Passive credential-leak discovery across breach sources
Tools that recon
Gather open-source intelligence about a target.
90 tools indexed
Linux privilege-escalation enumerator.
Curated kernel privesc exploit database.
Local-LLM CLI that drives recon tools and AI-analyzes targets.
Username OSINT across 3000+ sites.
Self-hostable email OSINT platform, no API keys required.
Graph-based OSINT and link analysis.
Mass IP port scanner.
Fast port scanner in Go.
Fast service fingerprinting CLI for 170+ protocols
Network service exploitation.
Nmap
—The classic network mapper and port scanner.
Nox
—Modular Go framework for attack surface management and scanning
Local-first link-analysis and geospatial board for investigations.
In-depth attack surface mapping.
AI-powered OSINT agent with REPL, CLI and MCP server.
Evaluate IAM permissions in AWS.
Pacu
—Open-source AWS exploitation framework.
Burp extension for parameter discovery.
Human-in-the-loop agentic AI CLI for pentesters and bug hunters
OSINT framework for phone numbers.
PowerShell post-exploitation framework.
PowerShell AD post-exploitation.
Full-featured reconnaissance framework.