Exposor is a tool using internet search engines to detect exposed technologies with a unified syntax.
-
Updated
Nov 12, 2025 - Python
Exposor is a tool using internet search engines to detect exposed technologies with a unified syntax.
Passive recon & attack surface mapper — zero requests sent
Passive attack-surface scanner: turn a domain into a risk grade, copy-paste fixes, and a client-ready report. Safe DNS, HTTP, TLS, email, and certificate-transparency checks.
Grassmarlin replacement. Open-source multi-user ICS/SCADA passive network discovery and topology platform. Upload PCAPs, visualize OT networks, generate assessment reports. Flask + Docker. The open-source engine behind Fathom.
Passive Reconnaissance Techniques Approach helps for penetration testing and bug bounty hunting by gathering information about a target system or network.
Passive Attack Surface Toolkit: Module-based passive OSINT recon for web domains. Runs non-destructive subdomain/DNS/WHOIS/SSL/header/wayback/tech discovery, maps depth‑1 surface, computes a 0–100 exposure score, and emits presentation-ready HTML, JSON, Markdown and an interactive graph.
OSINT Exposure Toolkit: A modular, passive reconnaissance CLI that inspects emails, domains, and usernames for leaks and misconfigurations. Generates interactive HTML, JSON and Markdown reports and a visual exposure graph. Includes GitHub secret scans, HIBP/LeakCheck support, Shodan, Google dorks, JS and metadata scanning.
Instagram information gathering
Phone number osint
A lightweight Python tool for passive reconnaissance, including subdomain, email, and S3 bucket extraction, with AI-powered scanner for sensitive infrastructure mentions.
This is a Python script that provides the ability to perform: Check all NS Records for Zone Transfers. Enumerate General DNS Records for a given Domain (MX, SOA, NS, A, AAAA, SPF and TXT). Perform common SRV Record Enumeration. Top Level Domain (TLD) Expansion.
Recon-Scan: open‑source passive reconnaissance with AI‑powered security analysis. Zero‑touch, developer‑first, and privacy‑focused.
A basic passive reconnaissance tool made using Python. It checks tech stacks, security headers and hidden directories in a website.
An intelligent, Human-in-the-Loop OSINT framework.
⚡ Passive OSINT reconnaissance tool — subdomains, GitHub leaks, Shodan, Wayback Machine
Passive subdomain enumeration tool in Python. Collects subdomains, resolves DNS, and optionally checks HTTP/HTTPS status.
Public-metadata domain intelligence from DNS, certificate transparency, and unauthenticated identity discovery. Local Python CLI, versioned JSON, and stdio MCP server. No credentials or active scanning.
Passive hybrid fingerprinting engine — identify hosts without sending a single packet
WP-Dex is an advanced passive WordPress reconnaissance tool built in Python for security auditing and intelligence gathering. It extracts detailed information about WordPress websites including plugins, themes, users, server fingerprinting, exposed paths, and known vulnerabilities — without performing any exploitation or modification. Designed for
Static is a lightweight, dependency-free typosquatting reconnaissance tool written in pure Python. It generates common typo variations of a target domain and checks them using DNS and HTTP/HTTPS heuristics to identify potentially available domains and redirect behavior.
Add a description, image, and links to the passive-recon topic page so that developers can more easily learn about it.
To associate your repository with the passive-recon topic, visit your repo's landing page and select "manage topics."