L00king for a tool / link / command? Find it here ... by {THUGS}

Tool name Tags Description

OSINT Framework

The OSINT Framework is a collection of ways to gather information on specific topics

LINK

Raccoon

Offensive Security Tool for Reconnaissance and Information Gathering

LINK

Netdiscover

Great tool to discover assets on your network active/passive ARP reconnaissance tool

LINK

Hunter.io

Email enumeration tool

LINK

Crt.sh

Certificate enumeration tool

LINK

Haveibeenpwned

Useful for breach enumeraton

LINK

Sublist3r

Python tool designed to enumerate subdomains of websites using OSINT

LINK

Gobuster

tool used to brute-force URIs, DNS, Virtual Host, Open Amazon S3 buckets

LINK

Gobuster dir+session

gobuster dir -u http://<ip_host> -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php -c PHPSESSID=<session_value>

Reconnoitre

A reconnaissance tool made for the OSCP labs to automate information gathering and service enumeration whilst creating a directory structure to store results, findings and exploits used for each host

LINK

Searchcode

Find real life code examples

LINK

Unfurl

Unfurl takes a URL and expands ("unfurls") it into a directed graph, extracting every bit of information from the URL and exposing the obscured

LINK

Gqrx SDR

Gqrx is an open source software defined radio receiver (SDR) Airspy, Funcube Dongles, rtl-sdr, HackRF and USRP devices

LINK

SigintOS

SigintOS as the name suggests, SIGINT is an improved Linux distribution for Signal Intelligence. (HackRF, BladeRF, USRP, RTL-SDR)

LINK

URH

Universal Radio Hacker (URH) is a complete suite for wireless protocol investigation with native support for many common Software Defined Radios

LINK

CMSmap

Python open source CMS scanner that automates the process of detecting security flaws of the most popular CMSs

LINK

Recon-cheatsheet

A okay nice cheatsheet for doing recon, found on DEF CON - 9221 twitter now hosted locally for keepsake :)

LINK

Recon-ct

CTRECON - Certificate Transparency Reconnaissance

LINK

Recon-ntoo

NTOORECON - Number To Operator Reconnaissance

LINK

Recon

Small little RCON suite by me!

LINK

Autopsy

Autopsy is the premier end-to-end open source digital forensics platform

LINK

LinEnum

Best scripted local Linux enumeration & privilege escalation checks

LINK

Lynis

Security tool for systems running Linux, macOS, or Unix-based system. Performs an extensive health scan of your systems to support system hardening and compliance testing

LINK

Skipfish

Web application security scanner created by lcamtuf for google

LINK

Maltego CE

Comprehensive tool for graphical link analyses (OSINT) that offers real-time data mining and information gathering, as well as the representation of this information on a node-based graph

LINK

GHDB

Google Hacking Database (GHDB) is a compendium of Google hacking search terms that have been found to reveal sensitive data exposed by vulnerable servers and web applications

LINK

Sniffit

SniffIt is a Distribted Sniffer System, which allows users to capture network traffic from an unique machine using a graphical client application

LINK

Kismet

Kismet is a wireless network and device detector, sniffer, wardriving tool, and WIDS (wireless intrusion detection) framework

LINK

Nessus Essentials

Vulnerability assessment solution for security practitioners. Scan, detect, report, fix exploits, EOL, Risks etc. Utilizing over 65000 CVEs in it's scans. Free version allow 16 ip's to be scanned as much as you want every 90 days.

LINK

Shodan

Search Engine for the Internet of Everything. Very cool way to find services or hosts/devices of interest

LINK

SDRSharp

SDR software for Airspy and RTL-SDR dongles and HackRF/AirSpy/USRP! The best Windows SDR software out there

LINK

DKScan

Danish frequencies for all known services and bands. This might be outdated and also TXT document. You can refer to their site, this is just a backup. www.dkscan.dk

LINK

TheHarvester

Tool designed to be used in the early stages of penetration test or red team engagement. Use it for open source intelligence (OSINT) gathering (email/asn/dns/users/poeple/services)

LINK

Social-analyzer

API, CLI & Web App for analysing & finding a person's profile across +1000 social media \ websites (Detections are updated regularly by automated systems)

LINK

Dirsearch

Web path scanner

LINK

Spiderfoot

SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.

LINK

WhatWeb

Next generation web scanner. WhatWeb recognises web technologies including content management systems (CMS), blogging platforms, statistic/analytics packages, JavaScript libraries, web servers, and embedded devices

LINK

ReNgine

reNgine is an automated reconnaissance framework for web applications it makes is easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.

LINK

Sherlock

Hunt down social media accounts by username and email across social networks

LINK