Tools and Utilities
Last updated
Was this helpful?
Last updated
Was this helpful?
Here we can find some tools and utilities commonly used for processes related to information gathering:
Web tool that maps a Domain through DNS services it uses
Tool to perform general enumeration of a domain
Installation
Usage
Online service that is built as a search engine for internet-connected devices
The utility tries to connect to every device reachable online, once it gets a response, it collects all the information related to the service and saves it in the database to make it searchable
Installation
Usage
A website that creates snapshots of pages in time and displays them to the user
A website that helps to determine what technologies a page uses. Also works as a Firefox extension
Gives you the ability to pretend to be accessing the webpage from a different operating system or different web browser
Database to identify typical icons of Development Frameworks
Another tool for Linux enumeration
Installation
Usage
Open-source intelligence (OSINT) automation tool
Click the New Scan tab, enter a name for the scan, and select a target. Scanning can also be personalized by the type of information required or by choosing the individual scanner modules
To add API keys, go to the Settings tab, open the page for the module you are looking for, and complete the table including the type of information the module searches for
If you don't know how to get the API keys, click the ?
next to the API option in the module and follow the instructions to get API keys
Installation
Usage
OSINT Framework with several tools to gather information passively
OSINT framework that consists of a series of modules that can be run in workspaces
Installation
Usage
Tool to extract web servers, supporting frameworks, and applications
Installation
Usage
Obtain detailed certificate transparency information about a given domain
Command-line tool for testing and analyzing SSL/TLS-enabled services, checking their configuration and security
Installation
Usage
Command-line tool for doing reconnaissance and enumeration on Linux hosts
Installation
Usage
Social Engineering Toolkit, an open-source penetration testing framework designed for social engineering. Has many custom attack vectors that allow you to make a believable attack quickly
Installation
Usage
Browser Exploitation Framework, a tool that can be used to manipulate users by leveraging XSS vulnerabilities via sending fake notifications and stealing cookies, among others
Installation
Usage
Tool used for passive reconnaissance to find information about devices and networks on the Internet
Offers free DNS record, IP address, hostname, and WHOIS lookup information, providing transparent domain information
Provides a search engine for publicly accessible Amazon S3 buckets, allowing users to search for open storage buckets that may contain sensitive files, misconfigurations, or exposed data
Tool for information gathering and brute forcing of DNS domains and subdomains
Installation
Usage
Tool for information gathering and brute forcing of DNS domains and subdomains
Installation
Usage
Web site:
Firefox extension: