Reconnaissance & OSINT
Arsenal of tools for ethical hacking and pentesting
OWASP Amass
Reconnaissance & OSINTNetwork mapping and attack surface discovery tool. Finds subdomains and IPs.
Sherlock
Reconnaissance & OSINTFind usernames across multiple social networks. Ideal for OSINT investigations.
GoBuster
Reconnaissance & OSINTDirectory/file, DNS and vhost brute-forcing tool written in Go.
ffuf
Reconnaissance & OSINTFast web fuzzer written in Go. Ideal for discovering directories and parameters.
Maltego
Reconnaissance & OSINTLink analysis and data enrichment tool. Visualizes relationships between people, domains and emails.
Shodan
Reconnaissance & OSINTSearch engine for Internet-connected devices. Find servers, routers, webcams and more.
Recon-ng
Reconnaissance & OSINTFull-featured web reconnaissance framework designed to gather information from open sources quickly.
SpiderFoot
Reconnaissance & OSINTAutomated OSINT reconnaissance platform with over 200 data sources. Integrates Shodan, VirusTotal and HaveIBeenPwned.
OSINT Framework
Reconnaissance & OSINTCollection of free OSINT tools organized by categories. Essential starting point.
theHarvester
Reconnaissance & OSINTTool for gathering emails, subdomains, IPs and URLs using multiple public data sources.
Subfinder
Reconnaissance & OSINTFast passive subdomain discovery tool. Uses multiple data sources.
Aquatone
Reconnaissance & OSINTVisual inspection tool of websites for pentesting. Generates screenshots of hosts.
Censys
Reconnaissance & OSINTSearch platform that continuously scans the Internet to find exposed devices and services.
Photon
Reconnaissance & OSINTUltra-fast web crawler designed for OSINT. Extracts URLs, emails, files and more.
httpx
Reconnaissance & OSINTFast and multipurpose HTTP toolkit. Probes web services and extracts information.
Naabu
Reconnaissance & OSINTFast port scanner written in Go. Designed for large-scale scans.
Waybackurls
Reconnaissance & OSINTFetches known URLs for a domain from Wayback Machine.
gau (GetAllUrls)
Reconnaissance & OSINTFetches known URLs from AlienVault OTX, Wayback Machine and Common Crawl.
Assetfinder
Reconnaissance & OSINTFinds domains and subdomains related to a given domain.