Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

awesome-recon-tools

A compiled list of tools for reconnaissance and footprinting
https://github.com/nateahess/awesome-recon-tools

  • ARIN Whois/RDAP - A public resource that allows a user to retrieve information about IP number resources, organizations, and Points of Contact registered with ARIN.
  • Aquatone - A tool for visual inspection of websites across a large amount of hosts. Very convenient for quickly gaining an overview of HTTP-based attack surfaces.
  • Batch IP Converter - An award-winning network tool to work with IP addresses. Domain-to-IP Converter, Batch Ping, Tracert, Whois, and more.
  • BuiltWith - Scans for over 46,953 different web technologies. Discover what tools a site uses such as shopping carts, hosting, analytics, and more.
  • Censys - Mines a global internet dataset to enumerate assets that may compromise an attack surface.
  • DataSploit - Performs automated OSINT on a domain/email/username/phone and finds relevant information from different sources.
  • DNSDumpster - Can discover hosts related to a domain. Map an organizations attack surface with a virtual "dumpster dive."
  • Domaintools - Find Whois information quickly and easily including registrar, name servers, and etc.
  • FindSubDomains - From Spyse. Awesome tool to find subdomains.
  • FireCompass - Discovers and organization's digital attack surface.
  • Informer - Retrieves a quick aggregated view of everything the Web can promptly tell you about a site.
  • Maltego - Open Source Intelligence (OSINT) and graphical link analysis tool for gathering and connecting information for investigative tasks.
  • Netcraft - Multiple tools from site report to DNS search.
  • Professional Toolset - Ping, Tracert, HTTP Headers, and more!
  • Shodan - Shodan has servers around the world that crawl the internet 24/7 to provide the latest internet intelligence.
  • SpiderFoot - Automated OSINT collection!
  • Traceroute NG - Continuous probing, detects path changes, supports IPv4 & IPv6, Creates a txt logfile.
  • URL Fuzzer - Free light scan for hidden files and directories.
  • VisualRoute - Continuous trace routing, reverse tracing, port probing, route analysis, and much more!
  • You Get Signal - Port forwarding, network location, visual trace route, reverse IP domain check, and more!
  • Wappalyzer - Identify technologies on websites. Find out the technology stack of any website.
  • WebShag - Multi-threaded, multi-platform web server audit tool. Gathers useful functionalities for web server auditing like website crawling, URL scanning, or file fuzzing.
  • Wireshark - The world's foremost and widely-used network protocol analyzer.
  • Whois.net - Quick and easy Whois lookup. Domain name search, registration and availability, and more.
  • nslookup - Command-line tool for querying the Domain Name System to obtain name or IP address mapping and other DNS records.
  • tracert - Commmand-line tool for displaying a route and measuring transit delays of packets across an Internal Protocol network.
  • dig - Domain Information Groper - Queries the DNS of a given server.
  • dnsrecon - Check NS Records for Zone Transfers, enumerate general DNS records, check cached DNS records, and more.
  • dnstracer - Determines where a given Domain Name Server gets its information from for a given hostname.
  • Fierce - DNS reconnaissance tool for locating non-contiguous IP space.
  • Ghost Eye - Information gathering tool for Whois, DNS, EtherApe, Nmap, and more.
  • recon-ng - Provides a powerful environment to conduct open source web-based reconnaissance quickly and thoroughly.
  • traceroute - Print the route packets trace to network host.
  • unicornscan - Provides a superior interface for introducing a stimulus into and measuring a response from a TCP/IP enabled device or network.
  • whois - Quick and easy client for the whois directory service.
  • BeenVerified - Background checks with loads of information.
  • eMailTrackerPro - Pull detailed information from an email header. Also includes spam filtering.
  • Followerwonk - Information scraped from Twitter.
  • Infoga - Gather email OSINT. Domains, sources, breaches, and more.
  • Jigsaw - OSINT-X Intelligence Collection Tool from Jigsaw allows for the collection of data from RSS feeds, the dark web, Twitter, Facebook, and other sources.
  • PeekYou - Locate personal information from family members to social media accounts.
  • sherlock - Crawls the web for social profiles.
  • theHarvester - Pulls a list of email addresses of a specific domain from multiple search engines.