awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to punk-security/dnsreaper

Open-source alternatives to DnsReaper

30 open-source projects similar to punk-security/dnsreaper, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best DnsReaper alternative.

  • ice3man543/suboverIce3man543 avatar

    Ice3man543/SubOver

    966View on GitHub↗

    A Powerful Subdomain Takeover Tool

    Go
    View on GitHub↗966
  • anshumanbh/tko-subsanshumanbh avatar

    anshumanbh/tko-subs

    771View on GitHub↗

    A tool that can help detect and takeover subdomains with dead DNS records

    Go
    View on GitHub↗771
  • haccer/subjackhaccer avatar

    haccer/subjack

    2,091View on GitHub↗

    DNS Takeover tool written in Go

    Go
    View on GitHub↗2,091
  • jaykali/maskphishjaykali avatar

    jaykali/maskphish

    3,020View on GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Shellhackhackinghacking-tool
    View on GitHub↗3,020
  • six2dez/reconftwsix2dez avatar

    six2dez/reconftw

    7,226View on GitHub↗

    reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio

    Shellbug-bountybugbountybugbounty-tool
    View on GitHub↗7,226

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • k8gege/k8toolsk8gege avatar

    k8gege/K8tools

    6,167View on GitHub↗

    K8tools is a multi-stage attack framework that combines memory-only payload execution, credential testing, port forwarding, privilege escalation, and physical USB-based keystroke injection for comprehensive system compromise. At its core, the Ladon PowerShell module loads a multi-function scanner directly into memory, enabling command execution without writing files to disk, while supporting memory-only payload delivery that downloads and runs obfuscated shellcode or PowerShell commands to evade antivirus detection. The framework distinguishes itself through its breadth of integrated capabili

    PowerShell0daybrute-forcebypass
    View on GitHub↗6,167
  • 1n3/sn1per1N3 avatar

    1N3/Sn1per

    10,049View on GitHub↗

    Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets. The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan

    Shellattack-surfaceattack-surface-managementattacksurface
    View on GitHub↗10,049
  • anshumanbh/brutesubsanshumanbh avatar

    anshumanbh/brutesubs

    260View on GitHub↗

    An automation framework for running multiple open sourced subdomain bruteforcing tools (in parallel) using your own wordlists via Docker Compose

    Shell
    View on GitHub↗260
  • c3l3si4n/pugdnsC

    c3l3si4n/pugdns

    0View on GitHub↗
    View on GitHub↗0
  • alex14324/turbolist3ralex14324 avatar

    alex14324/Turbolist3r

    52View on GitHub↗

    Turbolist3r is a fork of the sublist3r subdomain discovery tool. In addition to the original OSINT capabilties of sublist3r, turbolist3r automates some analysis of the results, with a focus on subdomain takeover.

    Python
    View on GitHub↗52
  • guelfoweb/knockguelfoweb avatar

    guelfoweb/knock

    4,163View on GitHub↗

    Knock is an attack surface management tool and DNS reconnaissance framework used for discovering and mapping an organization's external infrastructure. It functions as a subdomain enumeration tool and HTTP security scanner to identify reachable hosts and organizational assets. The project distinguishes itself by using a passive-active hybrid enumeration strategy, combining external API lookups with active wordlist brute-force attacks and DNS zone transfers. It includes a multi-stage validation pipeline that detects DNS wildcard records and verifies host connectivity to filter out false positi

    Python
    View on GitHub↗4,163
  • christophetd/censys-subdomain-finderchristophetd avatar

    christophetd/censys-subdomain-finder

    843View on GitHub↗

    ⚡ Perform subdomain enumeration using the certificate transparency logs from Censys.

    Python
    View on GitHub↗843
  • cinerieus/as3ntcinerieus avatar

    cinerieus/as3nt

    14View on GitHub↗

    Another Subdomain ENumeration Tool

    Python
    View on GitHub↗14
  • codingo/vhostscancodingo avatar

    codingo/VHostScan

    1,299View on GitHub↗

    A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.

