awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to darryllane/bluto

Open-source alternatives to Bluto

30 open-source projects similar to darryllane/bluto, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Bluto alternative.

  • owasp/amassOWASP avatar

    OWASP/Amass

    14,722View on GitHub↗

    Amass is a network attack surface mapper and reconnaissance framework designed to discover and map the external, internet-facing infrastructure of a target organization. It functions as an open source intelligence tool that identifies public network boundaries and locates hidden or forgotten subdomains to define an organization's total reachable footprint. The project utilizes passive-source data aggregation from external APIs and public databases alongside active DNS brute-forcing and recursive subdomain expansion. It employs a graph-based asset mapping system to visualize the relationships

    Go
    View on GitHub↗14,722
  • oj/gobusterOJ avatar

    OJ/gobuster

    13,429View on GitHub↗

    Gobuster is a command-line security utility designed for brute-force discovery of hidden infrastructure and content. It operates by systematically testing wordlists against target network services to identify files, directories, subdomains, and cloud storage buckets. The tool utilizes a concurrent worker pool to execute these requests in parallel, ensuring efficient scanning across various network environments. The project distinguishes itself through a modular plugin architecture that supports multiple discovery modes, including HTTP, DNS, and TFTP. This design allows for protocol-agnostic r

    Godnsgopentesting
    View on GitHub↗13,429
  • aboul3la/sublist3raboul3la avatar

    aboul3la/Sublist3r

    10,957View on GitHub↗

    Sublist3r is a subdomain enumeration tool and passive reconnaissance framework designed to discover subdomains by querying search engines and public intelligence sources. It functions as a security tool for identifying the digital footprint of a target domain. The project provides both passive enumeration through multi-source API aggregation and active discovery via a DNS brute force tool. It includes a TCP port scanner to identify active services and open ports on discovered subdomains, facilitating attack surface mapping. The tool can be used as a standalone utility or as a Python security

    Python
    View on GitHub↗10,957

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • anonion0/nsec3mapanonion0 avatar

    anonion0/nsec3map

    218View on GitHub↗

    nsec3map - DNSSEC Zone Enumerator

    Python
    View on GitHub↗218
  • b0bac/apolloscannerB

    b0bac/ApolloScanner

    0View on GitHub↗
    View on GitHub↗0
  • bishopfox/jsluiceBishopFox avatar

    BishopFox/jsluice

    1,843View on GitHub↗

    Extract URLs, paths, secrets, and other interesting bits from JavaScript

    Go
    View on GitHub↗1,843
  • aufzayed/hydrareconA

    aufzayed/HydraRecon

    0View on GitHub↗
    View on GitHub↗0
  • blacklanternsecurity/bbotblacklanternsecurity avatar

    blacklanternsecurity/bbot

    9,929View on GitHub↗

    This project is an open-source intelligence reconnaissance framework and recursive attack surface mapper. It functions as a containerized security scanner designed to map public-facing infrastructure, perform subdomain enumeration, and automate the gathering of open-source intelligence. The system employs a recursive discovery engine to iteratively explore target infrastructure, utilizing a plugin-based module architecture to extend scanning capabilities. It integrates third-party APIs for data enrichment and applies YARA rules across discovered assets to identify specific vulnerability patte

    Python
    View on GitHub↗9,929
  • blark/aiodnsbruteblark avatar

    blark/aiodnsbrute

    674View on GitHub↗

    A Python 3.5+ tool that uses asyncio to brute force domain names asynchronously.

    Python
    View on GitHub↗674
  • bp0lr/dmutB

    bp0lr/dmut

    0View on GitHub↗
    View on GitHub↗0
  • bp0lr/gauplusB

    bp0lr/gauplus

    0View on GitHub↗
    View on GitHub↗0
  • brandonskerritt/rustscanB

    brandonskerritt/RustScan

    0View on GitHub↗
    View on GitHub↗0
  • byt3bl33d3r/witnessmebyt3bl33d3r avatar

    byt3bl33d3r/WitnessMe

    763View on GitHub↗

    Web Inventory tool, takes screenshots of webpages using Pyppeteer (headless Chrome/Chromium) and provides some extra bells & whistles to make life easier.

