🌐 Reconnaissance & OSINT

This category focuses on information gathering and reconnaissance, split between passive footprinting and active network scanning.

Tool Catalog

Select a tool below to view detailed specifications, cheatsheets, or definitions.

🎯

Naabu

High-speed TCP/UDP port scanner utilizing raw socket sweeps to identify active service endpoints.

View Wiki β†’
πŸ›‘οΈ

Nmap

Advanced network scanning, port enumeration, service fingerprinting, and Lua script-based audits.

View Wiki β†’
πŸ—ΊοΈ

Maltego

Graphical link analysis and relation mapping tool for mapping out digital footprints and open source intelligence.

πŸ”Ž

Shodan / Censys / FOFA

Search engines for internet-connected devices, certificates, exposing open ports, services, and vulnerabilities.

πŸ¦…

theHarvester

E-mail, subdomain, IP range, and employee name harvester querying public sources and search engines.

βš™οΈ

Recon-ng

Full-featured Web Reconnaissance Framework written in Python with modular query API wrappers.

πŸ•·οΈ

SpiderFoot

Automated OSINT reconnaissance tool that queries hundreds of public databases to compile risk analysis heatmaps.

πŸ•ΈοΈ

OSINT Framework

Web directory cataloging free OSINT data sources organized by information type.

πŸ“œ

crt.sh / certspotter

SSL/TLS Certificate Transparency logs scraping pipelines to harvest wildcards and subdomains.

⚑

Masscan

Asynchronous TCP port scanner capable of scanning the entire Internet in under 6 minutes.

πŸ¦€

RustScan

Fast modern port scanner written in Rust that integrates directly with Nmap for service detection.

πŸ›°οΈ

DNSx / HTTPx

Bulk multi-threaded DNS resolution and HTTP web server verification tools by ProjectDiscovery.

βš”οΈ

Katana / Gospider

High-performance web spiders and crawlers designed to parse client-side scripts and gather URL links.


πŸ”— Back to Toolkit