awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
guelfoweb avatar

guelfoweb/knockpy

0
View on GitHub↗
4,163 stars·883 forks·Python·GPL-3.0·15 viewsgithub.com/guelfoweb/knockpy↗

Knockpy

Knockpy is a DNS subdomain scanner and passive reconnaissance tool designed to discover subdomains and gather network intelligence. It functions as a DNS enumeration framework that combines active discovery methods with the ability to query external security services for passive domain data.

The tool identifies targets through a combination of wordlist-based brute forcing, DNS zone transfers, and the aggregation of data from external security APIs. To ensure accuracy, it includes wildcard DNS detection to filter out false positives during the enumeration process.

Beyond discovery, the system provides host security validation by probing endpoints for HTTP status and TLS certificate validity. All captured intelligence and scan results are managed through a local security research database that supports searching, deleting, and exporting data.

Features

  • Subdomain Enumeration Workflows - Combines wordlist brute-forcing, zone transfers, and wildcard detection into a comprehensive DNS enumeration workflow.
  • Subdomain Brute Forcing - Implements a combination of passive reconnaissance and active wordlist-based brute forcing to discover subdomains.
  • Attack Surface Mapping - Maps the external attack surface by identifying accessible hosts and validating TLS and HTTP security.
  • DNS Reconnaissance Frameworks - Provides a suite of utilities for detecting wildcard records and validating host security via TLS and HTTP checks.
  • Passive Intelligence Gathering - Provides capabilities to query external security services for passive subdomain intelligence and network data.
  • Passive Reconnaissance Aggregators - Aggregates subdomain intelligence from multiple external security APIs into a unified dataset.
  • Passive Reconnaissance - Gathers hidden subdomains from external security services to map a target network's external surface.
  • Subdomain Scanners - Discovers subdomains using a combination of passive reconnaissance, active wordlist brute-forcing, and DNS zone transfers.
  • Host Security Audits - Probes discovered endpoints to verify SSL certificate validity and check for outdated security protocols.
  • DNS Zone Transfers - Implements DNS zone transfers to retrieve complete zone files and uncover all registered subdomains.
  • Wildcard Domain Detectors - Detects wildcard DNS responses to filter out false positives during the subdomain enumeration process.
  • Host Security Validations - Probes discovered endpoints to verify SSL certificate validity and check for outdated security protocols.
  • Command Line Tools - Listed in the “Command Line Tools” section of the The Book Of Secret Knowledge awesome list.

Star history

Star history chart for guelfoweb/knockpyStar history chart for guelfoweb/knockpy

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with Knockpy

These projects share indexed features with Knockpy. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • aboul3la/sublist3raboul3la avatar

    aboul3la/Sublist3r

    10,957View on GitHub↗

    Sublist3r is a subdomain enumeration tool and passive reconnaissance framework designed to discover subdomains by querying search engines and public intelligence sources. It functions as a security tool for identifying the digital footprint of a target domain. The project provides both passive enumeration through multi-source API aggregation and active discovery via a DNS brute force tool. It includes a TCP port scanner to identify active services and open ports on discovered subdomains, facilitating attack surface mapping. The tool can be used as a standalone utility or as a Python security

    Python
    View on GitHub↗10,957
  • edu4rdshl/findomainEdu4rdSHL avatar

    Edu4rdSHL/findomain

    3,761View on GitHub↗

    Findomain is a subdomain enumeration and infrastructure analysis tool designed for attack surface mapping. It functions as a DNS reconnaissance suite that discovers subdomains using multiple data sources and API keys to identify the full extent of a target network. The system acts as an attack surface monitor by tracking subdomain changes over time and sending real-time alerts via webhooks when new assets are detected. It includes specialized capabilities for detecting DNS wildcards to filter false positives and resolving subdomain IPs through parallel resolution. The tool provides a workflo

    Rust
    View on GitHub↗3,761
  • six2dez/reconftwsix2dez avatar

    six2dez/reconftw

    7,226View on GitHub↗

    reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio

    Shellbug-bountybugbountybugbounty-tool
    View on GitHub↗7,226
  • jaykali/maskphishjaykali avatar

    jaykali/maskphish

    3,020View on GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Shellhackhackinghacking-tool
    View on GitHub↗3,020
Compare all 30 related projects→

Frequently asked questions

What does guelfoweb/knockpy do?

Knockpy is a DNS subdomain scanner and passive reconnaissance tool designed to discover subdomains and gather network intelligence. It functions as a DNS enumeration framework that combines active discovery methods with the ability to query external security services for passive domain data.

What are the main features of guelfoweb/knockpy?

The main features of guelfoweb/knockpy are: Subdomain Enumeration Workflows, Subdomain Brute Forcing, Attack Surface Mapping, DNS Reconnaissance Frameworks, Passive Intelligence Gathering, Passive Reconnaissance Aggregators, Passive Reconnaissance, Subdomain Scanners.

Which projects share features with guelfoweb/knockpy?

Projects with overlapping indexed features include: aboul3la/sublist3r — Sublist3r is a subdomain enumeration tool and passive reconnaissance framework designed to discover subdomains by… edu4rdshl/findomain — Findomain is a subdomain enumeration and infrastructure analysis tool designed for attack surface mapping. It… six2dez/reconftw — reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the… jaykali/maskphish — Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network… guelfoweb/knock — Knock is an attack surface management tool and DNS reconnaissance framework used for discovering and mapping an… findomain/findomain — Findomain is a subdomain discovery tool and DNS resolver used for mapping an organization's external attack surface.…