awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
smicallef avatar

smicallef/spiderfoot

0
View on GitHub↗
18,189 stars·3,029 forks·Python·MIT·12 viewswww.spiderfoot.net↗

Spiderfoot

SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the collection and correlation of data for security investigations. It functions as a comprehensive platform that automates the querying of hundreds of public data sources to map digital footprints, identify exposed assets, and uncover potential security threats across an organization's external perimeter.

The platform distinguishes itself through a modular, plugin-based architecture that executes data gathering tasks in parallel, supported by a directed graph data model that tracks relationships between discovered entities. It utilizes dynamic workflow orchestration and event-driven correlation to guide users through multi-stage investigations, automatically triggering follow-up queries based on newly discovered indicators of compromise.

Beyond core reconnaissance, the system provides extensive capabilities for attack surface management, credential leak monitoring, and threat actor tracking. It supports proactive security operations by facilitating automated threat hunting, generating detection signatures, and simulating attack scenarios to identify visibility gaps. The platform also manages the full intelligence lifecycle, from aggregating disparate data feeds and enriching findings with contextual analysis to producing actionable reports for risk evaluation.

Features

  • OSINT Automation Frameworks - Automates intelligence gathering by querying hundreds of public data sources to map digital footprints.
  • Attack Surface Management - Identifies and monitors internet-exposed digital assets to reduce organizational risk and uncover shadow IT.
  • Credential Monitoring Services - The platform notifies security teams in real-time when sensitive data or user credentials appear in underground markets to enable rapid mitigation of potential breaches.
  • Threat Intelligence Platforms - A unified database stores heterogeneous security data to facilitate cross-referencing and historical analysis of threat actor activity.
  • Investigation Orchestration - Sequential investigation steps are managed through a state machine that guides users through complex multi-stage security research.
  • Reconnaissance and Assessment Platforms - Aggregates data from public records and threat feeds to discover exposed assets and analyze attack surfaces.
  • Asset Discovery Tools - The platform scans networks and public records continuously to locate shadow IT, subsidiary assets, and distributed systems for comprehensive visibility across the organization.
  • Automated Hunting - Provides automated, high-frequency intelligence gathering to proactively identify adversary tactics across an organization's digital footprint.
  • Exposure Monitoring - Correlates vulnerability data with exploit status and tracks organizational mentions in breach alerts and underground forums.
  • Graph Data Models - Entities and their relationships are stored as a connected graph to track dependencies and propagate investigative findings.
  • Dark Web Monitoring - The platform scans underground forums and hidden digital spaces to identify leaked credentials, mentions of organizational assets, or emerging cyber threats.
  • Infrastructure Detection - The platform identifies malicious IP addresses, command and control servers, and malware families associated with an organization's domains or network assets.
  • Brand Impersonation Detection - The platform identifies phishing infrastructure, lookalike domains, and fraudulent applications to mitigate brand abuse and protect against customer-facing digital threats.
  • Automated Hunting - Executes systematic investigation workflows to proactively detect malicious activity and security control gaps.
  • OSINT Frameworks - Automates intelligence gathering and attack surface mapping.
  • Investigation Frameworks - Automated reconnaissance tool for gathering intelligence from various sources.
  • Reconnaissance and Discovery - Automated OSINT collection tool with 200+ modules for reconnaissance.
  • Reconnaissance Frameworks - Automation platform with modules for threat intelligence and asset discovery.
  • Reconnaissance Tools - Automation tool for OSINT and reconnaissance.
  • OSINT and Search Tools - Automation framework for gathering and analyzing OSINT data.
  • Miscellaneous Tools - OSINT automation tool.
  • Open Source Intelligence - Automated OSINT collection tool with numerous integrated modules.
  • Reconnaissance - Automates OSINT and attack surface mapping.
  • Security And Forensics - Reconnaissance tool for gathering intelligence from public sources.
  • Security And Privacy - OSINT automation for threat intelligence.
  • Vulnerability Scanning and Auditing - OSINT automation tool for intelligence gathering.
  • Indicator Feed Ingestion - Integrates high-fidelity indicator feeds into security stacks to automate the detection and blocking of malicious activity.
  • Behavioral Hunt Packages - Deploys behavior-based hunt packages to identify security control gaps and adversary activity within internal data.
  • Contextual Enrichment - Enriches security findings with contextual data to help teams prioritize risks and reduce false positive alerts.
  • Fraud Analysis - The platform tracks and investigates deceitful operations targeting sensitive information to identify exploitation patterns and prevent financial or personal harm.
  • Fraud Detection Systems - The platform identifies the source of fraudulent transactions by correlating stolen card data with point-of-purchase history to support investigations and preventative action.
  • Attack Simulations - Tests existing security defenses against potential attack vectors to identify visibility gaps and validate response strategies.
  • Signature Generators - Generates intrusion detection system signatures and rules to identify malicious network traffic and malware families.
  • Vendor Risk Assessments - The platform evaluates the security posture of vendors and suppliers by tracking vulnerabilities and configuration issues across their digital assets on a recurring schedule.
  • Threat Actor Tracking Tools - Tracks the activities, tools, and infrastructure of cybercriminal groups using deep and dark web sources.
  • Contextual Vulnerability Analysis - Produces contextualized analysis and remediation strategies to help security teams evaluate risks and prioritize patching efforts.
  • Event-Driven Triggers - New intelligence triggers automated follow-up queries to expand the investigation scope based on discovered indicators of compromise.
  • Asynchronous Task Queueing - Background workers process long-running data collection jobs to maintain system responsiveness during intensive scanning operations.
  • Monitoring Coverage Audits - The platform analyzes the digital environment to identify gaps in monitoring coverage and optimize the configuration of security tools.
  • Breach Monitoring - Provides continuous monitoring of data breaches and leaked information to support incident response.
  • Detection Logic Development - Enables the creation of specialized detection logic and behavioral signatures to identify signs of malicious activity.
  • Malware Analysis - Tracks adversary infrastructure in near real-time to capture secondary payloads and botnet commands.
  • Intelligence Reporting - Produces detailed bulletins and actor summaries to provide context on emerging underground trends and security risks.
  • Modular Plugin Architectures - Independent data gathering modules execute in parallel to collect and normalize intelligence from diverse external sources.
  • Alert Management - The platform filters and prioritizes incoming security notifications to reduce noise and ensure analysts focus on the most critical threats to the organization.

