awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
FortyNorthSecurity avatar

FortyNorthSecurity/EyeWitness

0
View on GitHub↗
5,753 stars·900 forks·Python·GPL-3.0·13 views

EyeWitness

EyeWitness is a web infrastructure mapper and reconnaissance tool designed to automate the visual mapping of exposed web services. It functions as a headless browser screenshotter and HTTP reconnaissance utility that captures visual evidence and extracts server headers from lists of web targets.

The system identifies server technologies and audits for common default administrative credentials to map an organization's external attack surface. It generates searchable HTML security reports that combine screenshots, page source code, and categorized analysis results for vulnerability assessment.

The tool includes capabilities for web server reconnaissance and attack surface mapping, utilizing multithreaded target processing and buffer-based resource management to handle high-volume scanning. It supports importing target lists from text and XML formats.

Features

  • Attack Surface Mapping - Discovers and documents internet-facing assets by capturing screenshots to identify an organization's external attack surface.
  • Website Analysis and Reconnaissance - Analyzes HTTP server headers and technology stacks to identify versions and potential vulnerabilities.
  • Browser Screenshot Capture - Captures screenshots of the visible browser area to visually identify exposed web interfaces.
  • Reconnaissance Screenshot Tools - Captures full-page screenshots and extracts headers from web targets for visual security reconnaissance.
  • Server Configuration Analysis - Audits HTTP headers to extract specific service and version information from targeted websites.
  • Attack Surface Mappers - Identifies server technologies and default credentials to catalog internet-facing infrastructure and organizational exposure.
  • HTTP Header Analyzers - Captures and inspects HTTP response headers to analyze the technology stack of web services.
  • HTTP Response Header Inspectors - Inspects HTTP response headers to isolate technology signatures and server version strings.
  • Headless Browsers - Utilizes automated headless browser engines to render remote web pages and capture visual evidence.
  • Screenshotters - Provides a headless browser utility to automate the visual mapping of exposed web services.
  • Static Report Generation - Converts collected scan data and screenshots into standalone HTML websites for offline analysis.
  • Portable HTML Reports - Produces self-contained, searchable HTML reports containing page source and visual evidence.
  • Screenshot Reports - Generates browsable HTML reports that embed screenshots and response headers for visual analysis.
  • Concurrent Target Scanners - Distributes network requests across multiple concurrent threads to accelerate large-scale infrastructure reconnaissance.
  • Credential Testing Tools - Provides an active auditing feature that tests discovered web interfaces against a list of common default administrative credentials.
  • Default Credential Auditing - Checks discovered web interfaces for common default administrative passwords to identify insecure access points.
  • Vulnerability Report Generation - Generates detailed HTML reports combining visual evidence and server data for security audits.
  • Visual Reconnaissance - Automated screenshot capture and header analysis for web targets.
  • Visual Reconnaissance - Designated tool for taking screenshots and reporting on web services.
  • Exploitation Frameworks - Screenshots web services.
  • Reconnaissance - Automates domain screenshotting for manual review.

Star history

Star history chart for fortynorthsecurity/eyewitnessStar history chart for fortynorthsecurity/eyewitness

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does fortynorthsecurity/eyewitness do?

EyeWitness is a web infrastructure mapper and reconnaissance tool designed to automate the visual mapping of exposed web services. It functions as a headless browser screenshotter and HTTP reconnaissance utility that captures visual evidence and extracts server headers from lists of web targets.

What are the main features of fortynorthsecurity/eyewitness?

The main features of fortynorthsecurity/eyewitness are: Attack Surface Mapping, Website Analysis and Reconnaissance, Browser Screenshot Capture, Reconnaissance Screenshot Tools, Server Configuration Analysis, Attack Surface Mappers, HTTP Header Analyzers, HTTP Response Header Inspectors.

Which projects share features with fortynorthsecurity/eyewitness?

Projects with overlapping indexed features include: redsiege/eyewitness — EyeWitness is a web reconnaissance framework used to identify infrastructure and software versions across multiple… sensepost/gowitness — Gowitness is a system for rendering web interfaces at scale to capture visual snapshots, HTTP metadata, and network… michenriksen/aquatone — Aquatone is a web screenshot reconnaissance tool that captures full-page screenshots of web services discovered during… jaykali/maskphish — Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network… owasp/amass — Amass is a network attack surface mapper and reconnaissance framework designed to discover and map the external,… blacklanternsecurity/bbot — This project is an open-source intelligence reconnaissance framework and recursive attack surface mapper. It functions…

Projects sharing features with EyeWitness

These projects share indexed features with EyeWitness. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • redsiege/eyewitnessRedSiege avatar

    RedSiege/EyeWitness

    5,763View on GitHub↗

    EyeWitness is a web reconnaissance framework used to identify infrastructure and software versions across multiple websites through automated headless browser scans. It functions as an HTTP website screenshotter and a security reporting tool that captures visual snapshots and server headers from a list of web targets. The system distinguishes itself by combining visual documentation with security analysis. It generates searchable HTML reports that categorize website screenshots and metadata by content system or device type, while simultaneously performing server header analysis to determine u

    Python
    View on GitHub↗5,763
  • sensepost/gowitnesssensepost avatar

    sensepost/gowitness

    4,174View on GitHub↗

    Gowitness is a system for rendering web interfaces at scale to capture visual snapshots, HTTP metadata, and network scan results. It functions as a headless browser screenshot tool and a web surface mapper used to identify and visually document the attack surface of network ranges and URL lists. The tool includes a screenshot gallery server that provides a web-based interface for browsing, filtering, and managing a database of captures. It specifically serves as an Nmap target visualizer, parsing network scan results to automatically capture screenshots of discovered web services. Capabiliti

    Gochromechrome-headlessfingerprint
    View on GitHub↗4,174
  • michenriksen/aquatonemichenriksen avatar

    michenriksen/aquatone

    5,940View on GitHub↗

    Aquatone is a web screenshot reconnaissance tool that captures full-page screenshots of web services discovered during network reconnaissance and groups them by visual similarity. It scans a list of hosts or domains for HTTP and HTTPS services on common and custom ports to find responsive web endpoints, then takes full-page screenshots of those pages for quick review. The tool accepts piped input from other tools and extracts URLs, domains, and IP addresses using regex pattern matching, making it pipeline-friendly for integration into existing workflows. It can also read XML output from Nmap

    Go
    View on GitHub↗5,940
  • jaykali/maskphishjaykali avatar

    jaykali/maskphish

    3,020View on GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Shellhackhackinghacking-tool
    View on GitHub↗3,020
  • Compare all 30 related projects→