Recon Open Source Projects

Browse 244 Recon open source projects, ranked by GitHub stars. Find the most popular Recon tools and libraries.

Share your experience:✍️ Write a Post❓ Ask a Question
1-60 of 244 projects
19,767 stars

smicallef/spiderfoot

SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.

Metrics details
Stars19,767
16,843 stars

laramies/theHarvester

E-mails, subdomains and names Harvester - OSINT

Metrics details
Stars16,843
14,851 stars

owasp-amass/amass

In-depth attack surface mapping and asset discovery

Metrics details
Stars14,851
10,499 stars

infosecn1nja/Red-Teaming-Toolkit

This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

Metrics details
Stars10,499
10,189 stars

blacklanternsecurity/bbot

The recursive internet scanner for hackers. 🧡

Metrics details
Stars10,189
9,932 stars

shmilylty/OneForAll

OneForAll是一款功能强大的子域收集工具

Metrics details
Stars9,932
8,746 stars

yogeshojha/rengine

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.

Metrics details
Stars8,746
7,866 stars

six2dez/reconftw

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

Metrics details
Stars7,866
6,730 stars

urbanadventurer/WhatWeb

Next generation web scanner

Metrics details
Stars6,730
6,355 stars

s0md3v/Arjun

HTTP parameter discovery suite.

Metrics details
Stars6,355
6,145 stars

GhostTroops/scan4all

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty( ͡° ͜ʖ ͡°)...

Metrics details
Stars6,145
5,787 stars

lanmaster53/recon-ng

Open Source Intelligence gathering tool aimed at reducing the time spent harvesting information from open sources.

Metrics details
Stars5,787
5,106 stars

khast3x/h8mail

Email OSINT & Password breach hunting tool, locally or using premium services. Supports chasing down related email

Metrics details
Stars5,106
5,091 stars

hakluke/hakrawler

Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application

Metrics details
Stars5,091
4,905 stars

hahwul/WebHackersWeapons

⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting

Metrics details
Stars4,905
4,502 stars

TophantTechnology/ARL

ARL(Asset Reconnaissance Lighthouse)资产侦察灯塔系统旨在快速侦察与目标关联的互联网资产,构建基础资产信息库。 协助甲方安全团队或者渗透测试人员有效侦察和检索资产,发现存在的薄弱点和攻击面。

Metrics details
Stars4,502
3,913 stars

leebaird/discover

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload creation using Metasploit. For use with Kali Linux and Ubuntu.

Metrics details
Stars3,913
3,719 stars

Astrosp/osint-tools

OSINT tools can be used for Information gathering, Cybersecurity, Reverse searching, bugbounty, trust and safety, red team oprations and more.

Metrics details
Stars3,719
3,681 stars

S3cur3Th1sSh1t/WinPwn

Automation for internal Windows Penetrationtest / AD-Security

Metrics details
Stars3,681
3,460 stars

edoardottt/cariddi

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

Metrics details
Stars3,460
3,313 stars

gwen001/pentest-tools

A collection of custom security tools for quick needs.

Metrics details
Stars3,313
3,164 stars

dwisiswant0/awesome-oneliner-bugbounty

A collection of awesome one-liner scripts especially for bug bounty tips.

Metrics details
Stars3,164
3,099 stars

21y4d/nmapAutomator

A script that you can run in the background!

Metrics details
Stars3,099
3,020 stars

projectdiscovery/uncover

Quickly discover exposed hosts on the internet using multiple search engines.

Metrics details
Stars3,020
2,846 stars

thewhiteh4t/FinalRecon

All In One Web Recon

Metrics details
Stars2,846
2,797 stars

bugcrowd/bugcrowd_university

Open source education content for the researcher community

Metrics details
Stars2,797
2,750 stars

Integration-IT/Active-Directory-Exploitation-Cheat-Sheet

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

Metrics details
Stars2,750
2,739 stars

bhavsec/reconspider

🔎 Most Advanced Open Source Intelligence (OSINT) Framework for scanning IP Address, Emails, Websites, Organizations.

Metrics details
Stars2,739
2,737 stars

redhuntlabs/Awesome-Asset-Discovery

List of Awesome Asset Discovery Resources

Metrics details
Stars2,737
2,716 stars

imran-parray/Mind-Maps

Mind-Maps of Several Things

Metrics details
Stars2,716
2,679 stars

WebBreacher/WhatsMyName

Community-maintained dataset of 700+ websites for finding accounts by username — powers OSINT and digital footprint tools.