Star history

Star history chart for smicallef/spiderfootStar history chart for smicallef/spiderfoot

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to Spiderfoot

Similar open-source projects, ranked by how many features they share with Spiderfoot.
  • projectdiscovery/subfinderprojectdiscovery avatar

    projectdiscovery/subfinder

    13,105View on GitHub↗

    Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It functions as a discovery engine that identifies and maps internet-exposed infrastructure, cloud-hosted assets, and network ranges to maintain a comprehensive inventory of an organization's digital footprint. The project distinguishes itself through a modular, template-driven scanning engine that executes security checks against discovered assets. It leverages cloud-native asset discovery to query provider APIs and infrastructure metadata, while supporting distributed agent orc

    Gobugbountyhackinghacktoberfest
    View on GitHub↗13,105
  • six2dez/reconftwsix2dez avatar

    six2dez/reconftw

    7,226View on GitHub↗

    reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio

    Shellbug-bountybugbountybugbounty-tool
    View on GitHub↗7,226
  • owasp-amass/amassowasp-amass avatar

    owasp-amass/amass

    14,155View on GitHub↗

    Amass is an attack surface management tool designed to identify, map, and inventory an organization's internet-facing digital assets. It functions as a security asset discovery engine that systematically expands an organization's known infrastructure footprint through recursive domain name resolution and the collection of intelligence from diverse public data sources. The platform distinguishes itself by utilizing a graph-based modeling approach to organize discovered resources. By maintaining a persistent graph database, it tracks the relationships between infrastructure components and norma

    Goattack-surfacesdnsenumeration
    View on GitHub↗14,155
  • yogeshojha/rengineyogeshojha avatar

    yogeshojha/rengine

    8,472View on GitHub↗

    Rengine is an automated reconnaissance framework and vulnerability management platform designed for attack surface monitoring. It functions as a centralized hub for discovering subdomains and open ports, gathering open-source intelligence, and tracking security flaws across target networks. The system integrates large language models to analyze reconnaissance data and generate vulnerability descriptions and insights. It distinguishes itself through a plugin-based tool integration that wraps external security scanning binaries and a target mapping system that tracks changes to assets over time

    HTMLbug-bountybugbountyhacking
    View on GitHub↗8,472
See all 30 alternatives to Spiderfoot→

Frequently asked questions

What does smicallef/spiderfoot do?

SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the collection and correlation of data for security investigations. It functions as a comprehensive platform that automates the querying of hundreds of public data sources to map digital footprints, identify exposed assets, and uncover potential security threats across an organization's external perimeter.

What are the main features of smicallef/spiderfoot?

The main features of smicallef/spiderfoot are: OSINT Automation Frameworks, Attack Surface Management, Credential Monitoring Services, Threat Intelligence Platforms, Investigation Orchestration, Reconnaissance and Assessment Platforms, Asset Discovery Tools, Automated Hunting.

What are some open-source alternatives to smicallef/spiderfoot?

Open-source alternatives to smicallef/spiderfoot include: projectdiscovery/subfinder — Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It… six2dez/reconftw — reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the… owasp-amass/amass — Amass is an attack surface management tool designed to identify, map, and inventory an organization's internet-facing… yogeshojha/rengine — Rengine is an automated reconnaissance framework and vulnerability management platform designed for attack surface… 1n3/sn1per — Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate… lanmaster53/recon-ng — recon-ng is an open source intelligence reconnaissance framework designed to automate the collection and aggregation…