#recon (29 Repositories)
Ranked open-source repositories tagged with #recon, scored by pull request acceptance likelihood and maintainer engagement velocity.
14.5%
22.8h
29 repositories tagged #recon
leebaird/discover
Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload creation using Metasploit. For use with Kali Linux and Ubuntu.
edoardottt/csprecon
Discover new target domains using Content Security Policy
oasm-platform/open-asm
AI-powered open-source platform for Attack Surface Management (OASM)
laramies/theHarvester
E-mails, subdomains and names Harvester - OSINT
shuvonsec/claude-bug-bounty
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.
reconurge/flowsint
A modern platform for visual, flexible, and extensible graph-based investigations. For cybersecurity analysts and investigators.
blacklanternsecurity/bbot
The recursive internet scanner for hackers. 🧡
rix4uni/medium-writeups
This repository updates latest Bug Bounty medium writeups every 10 minutes, https://readmedium.com/Medium_URL, https://archive.ph/Medium_URL, https://freedium.cfd/Medium_URL
003random/getJS
A tool to fastly get all javascript sources/files
utkusen/shotlooter
a recon tool that finds sensitive data inside the screenshots uploaded to prnt.sc
Chocapikk/wpprobe
A fast WordPress plugin enumeration tool
mhmdiaa/second-order
Second-order subdomain takeover scanner
pablosnt/rekono
Offensive security platform that automates attack surface discovery and vulnerability management
0xdekster/ReconNote
Web Application Security Automation Framework which recons the target for various assets to maximize the attack surface for security professionals & bug-hunters
six2dez/dorks_hunter
Simple Google Dorks search tool
hakluke/hakip2host
hakip2host takes a list of IP addresses via stdin, then does a series of checks to return associated domain names.
six2dez/reconftw
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
olizimmermann/s3dns
Find S3 AWS/GCP/Azure buckets while surfing. S3DNS acts as DNS server, follows CNAMEs and matches any bucket pattern
owasp-amass/amass
In-depth attack surface mapping and asset discovery
yogeshojha/rengine
reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.
0xPugal/SubDomz
An Automated Subdomain Enumeration Tool
g0ldencybersec/EasyEASM
Zero-dollar attack surface management tool
capt-meelo/LazyRecon
An automated approach to performing recon for bug bounty hunting and penetration testing.
gokulapap/Reconator
Automated Recon for Web Pentesting
r1cksec/corptrace
Automate Scoping, OSINT and Recon assessments.
edoardottt/favirecon
Use favicons to improve your target recon phase. Quickly detect technologies, WAF, exposed panels, known services.
reconness/reconness
ReconNess is a platform to allow continuous recon (CR) where you can set up a pipeline of #recon tools (Agents) and trigger it base on schedule or events.
pwnwriter/kanha
🦚 A web-app pentesting suite written in rust .
SilverPoision/Rock-ON
Rock-On is a all in one Recon tool that will just get a single entry of the Domain name and do all of the work alone.