spiderfoot

SpiderFoot, the most complete OSINT collection and reconnaissance tool.

Github星跟踪图

ABOUT

SpiderFoot is an open source intelligence (OSINT) automation tool. It integrates with just about every data source available and utilises a range of methods for data analysis, making that data easy to navigate.

SpiderFoot has an embedded web-server for providing a clean and intuitive web-based interface but can also be used completely via the command-line. It's written in Python 3 and GPL-licensed.

FEATURES

  • Web based UI or CLI
  • Over 170 modules (see below)
  • Python 3
  • CSV/JSON/GEXF export
  • API key export/import
  • SQLite back-end for custom querying
  • Highly configurable
  • Fully documented
  • Visualisations
  • TOR integration for dark web searching
  • Dockerfile for Docker-based deployments
  • Can call other tools like DNSTwist, Whatweb and CMSeeK
  • Actively developed since 2012!

USES

SpiderFoot's 170+ modules feed each other in a pub/sub model to ensure maximum data extraction to do things like:

  • Host/sub-domain/TLD enumeration/extraction
  • E-mail address enumeration/extraction
  • Phone number extraction
  • Bitcoin and Ethereum address extraction
  • DNS zone transfers
  • Threat intelligence and Blacklist queries
  • API integraiton with SHODAN, HaveIBeenPwned, Censys, AlienVault, SecurityTrails, etc.
  • Social media account enumeration
  • S3/Azure/Digitalocean bucket enumeration/scraping
  • IP geo-location
  • Web scraping, web content analysis
  • Image and binary file meta data analysis
  • Office document meta data analysis
  • Dark web searches
  • So much more...

See it in action here, performing some DNS recon:

asciicast

PURPOSE

SpiderFoot can be used offensively (e.g. in a red team exercise or penetration test) for reconnaissance of your target or defensively to gather information about what you or your organisation might have exposed over the Internet.

You can target the following entities in a SpiderFoot scan:

  • IP address
  • Domain/sub-domain name
  • Hostname
  • Network subnet (CIDR)
  • ASN
  • E-mail address
  • Phone number
  • Username
  • Person's name

Read more at the project website, including more complete documentation, blog posts with tutorials/guides, plus information about SpiderFoot HX.

Latest updates announced on Twitter.

主要指标

概览
名称与所有者smicallef/spiderfoot
主编程语言Python
编程语言Python (语言数: 6)
平台
许可证MIT License
所有者活动
创建于2012-04-28 07:10:13
推送于2024-12-15 13:13:03
最后一次提交2023-11-06 05:36:23
发布数33
最新版本名称v4.0 (发布于 )
第一版名称v2.0.0-final (发布于 2013-05-04 08:57:43)
用户参与
星数14.6k
关注者数374
派生数2.5k
提交数3.7k
已启用问题?
问题数619
打开的问题数188
拉请求数1162
打开的拉请求数27
关闭的拉请求数104
项目设置
已启用Wiki?
已存档?
是复刻?
已锁定?
是镜像?
是私有?