
RECONDB_
The ultimate searchable reference for GitHub recon & OSINT tools.
38 tools·16 categories·copy-paste commands
reconFTW
Automated recon framework chaining 45+ tools for full attack surface mapping.
Recon-ng
Metasploit-style web reconnaissance framework with modular architecture.
SpiderFoot
OSINT automation platform integrating 200+ data sources with visual graphs.
Subfinder
Fast passive subdomain discovery using 40+ online sources.
Amass
OWASP attack surface mapping with passive, active, and brute-force enumeration.
Assetfinder
Lightweight Go tool to find related domains and subdomains.
DNSx
Fast multi-purpose DNS toolkit for bulk resolution and record enumeration.
Fierce
DNS reconnaissance tool for locating non-contiguous IP space and hostnames.
Nmap
Industry-standard network discovery and security auditing tool.
Masscan
Internet-scale port scanner — 10 million packets/second from a single machine.
Naabu
Fast and reliable Go-based port scanner by ProjectDiscovery.
Photon
Incredibly fast OSINT crawler extracting URLs, emails, keys, and subdomains.
Hakrawler
Fast web crawler for discovering endpoints and assets within web applications.
Katana
Next-generation crawling framework with JavaScript parsing support.
Maigret
Collect a dossier on a person by username — checks 3,000+ sites, no API keys needed.
Sherlock
Hunt down social media accounts by username across 400+ social networks.
Holehe
Check if an email is attached to accounts on 120+ sites using password-reset flows.
h8mail
Email OSINT and password breach hunting tool with local and API-based search.
PhoneInfoga
Advanced international phone number scanner — carrier, location, VoIP detection.
Gitleaks
SAST tool for detecting hardcoded secrets, API keys, and tokens in git repos.
TruffleHog
Searches git repos for high entropy strings and secrets deep in commit history.
GitDorker
Uses GitHub Search API with dork lists to find sensitive information on GitHub.
Nuclei
Fast template-based vulnerability scanner with 9,000+ community templates.
Nikto
Comprehensive web server scanner testing for 6,700+ dangerous files and misconfigs.
TheHarvester
Gather emails, subdomains, virtual hosts, open ports, and employee names from public sources.
OSINT-SPY
Multi-target OSINT scanner for emails, domains, IPs, and SSL analysis.
Twint
Advanced Twitter scraping without API — scrape tweets, followers, and more.
Instaloader
Download Instagram posts, stories, metadata, and profile information.
OnionSearch
Scrape URLs across multiple .onion search engines (requires Tor).
ExifTool
Read, write, and edit metadata in images, videos, audio, and documents.
Metagoofil
Extract metadata from public documents (PDF, DOC, XLS, PPT) belonging to a target.
Aircrack-ng
Complete suite of tools to assess WiFi network security — capture, crack, inject.
CloudEnum
Multi-cloud OSINT tool for enumerating public resources in AWS, Azure, and GCP.
S3Scanner
Find open S3 buckets and dump their contents.
SQLMap
Automated SQL injection detection and exploitation tool.
XSStrike
XSS detection suite with intelligent payload generator and fuzzing engine.
Gobuster
Brute-force URIs, DNS subdomains, virtual hosts, and open S3 buckets.
Ffuf
Fuzz Faster U Fool — fast web fuzzer for directories, parameters, and headers.