⚡ ReconNinja v10.6.0— 38-phase recon framework for pentesters & bug bounty hunters. Subdomain enum → port scan → web recon → WAF/CORS/JS/cloud bucket detection → GitHub OSINT → CVE lookup → AI threat analysis → HTML report. Domains, IPs, CIDRs, target lists. Plugin system. 598 tests.
☆42Jun 23, 2026Updated 2 months ago
Alternatives and similar repositories for ReconNinja
Users that are interested in ReconNinja are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- VaultHound — A fast, pattern-based secret and credential scanner. Scans local directories, Git history, and URLs for leaked API keys, tok…☆17Mar 21, 2026Updated 5 months ago
- Cross-platform CLI to dump saved WiFi credentials — Linux, Windows, macOS☆17Mar 22, 2026Updated 5 months ago
- Scan codebases, git history, and Docker images for accidentally exposed secrets☆16Mar 22, 2026Updated 5 months ago
- Arch Linux fastfetch config with Kitty image protocol, Nerd Font icons, and a clean box-bordered layout.☆14Mar 7, 2026Updated 6 months ago
- Personal portfolio — self-taught dev from Bangladesh 🇧🇩☆12Updated this week
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Kali Linux Polyglot Framework for Autonomous Pentesting/Cyber Security☆136Aug 16, 2026Updated last month
- mattew crawls target websites, extracts hidden attack surface, runs security analysis, fingerprints technology, and generates professiona…☆17Jul 2, 2026Updated 2 months ago
- A python-based vulnerability scanner designed to identify open redirect flaws in website applications.☆26Mar 15, 2026Updated 6 months ago
- Multi-agent AI system using GPT-4o, DeepSeek v3, and Llama 3.3 to detect if CVE vulnerabilities were exploited as zero-days. Analyzes…☆21Feb 13, 2026Updated 7 months ago
- BountyLens MCP server — connect Claude Code to your Hunter Tracker☆64Jun 22, 2026Updated 2 months ago
- AutoAR is an automated security reconnaissance tool, ASM and Discord bot for bug bounty hunters and penetration testers. It automates gat…☆250Updated this week
- Deep scan domain and find all possible domain to takeover☆17Apr 19, 2023Updated 3 years ago
- An AI red-team agent for authorized labs and web app pentesting workflows. Turns Claude Code / OpenCode / Codex into a structured recon →…☆132Aug 2, 2026Updated last month
- the ultimate network monitoring dashboard for SOC analysts and cyber security professionals.☆16Sep 1, 2026Updated 2 weeks ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Generate wordlists using pattern logic and expressions.☆23Jun 18, 2026Updated 3 months ago
- JS+ is a browser extension that captures JS URLs from specified domains and scans them with AI.☆23Mar 16, 2026Updated 6 months ago
- Burp Suite extension — passively detects secrets, API keys, credentials, JWTs & PII in HTTP traffic. 160+ detection rules, bulk scan, ent…☆55Aug 24, 2026Updated 3 weeks ago
- Open-source passive reconnaissance and exposure discovery tool that leverages VirusTotal and the Wayback Machine to uncover subdomains, U…☆147Updated this week
- Demonstrate how a signed driver can bypass defenses to deploy ransomware on Windows 11 with advanced AV and UAC evasion techniques.☆34Updated this week
- Prompt-injection guardrail for LLM applications. Compact model that outperforms larger open-source guards. No regex, no signatures. Demo:…☆79May 31, 2026Updated 3 months ago
- DeepProbe - Memory Forensics Framework☆16May 16, 2026Updated 4 months ago
- Automated bug bounty reconnaissance and scanning agent☆51Aug 7, 2026Updated last month
- Run TTPs, with AI!☆142Feb 23, 2026Updated 6 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Burp Suite extension for cross-identity & cross-tenant access-control testing — BAC, IDOR, BOLA, and privilege escalation.☆61Jul 12, 2026Updated 2 months ago
- KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.☆238Updated this week
- Security AI helper for Caido: pipes your local Claude Code / Gemini / Codex / Copilot CLI through 18 MCP tools for manual web security te…☆42Sep 2, 2026Updated 2 weeks ago
- My Main App Hacking CheckList☆35Jun 20, 2026Updated 3 months ago
- 🎯 Chrome Extension - Passive scanner for Dependency Confusion vulnerabilities in npm/PyPI packages☆41Jan 31, 2026Updated 7 months ago
- safer-dependencies is a security layer for Claude Code that audits packages before they’re added to your project. It detects and fixes ri…☆40Aug 31, 2026Updated 2 weeks ago
- TokenTwin Checker — Dual Token BAC/IDOR Tester for Burp Suite☆97Aug 24, 2026Updated 3 weeks ago
- Graph-Greener is a powerful tool designed to enhance your GitHub contribution graph by generating backdated commits. It helps developers …☆65Jun 7, 2025Updated last year
- Thermal pocket printer - BLE protocol reverse engineering, Python CLI, and web GUI☆21Sep 4, 2026Updated 2 weeks ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆25Apr 29, 2025Updated last year
- High-performance OSINT/CTI framework for automated identity pivoting and risk analysis across 120+ sources.☆326May 6, 2026Updated 4 months ago
- 👁️ Uncover the unseen☆19Updated this week
- [ Multi Encryption / Decryption ]☆21Dec 31, 2019Updated 6 years ago
- ☆16Jun 26, 2025Updated last year
- Professional AWS pentest tool: IAM privilege escalation, S3 exploits, compute enumeration, detailed audit reports☆34May 2, 2026Updated 4 months ago
- Offensive Security Scripts (OSS) - Repository of random scripts I've written for offensive purposes.☆12Feb 21, 2025Updated last year