TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes.
CGNU Affero General Public License v3.0steady
19 projectsNetwork Tools › Network Reconnaissance Tools
TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes.
CGNU Affero General Public License v3.0steady
Next-generation crawling and spidering framework.
GoMIT Licenseactive
Fast passive subdomain enumeration tool.
GoMIT Licenseactive
Fast port scanner written in Go with focus on reliability.
GoMIT Licenseactive
Subdomain discovery tool utilizing various open sources producing a report that can be used as input to other tools.
GoMIT Licensedormantarchived
DNS meta-query spider that enumerates DNS records, and subdomains.
PythonGNU General Public License v3.0dormant
DNS enumeration script.
PythonGNU General Public License v2.0active
Unmask server IP addresses hidden behind Cloudflare by searching old database records and detecting misconfigured DNS.
PythonMIT Licenseslowing
Network (sub)domain discovery and reconnaissance automation tool.
GoGNU General Public License v3.0slowingarchived
Handy SMB enumeration tool.
PythonGNU General Public License v3.0steady
Python3 port of the original fierce.pl DNS reconnaissance tool for locating non-contiguous IP space.
PythonGNU General Public License v3.0slowing
Network sniffer that logs all DNS server replies for use in a passive DNS setup.
Cslowing
Utility for using websites to perform port scans on your behalf so as not to reveal your own IP.
PythonThe Unlicensedormantarchived
Script for advanced discovery of sensitive Privileged Accounts - includes Shadow Admins.
PowerShellBSD 3-Clause "New" or "Revised" Licensedormant
Perl script that enumerates DNS information from a domain, attempts zone transfers, performs a brute force dictionary style attack, and then performs reverse look-ups on the results.
Perldormant
POSIX-compliant BASH script to quickly enumerate large networks by calling masscan to quickly identify open ports and then nmap to gain details on the systems/services on those ports.
ShellOtheractive
Network address discovery scanner, based on ARP sweeps, developed mainly for those wireless networks without a DHCP server.
CGNU General Public License v3.0slowing
Library and query tool for querying several passive DNS providers.
RubyMIT Licensedormant
Passive DNS network mapper.
Cdormant