A lightweight Python tool for passive reconnaissance, including subdomain, email, and S3 bucket extraction, with AI-powered scanner for sensitive infrastructure mentions.
-
Updated
Apr 27, 2025 - Python
A lightweight Python tool for passive reconnaissance, including subdomain, email, and S3 bucket extraction, with AI-powered scanner for sensitive infrastructure mentions.
A basic passive reconnaissance tool made using Python. It checks tech stacks, security headers and hidden directories in a website.
A web application security scanner a very big competitor of OWASP ZAP and Burp Suit — intercepting proxy, passive scanner, spider, active scanner, and a native desktop GUI.
Passive OSINT domain reconnaissance tool — CLI + Web UI
Hybrid tool for passive reconnaissance and attack surface analysis in web applications. It combines advanced scraping, technology fingerprinting, security assessment, and reporting into a single CLI solution. Designed for ethical, educational, and auditing purposes. This software MUST NOT be used on third-party systems.
Iron Veil is a comprehensive, militarized subdomain enumeration and verification tool built in Python.
A high-performance Chrome Extension (Manifest V3) for automated passive web reconnaissance, header analysis, and PDF security report generation
🌌 NEBULA ANTISCAN v2.0– Demo pública de detección de escaneos agresivos, IPs de Killnet y botnets. ✅ 73 fuentes OSINT + 80 feeds de inteligencia ✅ Dashboard cyberpunk con mapa y gráficos ✅ Geolocalización, ASN, clasificación por grupo ✅ Ligera, funciona en Linux, macOS y Termux
VirusTotal Domain Scan
SubGhost is a powerful subdomain discovery tool. It helps you discover hidden or less visible subdomains for a given domain using public API services. The tool is designed to be simple to use while offering great flexibility, such as the ability to choose the output format for results.
Passive OSINT security auditing framework aligned to OWASP Top 10:2025 - deterministic risk scoring, JSON/PDF reporting, and Streamlit dashboard. No exploitation, no brute force, 100% passive.
Herramienta híbrida para el reconocimiento pasivo y el análisis de superficie de ataque en aplicaciones web. Combina scraping avanzado, fingerprinting tecnológico, evaluación de seguridad y reporting en una sola solución CLI. Diseñada para un uso ético, educativo y de auditoría. Este software NO debe utilizarse en sistemas ajenos.
Generate a full domain recon report: DNS, TLS certificate, security headers, redirects and subdomains
Local-first defensive passive reconnaissance planner and analyst workspace.
With the aid of 43 techniques, including Google dorks. SmartRecon serves as a passive reconnaissance tool that used to gain initial information about an organization OR target domain.
A sleek passive origin IP discovery tool featuring a Flask web UI, real-time SSE streaming, secure session-specific API keys, and automatic CDN edge node pruning.
Passive Joomla attack surface mapping and endpoint exposure auditing tool.
A responsive cybersecurity posture-assessment web application for SMBs. Performs permission-first passive scans (HTTPS, DNS, RDAP) to generate A–F scores, evidence led reports, and AI-assisted remediation guidance.
1-click passive web security audit Chrome Extension (Manifest V3) for headers, cookie hygiene, and attack surface assessment.
A Comprehensive Web-Based Passive Reconnaissance Tools Directory
To associate your repository with the passive-reconnaissance topic, visit your repo's landing page and select "manage topics."