    Python
    View on GitHub↗763
  • chris408/ct-exposerchris408 avatar

    chris408/ct-exposer

    485View on GitHub↗

    Certificate Transparency (CT) is an experimental IETF standard. The goal of it was to allow the public to audit which certificates were created by Certificate Authorities (CA). TLS has a weakness that comes from the large list of CAs that your browser implicitly trusts. If any of those CAs were…

    Python
    View on GitHub↗485
  • cyberark/aclightcyberark avatar

    cyberark/ACLight

    828View on GitHub↗

    A script for advanced discovery of Privileged Accounts - includes Shadow Admins

    PowerShell
    View on GitHub↗828
  • chvancooten/bugbountyscannerchvancooten avatar

    chvancooten/BugBountyScanner

    921View on GitHub↗
    Shellbug-bounty-reconnaissancebugbountydocker-image
    View on GitHub↗921
  • d3mondev/purednsd3mondev avatar

    d3mondev/puredns

    2,193View on GitHub↗

    Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries.

    Go
    View on GitHub↗2,193
  • devanshbatham/favfreakdevanshbatham avatar

    devanshbatham/FavFreak

    1,290View on GitHub↗
    Pythonbugbountybughuntinghacking
    View on GitHub↗1,290
  • devanshbatham/paramspiderdevanshbatham avatar

    devanshbatham/ParamSpider

    3,103View on GitHub↗

    Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing

    Python
    View on GitHub↗3,103
  • dirkjanm/adidnsdumpdirkjanm avatar

    dirkjanm/adidnsdump

    1,167View on GitHub↗

    Active Directory Integrated DNS dumping by any authenticated user

    Python
    View on GitHub↗1,167
  • dirkjanm/ldapdomaindumpdirkjanm avatar

    dirkjanm/ldapdomaindump

    1,379View on GitHub↗
    Python
    View on GitHub↗1,379
  • dolevf/graphw00fdolevf avatar

    dolevf/graphw00f

    857View on GitHub↗

    graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology is behind a given GraphQL endpoint.

    Python
    View on GitHub↗857
  • dwisiswant0/apkleaksdwisiswant0 avatar

    dwisiswant0/apkleaks

    6,102View on GitHub↗

    Apkleaks is a static analysis tool and security auditor designed to extract hardcoded secrets, API endpoints, and sensitive data from Android application packages. It operates as a secret scanner that analyzes compiled binaries without executing them to identify potential information leaks and insecure endpoints. The tool utilizes a regex-based data extraction engine to identify sensitive strings within decompiled code. It supports customization through JSON-defined search patterns and provides configuration flags to tune the behavior of the underlying disassembler. The analysis pipeline enc

    Python
    View on GitHub↗6,102
  • dwisiswant0/go-dorkdwisiswant0 avatar

    dwisiswant0/go-dork

    1,284View on GitHub↗

    The fastest dork scanner written in Go.

    Go
    View on GitHub↗1,284
  • easyrecon/hunt3rE

    EasyRecon/Hunt3r

    0View on GitHub↗
    View on GitHub↗0
  • edoardottt/cariddiedoardottt avatar

    edoardottt/cariddi

    3,427View on GitHub↗

    Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

    Go
    View on GitHub↗3,427
  • edoardottt/cspreconedoardottt avatar

    edoardottt/csprecon

    514View on GitHub↗

    Discover new target domains using Content Security Policy

    Go
    View on GitHub↗514
  • edoardottt/favireconE

    edoardottt/favirecon

    0View on GitHub↗
    View on GitHub↗0
  • edoardottt/longtongueE

    edoardottt/longtongue

    0View on GitHub↗
    View on GitHub↗0
  • bishopfox/spoofcheckB

    BishopFox/spoofcheck

    0View on GitHub↗
    View on GitHub↗0