awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoServidor MCPAcerca deCómo clasificamosPrensa
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

17 repositorios

Awesome GitHub RepositoriesSecurity Reconnaissance Tools

Command-line utilities for performing security assessments and reconnaissance across diverse hardware environments.

Distinguishing note: Focuses on cross-platform security reconnaissance and transmission control, distinct from general-purpose network monitoring.

Explore 17 awesome GitHub repositories matching security & cryptography · Security Reconnaissance Tools. Refine with filters or upvote what's useful.

Awesome Security Reconnaissance Tools GitHub Repositories

Encuentra los mejores repositorios con IA.Buscaremos los repositorios que mejor coincidan usando IA.
  • robertdavidgraham/masscanAvatar de robertdavidgraham

    robertdavidgraham/masscan

    25,355Ver en GitHub↗

    Masscan is a command-line network scanner designed for large-scale discovery and infrastructure reconnaissance. It identifies open ports across specific network segments or the entire internet by probing vast address ranges with high efficiency. The tool functions as an asynchronous packet engine, bypassing standard operating system kernel networking stacks to transmit raw packets directly from application memory. The project distinguishes itself through a specialized architecture that manages millions of concurrent connections by separating packet transmission and reception into independent

    Provides a portable command-line interface for consistent security reconnaissance and transmission rate management across hardware platforms.

    C
    Ver en GitHub↗25,355
  • rustscan/rustscanAvatar de RustScan

    RustScan/RustScan

    19,932Ver en GitHub↗

    RustScan is a high-speed TCP network scanner written in Rust, designed for security reconnaissance and network mapping. It functions as an automated port discovery engine that identifies open ports on remote hosts using IPv6 addresses, CIDR ranges, or bulk input files. The tool is built for rapid surface area discovery, utilizing parallel port processing and OS-aware performance optimizations to identify active services. It allows for scan precision tuning through adjustable connection timeout thresholds and concurrent request controls to balance speed and accuracy. The system integrates wit

    Provides rapid network mapping and surface area discovery for security reconnaissance.

    Rust
    Ver en GitHub↗19,932
  • bettercap/bettercapAvatar de bettercap

    bettercap/bettercap

    18,855Ver en GitHub↗

    Bettercap is a modular framework designed for network reconnaissance, security testing, and the execution of man-in-the-middle attacks. It functions as a comprehensive utility for surveying wired and wireless network segments, identifying connected devices, and analyzing communication protocols through real-time traffic interception and manipulation. The platform distinguishes itself through an event-driven architecture that coordinates network state changes and packet-level data through a centralized message pipeline. It provides a programmable scripting engine and an API for orchestrating s

    Performs network reconnaissance, traffic interception, and security testing across wired and wireless environments.

    Gobledeauthentication-attackdot11
    Ver en GitHub↗18,855
  • techarohq/anubisAvatar de TecharoHQ

    TecharoHQ/anubis

    17,067Ver en GitHub↗

    Anubis is a command-line security reconnaissance framework designed for subdomain enumeration and attack surface mapping. It functions as a utility for security professionals to identify, catalog, and visualize the external digital footprint of an organization by discovering all subdomains associated with a target domain. The tool distinguishes itself through a modular resolver pipeline that integrates passive reconnaissance from third-party security APIs and public certificate transparency logs. It combines this data with active discovery methods, including recursive DNS brute-forcing and al

    Provides a command-line framework for security professionals to perform infrastructure asset discovery and domain reconnaissance.

    Godefensesecurity
    Ver en GitHub↗17,067
  • projectdiscovery/katanaAvatar de projectdiscovery

    projectdiscovery/katana

    15,584Ver en GitHub↗

    Katana is a web crawler and spider designed for security reconnaissance and web application mapping. It functions as a utility for identifying endpoints, forms, and API structures across web targets by combining standard HTTP request traversal with headless browser automation to render dynamic, JavaScript-heavy content. The tool distinguishes itself through its ability to maintain authenticated sessions and handle complex web interactions, such as automated form submission and captcha resolution. It provides granular control over the discovery process, allowing users to define specific crawl

    Acts as a specialized utility for identifying sensitive information, forms, and API structures across web targets.

    Goclicrawlergocrawler
    Ver en GitHub↗15,584
  • nmap/nmapAvatar de nmap

    nmap/nmap

    13,065Ver en GitHub↗

    Nmap is a command-line network security scanner and reconnaissance framework designed for infrastructure mapping and security auditing. It functions as a packet crafting utility that probes target systems to identify active hosts, detect open ports, and determine the services and operating systems running on a network. The tool distinguishes itself through its ability to perform raw socket packet injection and stateful connection tracking, allowing it to bypass standard operating system networking stacks. It utilizes an asynchronous concurrency model to manage large-scale network scans and em

    Employs specialized packet crafting to evade firewalls and intrusion detection systems during reconnaissance.