    Pythonbugbountyctf-toolsdiscovery-service
    View on GitHub↗1,299
  • blechschmidt/massdnsblechschmidt avatar

    blechschmidt/massdns

    3,611View on GitHub↗

    A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)

    Cbulk-dnsdnsdns-bruteforcer
    View on GitHub↗3,611
  • blacklanternsecurity/bbotblacklanternsecurity avatar

    blacklanternsecurity/bbot

    9,929View on GitHub↗

    This project is an open-source intelligence reconnaissance framework and recursive attack surface mapper. It functions as a containerized security scanner designed to map public-facing infrastructure, perform subdomain enumeration, and automate the gathering of open-source intelligence. The system employs a recursive discovery engine to iteratively explore target infrastructure, utilizing a plugin-based module architecture to extend scanning capabilities. It integrates third-party APIs for data enrichment and applies YARA rules across discovered assets to identify specific vulnerability patte

    Python
    View on GitHub↗9,929
  • aboul3la/sublist3raboul3la avatar

    aboul3la/Sublist3r

    10,957View on GitHub↗

    Sublist3r is a subdomain enumeration tool and passive reconnaissance framework designed to discover subdomains by querying search engines and public intelligence sources. It functions as a security tool for identifying the digital footprint of a target domain. The project provides both passive enumeration through multi-source API aggregation and active discovery via a DNS brute force tool. It includes a TCP port scanner to identify active services and open ports on discovered subdomains, facilitating attack surface mapping. The tool can be used as a standalone utility or as a Python security

    Python
    View on GitHub↗10,957
  • edoardottt/scillaedoardottt avatar

    edoardottt/scilla

    1,236View on GitHub↗

    Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration

    Go
    View on GitHub↗1,236
  • edu4rdshl/findomainEdu4rdSHL avatar

    Edu4rdSHL/findomain

    3,761View on GitHub↗

    Findomain is a subdomain enumeration and infrastructure analysis tool designed for attack surface mapping. It functions as a DNS reconnaissance suite that discovers subdomains using multiple data sources and API keys to identify the full extent of a target network. The system acts as an attack surface monitor by tracking subdomain changes over time and sending real-time alerts via webhooks when new assets are detected. It includes specialized capabilities for detecting DNS wildcards to filter false positives and resolving subdomain IPs through parallel resolution. The tool provides a workflo

    Rust
    View on GitHub↗3,761
  • findomain/findomainFindomain avatar

    Findomain/Findomain

    3,684View on GitHub↗

    Findomain is a subdomain discovery tool and DNS resolver used for mapping an organization's external attack surface. It functions as a DNS infrastructure analyzer that searches for registered subdomains associated with a root domain to uncover undocumented infrastructure and services. The project includes an attack surface monitor that tracks changes to subdomains over time, using differential state monitoring to identify newly created or deleted assets. It provides real-time alerting via webhooks when changes in the monitored domain surface are detected. The system performs high-speed DNS r

    Rustbugbountydnsosint
    View on GitHub↗3,684
  • fleetcaptain/turbolist3rfleetcaptain avatar

    fleetcaptain/Turbolist3r

    397View on GitHub↗

    Subdomain enumeration tool with analysis features for discovered domains

    Python
    View on GitHub↗397
  • glebarez/ceroglebarez avatar

    glebarez/cero

    691View on GitHub↗

    Scrape domain names from SSL certificates of arbitrary hosts

    Go
    View on GitHub↗691
  • edoardottt/cspreconedoardottt avatar

    edoardottt/csprecon

    514View on GitHub↗

    Discover new target domains using Content Security Policy

    Go
    View on GitHub↗514
  • gwen001/github-subdomainsgwen001 avatar

    gwen001/github-subdomains

    822View on GitHub↗
    Gobugbountygithubgo
    View on GitHub↗822
  • gwen001/gitlab-subdomainsgwen001 avatar

    gwen001/gitlab-subdomains

    106View on GitHub↗

    Find subdomains on GitLab.

    Go
    View on GitHub↗106
  • gwen001/related-domainsgwen001 avatar

    gwen001/related-domains

    105View on GitHub↗

    Find related domains of a given domain.

    Python
    View on GitHub↗105
  • appsecco/bugcrowd-levelup-subdomain-enumerationappsecco avatar

    appsecco/bugcrowd-levelup-subdomain-enumeration

    632View on GitHub↗

    This repository contains all the material from the talk "Esoteric sub-domain enumeration techniques" given at Bugcrowd LevelUp 2017 virtual conference

    Python
    View on GitHub↗632
  • hakluke/hakip2hosthakluke avatar

    hakluke/hakip2host

    459View on GitHub↗

    hakip2host takes a list of IP addresses via stdin, then does a series of checks to return associated domain names.

    Go
    View on GitHub↗459
  • hakluke/hakrevdnshakluke avatar

    hakluke/hakrevdns

    1,563View on GitHub↗

    Small, fast tool for performing reverse DNS lookups en masse.

    Go
    View on GitHub↗1,563
  • d3mondev/purednsd3mondev avatar

    d3mondev/puredns

    2,193View on GitHub↗

    Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries.

    Go
    View on GitHub↗2,193