Automated Bash pipeline for passive and active subdomain enumeration using Sublist3r, Subfinder, PureDNS, AltDNS, and MassDNS.
-
Updated
Jul 13, 2026 - Python
8000
Automated Bash pipeline for passive and active subdomain enumeration using Sublist3r, Subfinder, PureDNS, AltDNS, and MassDNS.
Bash recon automation that chains subdomain enumeration, live-host probing, fingerprinting, and vulnerability/port scanning into a single command built for authorized bug bounty and pentest recon
BaRecon is a Bash-based tool that performs basic reconnaissance on a network block, a domain and its subdomains, or a single IP address.
Security-aware URL deduplicator for recon pipelines.
The "Uh-Recon" tools used by Unhackers for pre-engagement reconnaissance
Ultimate Automation using tools like puredns, httpx, dnsx, smap, aquatone, waybackurls, gf, massdns, subzy, waymore, assetfinder, subfinder, and amass. Runs in Docker.
PyQt5-based GUI tool that unifies multiple reconnaissance utilities for active and passive information gathering
Passive Recon Suite — Harvest URLs, discover subdomains, filter live endpoints and extract parameters from public archives & OSINT sources.
An interactive CLI-based web scraping tool for automated information gathering from target websites.
Quick Offensive Security Toolkit
FlowOsint is an all-in-one web reconnaissance framework built for security researchers, penetration testers, and bug bounty hunters. Point it at a target and it automatically maps the attack surface — subdomains, hidden files, exposed secrets, misconfigurations, open ports, breach history, and more — all from a single interactive terminal menu.
A Recon/OSINT WHOIS/DNS enumerator tool coded in python
NetDeltaMonitor is a comprehensive network reconnaissance and port scanning tool designed with a focus on security and continuous monitoring.
Reverse IP & Subdomain enumeration tool : bulk scan with 30 threads, powered by 3B+ DNS records from dnsrift.net
PII-Scanner3 is a Python tool for bug bounty recon that automates 7 key phases, including subdomain discovery, endpoint finding, GitHub intel, and takeover detection, with CLI/TUI support and exportable reports.
It will help security researchers, red teamers and bug bounty hunters for their sub domain enumeration. It gathers all tools for subdomain enumeration for getting best results while looking for sub domain. It is open for any kind of suggestion for improvement. It is free also.
High-performance network reconnaissance engine built with a modular C11/Rust architecture. Features epoll-based async I/O, O(1) scheduling, and 5-level stealth profiling for advanced security auditing.
Advanced reconnaissance framework for bug bounty hunters - Automate subdomain enumeration, vulnerability scanning, and security reconnaissance with 30+ integrated tools.
AynOps Home Page
A web-based command center for reconnaissance tools like Nmap, Gobuster, and Assetfinder. Features real-time output, intelligent parsing, an automated exploit suggestion engine (searchsploit), and persistent scan history. Built with Python, FastAPI, and WebSockets.
Add a description, image, and links to the reconnaissance-tool topic page so that developers can more easily learn about it.
To associate your repository with the reconnaissance-tool topic, visit your repo's landing page and select "manage topics."