    Casynchronousc-plus-pluslibpcap
    Ver en GitHub↗13,065
  • six2dez/reconftwAvatar de six2dez

    six2dez/reconftw

    7,226Ver en GitHub↗

    reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio

    Runs individual reconnaissance functions for targeted tasks like port scanning.

    Shellbug-bountybugbountybugbounty-tool
    Ver en GitHub↗7,226
  • i-am-jakoby/flipper-zero-badusbAvatar de I-Am-Jakoby

    I-Am-Jakoby/Flipper-Zero-BadUSB

    6,883Ver en GitHub↗

    This project is a library of pre-defined keyboard scripts and payloads designed for execution via HID injection hardware. It provides a collection of scripted keystroke sequences specifically for the Flipper Zero and other compatible hardware to automate tasks on target computers. The library includes HID attack scripts and USB Rubber Ducky payloads that automate commands to bypass manual user interaction. These scripts are designed to perform system reconnaissance, exfiltrate data, and manipulate user interfaces. The available payloads cover several capability areas, including automated sys

    Provides capabilities for collecting system specifications and network details for external analysis.

    PowerShellbadusbbadusb-payloadsflipper-zero
    Ver en GitHub↗6,883
  • j3ssie/osmedeusAvatar de j3ssie

    j3ssie/Osmedeus

    6,425Ver en GitHub↗

    Osmedeus is a security workflow orchestration engine that coordinates AI agents, shell commands, and scanning tools through declarative YAML pipelines. It functions as a distributed security scanner, a declarative workflow automator, and an AI agent framework for security, enabling automated multi-step security analysis with conditional branching, parallel execution, and distributed workers. The engine distinguishes itself through a hybrid runner model that executes workflow steps on the local host, inside Docker containers, or over SSH to remote machines, selected per step or module. It supp

    Integrates private and premium security tools for enhanced reconnaissance capabilities.

    Go
    Ver en GitHub↗6,425
  • enablesecurity/wafw00fAvatar de EnableSecurity

    EnableSecurity/wafw00f

    6,414Ver en GitHub↗

    WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.

    Enumerates WAF products from a database of over 200 known vendors for security assessments.

    Python
    Ver en GitHub↗6,414
  • urbanadventurer/whatwebAvatar de urbanadventurer

    urbanadventurer/WhatWeb

    6,424Ver en GitHub↗

    WhatWeb is a web application fingerprinting tool that identifies the technology stack powering a website by scanning HTTP responses and page content. It matches responses against a library of over 1800 signatures to detect CMS platforms, JavaScript libraries, web servers, embedded devices, and third-party addons, while also extracting technical metadata such as software versions, user accounts, and module names. The tool operates through a plugin-based detection framework that supports both passive and aggressive scanning modes. Passive plugins analyze existing HTTP headers and page content w

    Probes websites to enumerate software versions, user accounts, and misconfigurations for vulnerability assessment.

    Rubyapplication-securityappsechacking
    Ver en GitHub↗6,424
  • rhinosecuritylabs/pacuAvatar de RhinoSecurityLabs

    RhinoSecurityLabs/pacu

    5,234Ver en GitHub↗

    Pacu es un framework de explotación diseñado para auditar y probar la seguridad de entornos de Amazon Web Services. Sirve como herramienta de pruebas de penetración en la nube y enumerador de recursos utilizado para identificar configuraciones erróneas, mapear superficies de ataque y ejecutar rutas de escalada de privilegios. El framework proporciona capacidades especializadas para operaciones de post-explotación y equipos rojos (red team), incluyendo el establecimiento de persistencia mediante la creación de puertas traseras en la gestión de identidad y acceso. Se distingue por un sistema de módulos basado en plugins que permite el desarrollo de tareas personalizadas y la orquestación de solicitudes de API en múltiples regiones geográficas. El proyecto cubre una amplia gama de actividades de auditoría de seguridad, incluyendo enumeración de infraestructura, exfiltración de datos de servicios de almacenamiento y auditoría de identidad. Incluye herramientas para la ejecución remota de código mediante inyección de carga útil y scripts de inicio, así como capacidades para interrumpir servicios de detección y analizar el movimiento lateral en la red. Pacu gestiona claves de autenticación específicas del objetivo y metadatos de sesión utilizando contenedores aislados y una base de datos local para mantener el estado y reducir las llamadas a la API.

    Enumerates rule groups and matching sets across AWS regions to map the target's web application firewall configuration.

    Python
    Ver en GitHub↗5,234
  • hakluke/hakrawlerAvatar de hakluke

    hakluke/hakrawler

    4,993Ver en GitHub↗

    Hakrawler is a command-line web spider tool designed for security reconnaissance, built to crawl target websites and extract hyperlinks along with JavaScript file references. As a focused reconnaissance utility, it collects every discoverable URL and script source from a given domain, mapping the attack surface for penetration testing and vulnerability assessment. The tool differentiates itself through its concurrent architecture: a fixed-size goroutine pool fetches pages in parallel, while CSS selectors parse HTML to extract anchor and script references. A depth-aware recursion limiter preve

    A command-line utility that spiders a target domain to gather endpoints and script sources for penetration testing.

