Reconnaissance
Reconnaissance is a reference category for Red Team work. Select an upstream project only after confirming scope, authorization, license, and maintenance status.
15 published reference entries · reviewed catalogue metadata is shown on every card.
Next research step: continue with enumeration references.
An active/passive ARP reconnaissance tool, initially developed to gain information about wireless networks without DHCP servers.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
A fast ARP packet scanner that shows every active IPv4 device on your local subnet.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
A tool used to brute-force URIs (directories and files) in web sites, DNS subdomains, and virtual host names.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
A fast web fuzzer written in Go.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
The Web Fuzzer. A tool designed for bruteforcing Web Applications.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
An advanced web path scanner.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Next generation web scanner that identifies what websites are running, including CMS, blogging platforms, statistic/analytics packages, JavaScript libraries, web servers, and embedded devices.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
An HTTP parameter discovery tool used to find hidden GET/POST parameters for web application testing.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
A Web Content Scanner. It looks for existing (and/or hidden) Web Objects by launching a dictionary based attack against a web server.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
A multi threaded java application designed to brute force directories and files names on web/application servers.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
A full-featured Web Reconnaissance framework written in Python.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
A subdomain discovery tool that discovers valid subdomains for websites by using passive online sources.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
A fast and effective cross-platform subdomain enumeration tool that heavily leverages Certificate Transparency logs and OSINT APIs.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
A powerful utility that uncovers the technologies used on websites. It detects content management systems, ecommerce platforms, web servers, JavaScript frameworks, analytics tools and many more.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.