awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to shmilylty/oneforall

Open-source alternatives to OneForAll

30 open-source projects similar to shmilylty/oneforall, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best OneForAll alternative.

  • gwen001/github-subdomainsgwen001 的头像

    gwen001/github-subdomains

    822在 GitHub 上查看↗
    Gobugbountygithubgo
    在 GitHub 上查看↗822
  • projectdiscovery/naabuprojectdiscovery 的头像

    projectdiscovery/naabu

    5,766在 GitHub 上查看↗

    Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to identify active services. It functions as a Go library for embedding port scanning into programs, and as a standalone tool that accepts targets as hostnames, IP addresses, CIDR ranges, or ASN numbers. The tool discovers live hosts before scanning, filters ports by range or top lists, and can integrate with Nmap for service version detection. The project distinguishes itself through its SYN-based port probing approach that sends TCP SYN packets and analyzes responses without complet

    Gocdn-exclusionhacktoberfestnmap
    在 GitHub 上查看↗5,766
  • ice3man543/suboverIce3man543 的头像

    Ice3man543/SubOver

    966在 GitHub 上查看↗

    A Powerful Subdomain Takeover Tool

    Go
    在 GitHub 上查看↗966
  • projectdiscovery/subfinderprojectdiscovery 的头像

    projectdiscovery/subfinder

    13,105在 GitHub 上查看↗

    Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It functions as a discovery engine that identifies and maps internet-exposed infrastructure, cloud-hosted assets, and network ranges to maintain a comprehensive inventory of an organization's digital footprint. The project distinguishes itself through a modular, template-driven scanning engine that executes security checks against discovered assets. It leverages cloud-native asset discovery to query provider APIs and infrastructure metadata, while supporting distributed agent orc

    Gobugbountyhackinghacktoberfest
    在 GitHub 上查看↗13,105

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Find more with AI search
  • michenriksen/aquatonemichenriksen 的头像

    michenriksen/aquatone

    5,940在 GitHub 上查看↗

    Aquatone is a web screenshot reconnaissance tool that captures full-page screenshots of web services discovered during network reconnaissance and groups them by visual similarity. It scans a list of hosts or domains for HTTP and HTTPS services on common and custom ports to find responsive web endpoints, then takes full-page screenshots of those pages for quick review. The tool accepts piped input from other tools and extracts URLs, domains, and IP addresses using regex pattern matching, making it pipeline-friendly for integration into existing workflows. It can also read XML output from Nmap

    Go
    在 GitHub 上查看↗5,940
  • infosec-au/altdnsinfosec-au 的头像

    infosec-au/altdns

    2,501在 GitHub 上查看↗

    Generates permutations, alterations and mutations of subdomains and then resolves them

    Python
    在 GitHub 上查看↗2,501
  • knownsec/ksubdomainknownsec 的头像

    knownsec/ksubdomain

    2,388在 GitHub 上查看↗

    ksubdomain是一款基于无状态子域名爆破工具,支持在Windows/Linux/Mac上使用,它会很快的进行DNS爆破,在Mac和Windows上理论最大发包速度在30w/s,linux上为160w/s的速度。 ksubdomain的发送和接收是分离且不依赖系统,即使高并发发包,也不会占用系统描述符让系统网络阻塞。

    Go
    在 GitHub 上查看↗2,388
  • guelfoweb/knockguelfoweb 的头像

    guelfoweb/knock

    4,163在 GitHub 上查看↗

    Knock is an attack surface management tool and DNS reconnaissance framework used for discovering and mapping an organization's external infrastructure. It functions as a subdomain enumeration tool and HTTP security scanner to identify reachable hosts and organizational assets. The project distinguishes itself by using a passive-active hybrid enumeration strategy, combining external API lookups with active wordlist brute-force attacks and DNS zone transfers. It includes a multi-stage validation pipeline that detects DNS wildcard records and verifies host connectivity to filter out false positi

    Python
    在 GitHub 上查看↗4,163
  • owasp/amassOWASP 的头像

    OWASP/Amass

    14,722在 GitHub 上查看↗

    Amass is a network attack surface mapper and reconnaissance framework designed to discover and map the external, internet-facing infrastructure of a target organization. It functions as an open source intelligence tool that identifies public network boundaries and locates hidden or forgotten subdomains to define an organization's total reachable footprint. The project utilizes passive-source data aggregation from external APIs and public databases alongside active DNS brute-forcing and recursive subdomain expansion. It employs a graph-based asset mapping system to visualize the relationships

    Go
    在 GitHub 上查看↗14,722
  • yunxu1/dnsubY

    yunxu1/dnsub

    0在 GitHub 上查看↗

    ​ 本工具通过字典枚举的方式用于扫描探测子域名,意在帮助用户梳理子域名资产使用,dnsub使用go语言高并发扫描,并可展示 子域名、IP 、 CNAME、域名信息,处理了枚举中常见的泛解析问题,支持加载多个字典,枚举探测更多深度的子域名信息,帮助用户快速掌握域名资产,扫描速度快效率高且跨平台,希望这款工具能帮助你有更多的收获 : )

