ScanReview
Discovery-focused tools for finding internet-facing systems and signals.
Open-source reconnaissance and network discovery tools for subdomain enumeration and OSINT — find internet-facing systems, subdomains, and signals before anyone else does.
Passive and active tools for finding subdomains and mapping external attack surfaces.
Advanced subdomain enumeration — network mapping of attack surfaces using OSINT and active techniques.
GitHub →Fast passive subdomain discovery using certificate transparency logs, search engines, and APIs.
GitHub →Find domains and subdomains potentially related to a given domain from various public sources.
GitHub →Python tool that enumerates subdomains using OSINT through search engines and passive DNS sources.
GitHub →Fast, cross-platform subdomain enumerator leveraging certificate transparency logs and multiple APIs.
GitHub →ProjectDiscovery's actively maintained DNS dataset — query millions of known subdomains for any target.
GitHub →Fast domain resolver and subdomain bruteforcing tool with wildcard detection and filtering.
GitHub →MassDNS wrapper for subdomain bruteforcing with wildcard handling and smart filtering.
GitHub →Generates permutations, alterations, and mutations of subdomains to discover overlooked infrastructure.
GitHub →
Gather intelligence from public sources without directly touching the target.
Powerful internet asset discovery — search certificates, hosts, and services across the public internet.
GitHub →Internet-wide device search engine — find exposed servers, IoT devices, and industrial control systems.
GitHub →Gathers emails, subdomains, IPs, and URLs using search engines, Shodan, certificate logs, and more.
GitHub →Automated OSINT reconnaissance with 200+ modules querying hundreds of public data sources.
GitHub →Full-featured web reconnaissance framework with a modular architecture and marketplace.
GitHub →Hunt down social media accounts by username across 400+ social networks and platforms.
GitHub →Check if an email address is registered on different sites without alerting the target.
GitHub →Collect detailed profile information about a person by username across thousands of sites.
GitHub →
Specialized tools for DNS-based discovery and enumeration.
Comprehensive DNS enumeration script — zone transfers, brute-force, SRV records, and more.
GitHub →Fast multi-purpose DNS toolkit — run A, AAAA, CNAME, MX, NS, TXT, and SOA queries at scale.
GitHub →High-performance DNS stub resolver capable of resolving millions of domains in minutes.
GitHub →DNS reconnaissance tool for locating non-contiguous IP space and discovering internal network ranges.
GitHub →Quick-fire tools for mapping live hosts, open ports, and running services across networks.
Fast port scanner by ProjectDiscovery — SYN scan with high concurrency for rapid network mapping.
GitHub →Blazingly fast port scanner — scans all 65,535 ports in seconds, pipes results into Nmap.
GitHub →Fast HTTP probing toolkit — identify live web servers, status codes, titles, technologies, and more.
GitHub →Website fingerprinting — identifies CMS, JS frameworks, analytics, and server software.
GitHub →Visual inspection tool — takes a list of hosts and produces screenshot-based reports for quick triage.
GitHub →Surface hidden endpoints, historical URLs, and exposed content across the web.
Get All URLs — fetches known URLs from AlienVault OTX, Wayback Machine, Common Crawl, and URLScan.
GitHub →Fetch all URLs the Wayback Machine knows about for a domain — great for finding forgotten endpoints.
GitHub →Fast directory, file, DNS, and VHOST busting tool written in Go — brute-forces URI paths and subdomains.
GitHub →Find accidentally exposed credentials, API keys, and secrets in public repositories.