ReconDB Terminal Banner
▶ INITIALIZED — 2026

RECONDB_

The ultimate searchable reference for GitHub recon & OSINT tools.
38 tools·16 categories·copy-paste commands

Showing 38 tools

reconFTW

7.4k

Automated recon framework chaining 45+ tools for full attack surface mapping.

Dual-UseBash2026
#automation#full-scan#docker#bug-bounty

Recon-ng

5.5k

Metasploit-style web reconnaissance framework with modular architecture.

Dual-UsePython2024
#framework#modular#web-recon#metasploit-style

SpiderFoot

13k

OSINT automation platform integrating 200+ data sources with visual graphs.

Dual-UsePython2025
#automation#osint#data-sources#visualization

Subfinder

10k

Fast passive subdomain discovery using 40+ online sources.

Ethical / DefensiveGo2025
#subdomain#passive#projectdiscovery#fast

Amass

12k

OWASP attack surface mapping with passive, active, and brute-force enumeration.

Ethical / DefensiveGo2025
#owasp#attack-surface#brute-force#visualization

Assetfinder

3k

Lightweight Go tool to find related domains and subdomains.

Ethical / DefensiveGo2023
#subdomain#lightweight#tomnomnom

DNSx

2k

Fast multi-purpose DNS toolkit for bulk resolution and record enumeration.

Ethical / DefensiveGo2025
#dns#resolution#cname#projectdiscovery

Fierce

1.5k

DNS reconnaissance tool for locating non-contiguous IP space and hostnames.

Ethical / DefensivePython2023
#dns#zone-transfer#reconnaissance

Nmap

10k

Industry-standard network discovery and security auditing tool.

Dual-UseC/Lua2025
#port-scan#os-detection#nse-scripts#industry-standard

Masscan

25.4k

Internet-scale port scanner — 10 million packets/second from a single machine.

Dual-UseC2025
#port-scan#internet-scale#fast#async

Naabu

4.5k

Fast and reliable Go-based port scanner by ProjectDiscovery.

Dual-UseGo2025
#port-scan#go#projectdiscovery#fast

Photon

12.8k

Incredibly fast OSINT crawler extracting URLs, emails, keys, and subdomains.

Dual-UsePython2025
#crawler#osint#email-extraction#wayback

Hakrawler

4k

Fast web crawler for discovering endpoints and assets within web applications.

Dual-UseGo2024
#crawler#endpoints#go#hakluke

Katana

12k

Next-generation crawling framework with JavaScript parsing support.

Dual-UseGo2025
#crawler#javascript#projectdiscovery#next-gen

Maigret

19.2k

Collect a dossier on a person by username — checks 3,000+ sites, no API keys needed.

Dual-UsePython2025
#username#dossier#3000-sites#no-api-key

Sherlock

60k

Hunt down social media accounts by username across 400+ social networks.

Dual-UsePython2025
#username#social-media#400-sites#popular

Holehe

10.5k

Check if an email is attached to accounts on 120+ sites using password-reset flows.

Dual-UsePython2023
#email#account-check#120-sites#stealthy

h8mail

4.9k

Email OSINT and password breach hunting tool with local and API-based search.

Dual-UsePython2022
#email#breach#password#haveibeenpwned

PhoneInfoga

16.1k

Advanced international phone number scanner — carrier, location, VoIP detection.

Dual-UseGo2024
#phone#carrier#voip#international

Gitleaks

25.5k

SAST tool for detecting hardcoded secrets, API keys, and tokens in git repos.

Ethical / DefensiveGo2025
#secrets#api-keys#sast#ci-cd

TruffleHog

17k

Searches git repos for high entropy strings and secrets deep in commit history.

Ethical / DefensiveGo2025
#secrets#entropy#git-history#github-org

GitDorker

2k

Uses GitHub Search API with dork lists to find sensitive information on GitHub.

Dual-UsePython2022
#github-dorking#search-api#sensitive-files

Nuclei

22k

Fast template-based vulnerability scanner with 9,000+ community templates.

Dual-UseGo2025
#vulnerability#templates#cve#projectdiscovery

Nikto

8k

Comprehensive web server scanner testing for 6,700+ dangerous files and misconfigs.

Dual-UsePerl2024
#web-server#misconfig#6700-checks#ssl

TheHarvester

12k

Gather emails, subdomains, virtual hosts, open ports, and employee names from public sources.

Dual-UsePython2025
#email#subdomain#linkedin#shodan

OSINT-SPY

1.5k

Multi-target OSINT scanner for emails, domains, IPs, and SSL analysis.

Dual-UsePython2019
#email#domain#ip#ssl

Twint

15k

Advanced Twitter scraping without API — scrape tweets, followers, and more.

Dual-UsePython2023
#twitter#scraping#no-api#social-media

Instaloader

9k

Download Instagram posts, stories, metadata, and profile information.

Dual-UsePython2025
#instagram#download#metadata#stories

OnionSearch

1k

Scrape URLs across multiple .onion search engines (requires Tor).

Dual-UsePython2023
#dark-web#onion#tor#search

ExifTool

3k

Read, write, and edit metadata in images, videos, audio, and documents.

Ethical / DefensivePerl2025
#metadata#gps#exif#images

Metagoofil

1k

Extract metadata from public documents (PDF, DOC, XLS, PPT) belonging to a target.

Dual-UsePython2023
#metadata#pdf#doc#document-osint

Aircrack-ng

5k

Complete suite of tools to assess WiFi network security — capture, crack, inject.

Offensive / Red TeamC2025
#wifi#wpa2#monitor-mode#packet-injection

CloudEnum

3k

Multi-cloud OSINT tool for enumerating public resources in AWS, Azure, and GCP.

Dual-UsePython2024
#aws#azure#gcp#cloud-storage

S3Scanner

2.5k

Find open S3 buckets and dump their contents.

Dual-UsePython2024
#aws#s3#bucket#misconfiguration

SQLMap

32k

Automated SQL injection detection and exploitation tool.

Offensive / Red TeamPython2025
#sql-injection#database#exploitation#pentest

XSStrike

13k

XSS detection suite with intelligent payload generator and fuzzing engine.

Offensive / Red TeamPython2024
#xss#fuzzing#payload#crawler

Gobuster

10k

Brute-force URIs, DNS subdomains, virtual hosts, and open S3 buckets.

Dual-UseGo2025
#brute-force#directory#dns#vhost

Ffuf

13k

Fuzz Faster U Fool — fast web fuzzer for directories, parameters, and headers.

Dual-UseGo2025
#fuzzing#directory#parameters#headers