    在 GitHub 上查看↗0
  • aboul3la/sublist3raboul3la 的头像

    aboul3la/Sublist3r

    10,957在 GitHub 上查看↗

    Sublist3r is a subdomain enumeration tool and passive reconnaissance framework designed to discover subdomains by querying search engines and public intelligence sources. It functions as a security tool for identifying the digital footprint of a target domain. The project provides both passive enumeration through multi-source API aggregation and active discovery via a DNS brute force tool. It includes a TCP port scanner to identify active services and open ports on discovered subdomains, facilitating attack surface mapping. The tool can be used as a standalone utility or as a Python security

    Python
    在 GitHub 上查看↗10,957
  • laramies/theharvesterlaramies 的头像

    laramies/theHarvester

    15,687在 GitHub 上查看↗

    theHarvester is a command-line utility designed for gathering open-source intelligence and mapping an organization's external attack surface. It functions as a security information gathering framework that automates the collection of publicly available data to assist in reconnaissance and threat analysis. The tool utilizes a plugin-based architecture to execute isolated queries against various search engines and public databases. It employs asynchronous task execution to run multiple discovery operations in parallel, while a centralized pipeline aggregates and deduplicates findings from these

    Pythonblueteamdiscoveryemails
    在 GitHub 上查看↗15,687
  • hktalent/scan4allhktalent 的头像

    hktalent/scan4all

    6,127在 GitHub 上查看↗

    scan4all is an all-in-one vulnerability scanner that orchestrates parallel network reconnaissance, service cracking, and exploit execution across a wide range of protocols. It combines port discovery, web fingerprinting, password cracking, and a plugin-based database of over 15,000 proof-of-concept exploits into a single automated pipeline, with results streamed to Elasticsearch for structured querying and analysis. The tool distinguishes itself through its multi-engine orchestration, coordinating tools like nmap, naabu, and nuclei under one pipeline to avoid redundant work and share results.

    Go
    在 GitHub 上查看↗6,127
  • chvancooten/bugbountyscannerchvancooten 的头像

    chvancooten/BugBountyScanner

    921在 GitHub 上查看↗
    Shellbug-bounty-reconnaissancebugbountydocker-image
    在 GitHub 上查看↗921
  • chuhades/dnsbruteC

    chuhades/dnsbrute

    0在 GitHub 上查看↗

    query over api - http://www.hackertarget.com/ - http://ptrarchive.com/ - ...

    在 GitHub 上查看↗0
  • bit4woo/teemobit4woo 的头像

    bit4woo/Teemo

    1,015在 GitHub 上查看↗

    项目地址:https://github.com/bit4woo/teemo

    Python
    在 GitHub 上查看↗1,015
  • christruncer/eyewitnessChrisTruncer 的头像

    ChrisTruncer/EyeWitness

    60在 GitHub 上查看↗

    EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.

    在 GitHub 上查看↗60
  • byt3bl33d3r/witnessmebyt3bl33d3r 的头像

    byt3bl33d3r/WitnessMe

    763在 GitHub 上查看↗

    Web Inventory tool, takes screenshots of webpages using Pyppeteer (headless Chrome/Chromium) and provides some extra bells & whistles to make life easier.

    Python
    在 GitHub 上查看↗763
  • bishopfox/spoofcheckB

    BishopFox/spoofcheck

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • aufzayed/hydrareconA

    aufzayed/HydraRecon

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • dwisiswant0/apkleaksdwisiswant0 的头像

    dwisiswant0/apkleaks

    6,102在 GitHub 上查看↗

    Apkleaks is a static analysis tool and security auditor designed to extract hardcoded secrets, API endpoints, and sensitive data from Android application packages. It operates as a secret scanner that analyzes compiled binaries without executing them to identify potential information leaks and insecure endpoints. The tool utilizes a regex-based data extraction engine to identify sensitive strings within decompiled code. It supports customization through JSON-defined search patterns and provides configuration flags to tune the behavior of the underlying disassembler. The analysis pipeline enc

    Python
    在 GitHub 上查看↗6,102
  • dolevf/graphw00fdolevf 的头像

    dolevf/graphw00f

    857在 GitHub 上查看↗

    graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology is behind a given GraphQL endpoint.

    Python
    在 GitHub 上查看↗857
  • dwisiswant0/go-dorkdwisiswant0 的头像

    dwisiswant0/go-dork

    1,284在 GitHub 上查看↗

    The fastest dork scanner written in Go.

    Go
    在 GitHub 上查看↗1,284
  • easyrecon/hunt3rE

    EasyRecon/Hunt3r

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • edoardottt/cariddiedoardottt 的头像

    edoardottt/cariddi

    3,427在 GitHub 上查看↗

    Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

    Go
    在 GitHub 上查看↗3,427
  • edoardottt/cspreconedoardottt 的头像

    edoardottt/csprecon

    514在 GitHub 上查看↗

    Discover new target domains using Content Security Policy

    Go
    在 GitHub 上查看↗514
  • edoardottt/favireconE

    edoardottt/favirecon

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • edoardottt/longtongueE

    edoardottt/longtongue

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • edoardottt/scillaedoardottt 的头像

    edoardottt/scilla

    1,236在 GitHub 上查看↗

    Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration

    Go
    在 GitHub 上查看↗1,236
  • brandonskerritt/rustscanB

    brandonskerritt/RustScan

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0