π Reconnaissance & OSINT
This category focuses on information gathering and reconnaissance, split between passive footprinting and active network scanning.
Tool Catalog
Select a tool below to view detailed specifications, cheatsheets, or definitions.
Naabu
High-speed TCP/UDP port scanner utilizing raw socket sweeps to identify active service endpoints.
Nmap
Advanced network scanning, port enumeration, service fingerprinting, and Lua script-based audits.
Maltego
Graphical link analysis and relation mapping tool for mapping out digital footprints and open source intelligence.
Shodan / Censys / FOFA
Search engines for internet-connected devices, certificates, exposing open ports, services, and vulnerabilities.
theHarvester
E-mail, subdomain, IP range, and employee name harvester querying public sources and search engines.
Recon-ng
Full-featured Web Reconnaissance Framework written in Python with modular query API wrappers.
SpiderFoot
Automated OSINT reconnaissance tool that queries hundreds of public databases to compile risk analysis heatmaps.
OSINT Framework
Web directory cataloging free OSINT data sources organized by information type.
crt.sh / certspotter
SSL/TLS Certificate Transparency logs scraping pipelines to harvest wildcards and subdomains.
Masscan
Asynchronous TCP port scanner capable of scanning the entire Internet in under 6 minutes.
RustScan
Fast modern port scanner written in Rust that integrates directly with Nmap for service detection.
DNSx / HTTPx
Bulk multi-threaded DNS resolution and HTTP web server verification tools by ProjectDiscovery.
Katana / Gospider
High-performance web spiders and crawlers designed to parse client-side scripts and gather URL links.