Subdomain Discovery Engine
Python script combining 8 passive sources for subdomain discovery: crt.sh, SecurityTrails, VirusTotal, Shodan, Archive.org, and more.
Professional offensive security tools & exploit frameworks
Python script combining 8 passive sources for subdomain discovery: crt.sh, SecurityTrails, VirusTotal, Shodan, Archive.org, and more.
Tool that scans an organization's GitHub repositories for leaked secrets: API keys, passwords, tokens, private keys.
Script that collects corporate emails from a domain using Hunter.io, TheHarvester, LinkedIn scraping, and automated Google dorks.
Collection of 200+ Shodan dorks organized by technology and vulnerability, with automated execution script and alerts.
Python web fingerprinting module that identifies technologies, versions, WAFs, CDNs, and frameworks by analyzing headers, cookies, HTML, and JavaScript.
Script that downloads and analyzes public documents (PDF, DOCX, XLSX) from a domain, extracting metadata: authors, software, internal paths, emails.
Tool that discovers an organization's cloud assets: S3 buckets, Azure blobs, GCP storage, cloud subdomains, and cloud service IPs.
SOCMINT collection framework: employee profiles on LinkedIn, Twitter, GitHub with identity correlation and timeline analysis.
Passive and active DNS analysis tool: zone transfers, DNSSEC walking, DNS history, and misconfiguration detection.
Python script with Tor integration that monitors paste sites, forums, and .onion marketplaces for mentions of a domain or organization.