Metrics details
Stars2,679
2,655 stars

m0rtem/CloudFail

Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network

Metrics details
Stars2,655
2,504 stars

infosec-au/altdns

Generates permutations, alterations and mutations of subdomains and then resolves them

Metrics details
Stars2,504
2,488 stars

kpcyrd/sn0int

Semi-automatic OSINT framework and package manager

Metrics details
Stars2,488
2,339 stars

s0md3v/Striker

Striker is an offensive information and vulnerability scanner.

Metrics details
Stars2,339
2,293 stars

bigb0sss/RedTeam-OffensiveSecurity

Tools & Interesting Things for RedTeam Ops

Metrics details
Stars2,293
2,218 stars

d3mondev/puredns

Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries.

Metrics details
Stars2,218
2,100 stars

chainreactors/gogo

面向红队的, 高性能高度自由可拓展的自动化扫描引擎 | A highly controllable and extensionable automated scanning engine for red teams

Metrics details
Stars2,100
2,083 stars

Sh1Yo/x8

Hidden parameters discovery suite

Metrics details
Stars2,083
2,078 stars

s0md3v/ReconDog

Reconnaissance Swiss Army Knife

Metrics details
Stars2,078
1,912 stars

nitefood/asn

ASN / RPKI validity / BGP stats / IPv4v6 / Prefix / URL / ASPath / Organization / IP reputation / IP geolocation / IP fingerprinting / Network recon / lookup API server / Web traceroute server

Metrics details
Stars1,912
1,717 stars

1ndianl33t/Bug-Bounty-Roadmaps

Bug Bounty Roadmaps

Metrics details
Stars1,717
1,684 stars

utkusen/urlhunter

a recon tool that allows searching on URLs that are exposed via shortener services

Metrics details
Stars1,684
1,657 stars

j3ssie/metabigor

OSINT tools and more but without API key

Metrics details
Stars1,657
1,615 stars

wwong99/pentest-notes

Metrics details
Stars1,615
1,593 stars

trickest/inventory

Asset inventory of over 800 public bug bounty programs.

Metrics details
Stars1,593
1,577 stars

m3n0sd0n4ld/GooFuzz

GooFuzz is a tool to perform fuzzing with an OSINT approach, managing to enumerate directories, files, subdomains or parameters without leaving evidence on the target's server and by means of advanced Google searches (Google Dorking).

Metrics details
Stars1,577
1,567 stars

BishopFox/GitGot

Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.

Metrics details
Stars1,567
1,559 stars

Viralmaniar/BigBountyRecon

BigBountyRecon tool utilises 58 different techniques using various Google dorks and open source tools to expedite the process of initial reconnaissance on the target organisation.

Metrics details
Stars1,559
1,552 stars

v-byte-cpu/sx

:vulcan_salute: Fast, modern, easy-to-use network scanner

Metrics details
Stars1,552
1,526 stars

zhongwencool/observer_cli

Visualize Erlang/Elixir Nodes On The Command Line

Metrics details
Stars1,526
1,423 stars

ferd/recon

Collection of functions and scripts to debug Erlang in production.

Metrics details
Stars1,423
1,352 stars

sham00n/buster

An advanced tool for email reconnaissance

Metrics details
Stars1,352
1,294 stars

devanshbatham/FavFreak

Making Favicon.ico based Recon Great again !

Metrics details
Stars1,294
1,292 stars

h4r5h1t/webcopilot

An automation tool that enumerates subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for vulnerabilities.

Metrics details
Stars1,292
1,240 stars

edoardottt/scilla

Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration

Metrics details
Stars1,240
1,228 stars

saeeddhqan/Maryam

Maryam: Open-source Intelligence(OSINT) Framework

Metrics details
Stars1,228
1,186 stars

ayoubfathi/leaky-paths

A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to scan passively for high-quality endpoints and quick-wins.

Metrics details
Stars1,186
1,168 stars

SpiderLabs/HostHunter

HostHunter a recon tool for discovering hostnames using OSINT techniques.

Metrics details
Stars1,168
1,103 stars

KathanP19/JSFScan.sh

Automation for javascript recon in bug bounty.

Metrics details
Stars1,103
1-60 of 244 projects
Get A Weekly Email With Trending Recon Projects
Stay updated on Recon plus related topics you pick below.

Copyright 2018-2026 Awesome Open Source.  All rights reserved.