spiderfoot

SpiderFoot, the most complete OSINT collection and reconnaissance tool.

Github星跟蹤圖

ABOUT

SpiderFoot is an open source intelligence (OSINT) automation tool. It integrates with just about every data source available and utilises a range of methods for data analysis, making that data easy to navigate.

SpiderFoot has an embedded web-server for providing a clean and intuitive web-based interface but can also be used completely via the command-line. It's written in Python 3 and GPL-licensed.

FEATURES

  • Web based UI or CLI
  • Over 170 modules (see below)
  • Python 3
  • CSV/JSON/GEXF export
  • API key export/import
  • SQLite back-end for custom querying
  • Highly configurable
  • Fully documented
  • Visualisations
  • TOR integration for dark web searching
  • Dockerfile for Docker-based deployments
  • Can call other tools like DNSTwist, Whatweb and CMSeeK
  • Actively developed since 2012!

USES

SpiderFoot's 170+ modules feed each other in a pub/sub model to ensure maximum data extraction to do things like:

  • Host/sub-domain/TLD enumeration/extraction
  • E-mail address enumeration/extraction
  • Phone number extraction
  • Bitcoin and Ethereum address extraction
  • DNS zone transfers
  • Threat intelligence and Blacklist queries
  • API integraiton with SHODAN, HaveIBeenPwned, Censys, AlienVault, SecurityTrails, etc.
  • Social media account enumeration
  • S3/Azure/Digitalocean bucket enumeration/scraping
  • IP geo-location
  • Web scraping, web content analysis
  • Image and binary file meta data analysis
  • Office document meta data analysis
  • Dark web searches
  • So much more...

See it in action here, performing some DNS recon:

asciicast

PURPOSE

SpiderFoot can be used offensively (e.g. in a red team exercise or penetration test) for reconnaissance of your target or defensively to gather information about what you or your organisation might have exposed over the Internet.

You can target the following entities in a SpiderFoot scan:

  • IP address
  • Domain/sub-domain name
  • Hostname
  • Network subnet (CIDR)
  • ASN
  • E-mail address
  • Phone number
  • Username
  • Person's name

Read more at the project website, including more complete documentation, blog posts with tutorials/guides, plus information about SpiderFoot HX.

Latest updates announced on Twitter.

主要指標

概覽
名稱與所有者smicallef/spiderfoot
主編程語言Python
編程語言Python (語言數: 6)
平台
許可證MIT License
所有者活动
創建於2012-04-28 07:10:13
推送於2024-12-15 13:13:03
最后一次提交2023-11-06 05:36:23
發布數33
最新版本名稱v4.0 (發布於 )
第一版名稱v2.0.0-final (發布於 2013-05-04 08:57:43)
用户参与
星數14.2k
關注者數374
派生數2.4k
提交數3.7k
已啟用問題?
問題數616
打開的問題數186
拉請求數1162
打開的拉請求數26
關閉的拉請求數103
项目设置
已啟用Wiki?
已存檔?
是復刻?
已鎖定?
是鏡像?
是私有?