Skip to main content
buildradar
Sign in
Topic · reconnaissance

reconnaissance

Tracked open-source repos tagged reconnaissance, sorted by stars.

78 repos
  • metabigor@j3ssie

    OSINT power without API key hassle

    1,755+19Star change over the last 7 days
  • shuffledns@projectdiscovery

    MassDNS wrapper written in go to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard filtering and easy input-output support.

    1,669+5Star change over the last 7 days
  • inventory@trickest

    Asset inventory of over 800 public bug bounty programs.

    1,604+1Star change over the last 7 days
  • GooFuzz@m3n0sd0n4ld

    GooFuzz is a tool to perform fuzzing with an OSINT approach, managing to enumerate directories, files, subdomains or parameters without leaving evidence on the target's server and by means of advanced Google searches (Google Dorking).

    1,583-1Star change over the last 7 days
  • GitGot@BishopFox

    Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.

    1,572+0Star change over the last 7 days
  • OpenOSINT@OpenOSINT

    AI-powered OSINT agent with interactive REPL, MCP server, and CLI. 19 tools. Works with Claude, GPT-4, or local models. For authorized security research only.

    1,513+32Star change over the last 7 days
  • r4ven@spyboy-productions

    Track the GPS location of the user's smartphone or PC and capture a picture of the target, along with IP and device information.

    1,497+4Star change over the last 7 days
  • AttackSurfaceMapper@superhedgy

    AttackSurfaceMapper is a tool that aims to automate the reconnaissance process.

    1,405+0Star change over the last 7 days
  • public-bugbounty-programs@projectdiscovery

    Community curated list of public bug bounty and responsible disclosure programs.

    1,342+1Star change over the last 7 days
  • secator@freelabz

    secator - the pentester's swiss knife

    1,306-1Star change over the last 7 days
  • webcopilot@h4r5h1t

    An automation tool that enumerates subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for vulnerabilities.

    1,295+0Star change over the last 7 days
  • scilla@edoardottt

    Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration

    1,264+1Star change over the last 7 days
  • OffSec OSINT Pentest/RedTeam Tools

    1,264+3Star change over the last 7 days
  • Buildware-Tools@v4lkyr0

    Buildware-Tools is an all-in-one multitool for security research and automation.

    1,245+42Star change over the last 7 days
  • recon-skills@uphiago

    Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh

    1,224+18Star change over the last 7 days
  • MailAccess@KatrielMoses

    Free email OSINT tool, 2500+ platforms, identity clustering, breach detection. No API keys required. pip install mailaccess

    1,182+100Star change over the last 7 days
  • pywerview@the-useless-one

    A (partial) Python rewriting of PowerSploit's PowerView

    1,133+0Star change over the last 7 days
  • sitedorks@Zarcolio

    Search Google/Bing/Ecosia/DuckDuckGo/Yandex/Yahoo for a search term (dork) with a default set of websites, bug bounty programs or custom collection.

    1,054-1Star change over the last 7 days
  • karma_v2@Dheerajmadhukar

    ⡷⠂𝚔𝚊𝚛𝚖𝚊 𝚟𝟸⠐⢾ is a Passive Open Source Intelligence (OSINT) Automated Reconnaissance (framework)

    1,024+3Star change over the last 7 days
  • OpenDoor@stanislav-web

    OWASP Web Recon & Directory Discovery Platform

    1,004+3Star change over the last 7 days
  • airecon@pikpikcu

    AIRecon is an autonomous cybersecurity agent that combines a self-hosted Large Language Model (Ollama) with a Kali Linux Docker sandbox and a Textual TUI. It is designed to automate security assessments, penetration testing, and bug bounty reconnaissance — without any API keys or cloud dependency.

    984+7Star change over the last 7 days
  • mailcat@sharsil

    Find existing email addresses by nickname using API/SMTP checking methods without user notification. Please, don't hesitate to improve cat's job! 🐱🔎 📬

    941+7Star change over the last 7 days
  • BugBountyScanner@chvancooten

    A Bash script and Docker image for Bug Bounty reconnaissance. Intended for headless use.

    923+1Star change over the last 7 days
  • urlfinder@projectdiscovery

    A high-speed tool for passively gathering URLs, optimized for efficient and comprehensive web asset discovery without active scanning.

    910+6Star change over the last 7 days
  • DataSurgeon@Drew-Alleman

    Quickly Extracts IP's, Email Addresses, Hashes, Files, Credit Cards, Social Security Numbers and a lot More From Text

    904+2Star change over the last 7 days
  • SatIntel@ANG13T

    SatIntel is an OSINT tool for Satellites 🛰. Extract satellite telemetry, receive orbital predictions, and parse TLEs 🔭

    900+1Star change over the last 7 days
  • getJS@003random

    A tool to fastly get all javascript sources/files

    892+2Star change over the last 7 days
  • Work in progress...

    845+3Star change over the last 7 days
  • sicat@justakazh

    The useful exploit finder

    830+2Star change over the last 7 days
  • Garud@R0X4R

    An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.

    811+0Star change over the last 7 days
← Back to topics