    Gobugbountycrawlinghacking
    Ver en GitHub↗4,993
  • ghostpack/seatbeltAvatar de GhostPack

    GhostPack/Seatbelt

    4,619Ver en GitHub↗

    Seatbelt is a C# offensive security framework and host security auditor designed to perform endpoint surveys on Windows systems. It functions as a modular tool for identifying vulnerabilities, misconfigurations, and security-relevant artifacts on both local and remote hosts. The project distinguishes itself through a module-based check system that allows for the integration of custom security command units. It features a security event log parser to track logon and process activity, alongside a credential extraction utility for gathering browser history, saved passwords, and cloud credentials

    Provides a suite of reconnaissance tools for enumerating OS versions, antivirus settings, and network rules to identify attack vectors.

    C#
    Ver en GitHub↗4,619
  • itm4n/privesccheckAvatar de itm4n

    itm4n/PrivescCheck

    3,860Ver en GitHub↗

    PrivescCheck is a PowerShell-based security auditing tool designed to scan Windows configurations for potential privilege escalation paths and local host vulnerabilities. It functions as a vulnerability assessment utility that analyzes system settings and registry configurations to identify weaknesses that could allow unauthorized administrative access. The tool automates internal security reconnaissance and post-exploitation data collection to gather environmental information. It serves as a security compliance reporter by exporting scan results into structured formats, including HTML, CSV,

    Automates the collection of system and environmental information during the initial phase of a security assessment.

    PowerShellpentest-toolpentestingprivilege-escalation
    Ver en GitHub↗3,860
  • hackerschoice/thc-tips-tricks-hacks-cheat-sheetAvatar de hackerschoice

    hackerschoice/thc-tips-tricks-hacks-cheat-sheet

    3,853Ver en GitHub↗

    This project is a comprehensive command-line reference and toolkit designed for Linux system administration and network security assessment. It provides a collection of technical snippets and operational guides focused on managing remote environments, orchestrating shell sessions, and executing administrative tasks through native terminal utilities. The repository distinguishes itself by offering specialized techniques for stealthy operations and infrastructure manipulation. It covers methods for establishing encrypted tunnels to bypass firewalls, obfuscating process identities and command hi

    Performs security audits, vulnerability scanning, and reconnaissance on remote systems using command-line utilities.

    Shell
    Ver en GitHub↗3,853
  • sofianehamlaoui/lockdoor-frameworkAvatar de SofianeHamlaoui

    SofianeHamlaoui/Lockdoor-Framework

    1,540Ver en GitHub↗

    Lockdoor-Framework es una suite de pruebas de penetración modular diseñada para facilitar evaluaciones de seguridad integrales a través de una interfaz de línea de comandos centralizada. Funciona como una plataforma integrada para reconocimiento, escaneo de vulnerabilidades y explotación de sistemas objetivo, proporcionando un entorno unificado para gestionar flujos de trabajo de seguridad complejos. El framework se distingue por una arquitectura de plugins modular que permite la extensión de capacidades centrales sin modificar el código base subyacente. Incorpora un pipeline de reconocimiento automatizado para mapear superficies de ataque y aprovecha la integración de herramientas externas para envolver utilidades estándar de la industria, permitiendo a los usuarios ejecutar diversas operaciones de seguridad dentro de un sistema único y cohesivo. La herramienta cubre una amplia superficie de capacidades, incluyendo análisis binario e ingeniería inversa para examinar software compilado, así como escaneo automatizado de aplicaciones web para identificar fallos de inyección y errores de configuración. También admite pruebas a nivel de sistema, como escalada de privilegios y auditoría de contraseñas, e incluye un motor dedicado para agregar hallazgos en informes de evaluación de seguridad estandarizados.

    Performs network scanning and information gathering to map target environments before formal security assessments.

    Pythonblackarch-packagesblueteamingcyber-security
    Ver en GitHub↗1,540
  1. Home
  2. Security & Cryptography
  3. Security Reconnaissance Tools

Explorar subetiquetas

  • Premium Tool IntegrationsExtends reconnaissance capabilities with private and premium security tools not available in the community edition. **Distinct from Security Reconnaissance Tools:** Distinct from Security Reconnaissance Tools: focuses on exclusive/premium tool access, not general reconnaissance utilities.
  • WAF Enumeration Tools1 sub-etiquetaEnumerates WAF products from a database of over 200 known vendors for security assessment purposes. **Distinct from Security Reconnaissance Tools:** Distinct from Security Reconnaissance Tools: focuses specifically on WAF product enumeration, not general hardware reconnaissance.