Amass
featuredOWASP Amass for in-depth subdomain enumeration and attack surface mapping.
Nmap
featuredIndustry-standard network scanner for port discovery, service detection, and OS fingerprinting. Core recon tool for every engagement.
Subfinder
featuredPassive subdomain discovery tool. Fast and reliable for bug bounty recon.
dnsenum
DNS enumeration script for zone transfers, subdomain brute force, and record discovery.
Enum4linux
Enumerate Windows/Samba information: users, shares, policies.
Maltego
Graph-based OSINT and link analysis for mapping people, domains, and infrastructure relationships.
Masscan
Internet-scale port scanner — extremely fast asynchronous TCP scanning.
Recon-ng
Modular recon framework with a Metasploit-like interface for OSINT workflows.
theHarvester
OSINT tool to gather emails, subdomains, hosts, and employee names from public sources.