Automate OSINT techniques
The Harvester
This tool gathers subdomain names, IP addresses, email addresses and employee names while only needing an initial domain name to start.
In order to use this tool you will need the following API Keys: Bing, Github, Hunter.io, Intelx, SecurityTrails, Shodan, Spyse.
theHarvester will work fine without these API keys but the search results may be limited.
Amass
Amass does not perform OSINT on employee names or email, it makes up for it in the large amount of subdomain OSINT sources.
Amass is set up as a suite of tools that can search for subdomains, ASNs, and IP addresses as well as perform brute force subdomain discovery.
Recon-ng
Recon-NG is more of a framework of tools rather than just one tool.
What makes it great is the extensibility through the Recon-NG Marketplace.
You can choose which addons you want to install as well as create your own for others to use.
Last updated