Category 08 · 41 resources

Domain / Dns / Ip / Internet-Asset Intelligence

Map the internet's infrastructure: find every subdomain, exposed service, certificate, IP and technology stack belonging to a target domain or organization.

shodan Web

https://www.shodan.io/

Search engine for internet-connected devices

How to use it

Search by IP, port, product or org (e.g., org:"Target" port:3389). Create a free account; filters like country:, ssl:, http.title: narrow results to exposed services.

Open resource →

censys Web

https://search.censys.io/

Internet asset & certificate search

How to use it

Query hosts and TLS certificates (e.g., parsed.names: example.com) to enumerate subdomains and services.

Open resource →

criminalip Web

https://www.criminalip.io/

IP & domain risk search

How to use it

Look up IPs and domains for open ports, vulnerabilities and abuse history.

Open resource →

binaryedge Web

https://www.binaryedge.io/

Attack-surface data platform

How to use it

Search their internet-scan data for exposed services, or use the API for continuous monitoring.

Open resource →

netlas Web

https://netlas.io/

Internet asset search

How to use it

Query by domain, IP, certificate field or response content; generous free tier.

Open resource →

onyphe Web

https://search.onyphe.io/

Cyber-defense search engine

How to use it

Search internet-scan, threat and passive-DNS data by IP or domain.

Open resource →

leakix Web

https://leakix.net/

Exposed-service & leak search

How to use it

Find services leaking data (open databases, git repos) by domain or keyword.

Open resource →

greynoise Web

https://viz.greynoise.io/

Internet noise intelligence

How to use it

Check whether an IP is a known scanner or benign service before treating alerts as attacks.

Open resource →

urlscan Web

https://urlscan.io/

URL sandbox scanner

How to use it

Submit a URL to screenshot it, record all requests, and see contacted IPs/domains — safely inspect phishing links.

Open resource →

virustotal Web

https://www.virustotal.com/

Multi-engine malware scanner

How to use it

Upload a file or paste a URL/hash to get verdicts from 70+ antivirus engines plus behavior reports. Don't upload confidential files — uploads are shared.

Open resource →

securitytrails Web

https://www.securitytrails.com/

DNS & domain intelligence

How to use it

Enter a domain for full DNS history, subdomains and neighboring IPs.

Open resource →

builtwith Web

https://builtwith.com/

Tech-stack profiler

How to use it

Enter any site to see the technologies, analytics and frameworks it runs.

Open resource →

wappalyzer Web

https://www.wappalyzer.com/

Technology detection

How to use it

Use the browser extension or lookup to identify a site's CMS, frameworks and servers.

Open resource →

dnsdumpster Web

https://dnsdumpster.com/

Free DNS recon

How to use it

Enter a domain for a map of subdomains and DNS records from passive sources.

Open resource →

crt Web

https://crt.sh/

Certificate Transparency search

How to use it

Search %.example.com to list every certificate ever issued — the classic free subdomain enumerator.

Open resource →

bgp Web

https://bgp.tools/

BGP & network intelligence

How to use it

Look up any IP or ASN to see prefixes, peers and ownership — map an organization's entire netblock.

Open resource →

he Web

https://bgp.he.net/

Hurricane Electric BGP toolkit

How to use it

Check ASN announcements, peers and IPv4/IPv6 prefixes.

Open resource →

who Web

https://who.is/

WHOIS lookup

How to use it

Enter a domain to see registrar, dates and (unredacted where legal) registrant info.

Open resource →

viewdns Web

https://viewdns.info/

Swiss-army DNS tools

How to use it

Reverse IP, WHOIS history, DNS record lookups and more from one page.

Open resource →

dnschecker Web

https://dnschecker.org/

Global DNS propagation checker

How to use it

Check a record from dozens of worldwide resolvers to verify propagation.

Open resource →

centralops Web

https://centralops.net/

Network utility suite

How to use it

WHOIS, traceroute, email dossier and domain dossier tools.

Open resource →

mxtoolbox Web

https://mxtoolbox.com/

Email/DNS health checker

How to use it

Diagnose MX, SPF, DKIM, blacklist status for a domain — standard for email deliverability and spoofing checks.

Open resource →

amass GitHub

https://github.com/owasp-amass/amass/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

subfinder GitHub

https://github.com/projectdiscovery/subfinder/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

httpx GitHub

https://github.com/projectdiscovery/httpx/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

nuclei GitHub

https://github.com/projectdiscovery/nuclei/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

naabu GitHub

https://github.com/projectdiscovery/naabu/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

dnsx GitHub

https://github.com/projectdiscovery/dnsx/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

katana GitHub

https://github.com/projectdiscovery/katana/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

shuffledns GitHub

https://github.com/projectdiscovery/shuffledns/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

chaos-client GitHub

https://github.com/projectdiscovery/chaos-client/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

nuclei-templates GitHub

https://github.com/projectdiscovery/nuclei-templates/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

dnstwist GitHub

https://github.com/elceef/dnstwist/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

massdns GitHub

https://github.com/blechschmidt/massdns/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

fierce GitHub

https://github.com/mschwager/fierce/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

puredns GitHub

https://github.com/d3mondev/puredns/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

assetfinder GitHub

https://github.com/tomnomnom/assetfinder/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

waybackurls GitHub

https://github.com/tomnomnom/waybackurls/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

gau GitHub

https://github.com/lc/gau/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

hakrawler GitHub

https://github.com/hakluke/hakrawler/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

gospider GitHub

https://github.com/jaeles-project/gospider/

Open-source code repository

How to use it

Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.

Open resource →

Frequently asked questions

Do I need to install anything for these 08 tools?

Most entries here are GitHub projects — clone the repository and follow the README's install steps (pip, npm, go or cargo). A Kali Linux VM gives you many of them pre-installed.

Is it legal to use these resources?

Public-record lookups and defensive/research use are generally lawful, but rules vary by country and tool. Only test systems you own or have written authorization to test, respect each site's terms of service, and never use personal data unlawfully.

Where should a beginner start in this category?

Start with the web-based tools at the top of the list — they need no setup. Read each card's “How to use it” panel, run one real query, and only then move to installable tools.