Skip to content
#

passive-recon

Here are 30 public repositories matching this topic...

Static is a lightweight, dependency-free typosquatting reconnaissance tool written in pure Python. It generates common typo variations of a target domain and checks them using DNS and HTTP/HTTPS heuristics to identify potentially available domains and redirect behavior.

  • Updated Dec 21, 2025
  • Python

JSHound is a recon tool designed for bug bounty hunters and pentesters. It helps you extract JavaScript files of a target domain from multiple sources (Wayback Machine, Common Crawl, urlscan.io), and then searches those files for potentially sensitive information such as API keys, tokens, credentials, and more.

  • Updated Feb 7, 2026
  • Python

👻 GhostPath — A powerful modular reconnaissance toolkit built for hackers, OSINT professionals & bug bounty hunters — passive + active recon in a sleek CLI shell. Discover subdomains, probe paths, mine archives and hunt certificates — all from one interactive terminal interface.

  • Updated Aug 28, 2025
  • Python

ReqEye is a CLI assistant for HTTP request analysis, designed to help security researchers, bug bounty hunters, and pentesters identify high‑value entry points worth manual testing. It does not scan targets, send traffic, or claim vulnerabilities. ReqEye focuses on where to look, not on making assumptions.

  • Updated Dec 23, 2025
  • Python

Improve this page

Add a description, image, and links to the passive-recon topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the passive-recon topic, visit your repo's landing page and select "manage topics."

Learn more