docker\n\n```bash\ncd yellow/\n\nmake docker\n```\n\n# 4. Running\n\n## 4.a Create your directory tree\n\nAt the beginning of your mission, you might want to have a nice little dir tree.\nEasy enough:\n\n```bash\n./yellow -d djnn.sh\n\n# example tree output for djnn.sh/\ndjnn.sh\n├── extracted\n│   ├── assets\n│   ├── code\n│   └── creds\n├── scans\n│   ├── infra\n│   ├── nessus\n│   ├── screenshots\n│   └── ssl\n└── www\n    ├── exploits\n    └── tools\n\n13 directories, 0 files\n```\n\n## 4.b Run passive enumeration\n\nRun various scans to retrieve more targets, using OSINT techniques.\n\n```bash\n./yellow osint --help\n\n# or, if in a hurry\n./yellow osint -d djnn.sh\n```\n\n## 4.c Run active scans\n\nRun scans against the target actively. (You might want to use a proxy for this !)\n\n```bash\n./yellow scan --help\n\n# run scan on ports 80, 443, 8080 \u0026 8443\nnmap -T4 -Pn -p 80,443,8080,8443 --open -oA domains -iL djnn.sh/scans/domains.txt\ncat *.gnmap | grep -i \"open/tcp\" | cut -d \" \" -f2 | sort -u \u003e djnn.sh/scans/web-targets.txt\n\n# you can also just run the domains.txt file directly\n\n./yellow scan -d djnn.sh/scans/infra --file djnn.sh/scans/web-targets.txt\n```\n\n#### Running port scans:\n\nYou can run a TCP port scan with service fingerprinting as part of the scan command:\n\n```bash\n./yellow scan -d djnn.sh --port-scan\n# or with custom ports\n./yellow scan -d djnn.sh --port-scan --ports \"22,80,443,8080-8090\"\n```\n\n#### Filter inactive web domains from a list of domains:\n\nThe `osint` subcommand is nice, but as it retrieves historical domains, it means there are\nsome domains that are not reachable anymore. To filter them out, you can run:\n\n```bash\n./yellow prune -f djnn.sh/scans/domains.txt -o djnn.sh/scans/cleaned-web-targets.txt\n```\n\n#### Retrieving CVEs automatically:\n\nCVE lookups use the [NVD API v2](https://nvd.nist.gov/developers/vulnerabilities) (NIST National\nVulnerability Database) — no account required. Results are queried by detected technology name and\nsaved to `cves.json` in your scan path.\n\nWithout an API key, NVD allows 5 requests per 30 seconds (yellow sleeps 7s between queries to stay\nsafe). For faster scans, grab a free key at https://nvd.nist.gov/developers/request-an-api-key\nand set it:\n\n```bash\nexport NVD_API_KEY=your-key-here\n```\n\n#### Credential Leak Checking (Leaker)\n\nThe `osint` subcommand can check for credential leaks using the integrated\n[leaker](https://github.com/vflame6/leaker) library.\n\nSome leaker sources (like LeakCheck) require API keys. Create a provider config file:\n\n```yaml\n# ~/.config/leaker/provider-config.yml\nleakcheck: [your-api-key-here]\n```\n\nSet the config path via environment variable:\n\n```bash\nexport LEAKER_PROVIDER_CONFIG=~/.config/leaker/provider-config.yml\n```\n\nUsage:\n\n```bash\n./yellow osint -d target.com --emails /path/to/emails.txt\n```\n\n#### Running fingerprinting\n\nIf you don't want to scan the whole website, but just run the fingerprint and retrieve the CVEs,\nyou can also run this:\n\n```bash\n./yellow fingerprint -d djnn.sh/scans/infra --file djnn.sh/scans/web-targets.txt\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdjnnvx%2Fyellow","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fdjnnvx%2Fyellow","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdjnnvx%2Fyellow/lists"}