Search by Internet of Things, IP, Domains, and Subdomains
Services:
- Shodan — A renowned search engine for gathering information about internet-connected devices.
- Censys Search, GreyNoise, ZoomEye, Netlas, CriminalIp — IoT-focused search engines similar to Shodan.
- Buckets by Grayhatwarfar — A publicly searchable database of open AWS Buckets, Azure Blobs, and Digital Ocean Spaces..
- Public buckets — Search tool for public AWS S3 & Azure Blob buckets.
- macaddress.io, MAC Vendor Lookup, maclookup.app — Determine device manufacturers by MAC address, OUI, or IAB.
- CIRT, Default Password Lookup, Router Password, Open Sez Me — Databases for default passwords on various devices.
- sitereport.netcraft — Provides a comprehensive summary of registration data and technologies used on a website.
- IPVoid — A suite of tools for researching IP addresses, including blacklist checks, Whois, DNS lookup, and ping.
- who.is, DomainDossier, whois.domaintools — Tools for searching by registration data and Whois.
- DNSDumpster — A domain exploration tool that discovers hosts associated with a domain.
- ip-neighbors — Determines server location and names of hosts sharing the IP address.
- ShowMyIP — Bulk IP address search tool, capable of checking up to 100 IP addresses at once and exporting results to .csv files.
- MX Toolbox — Feature-rich tool for searching by domain name, IP address, or hostname.
- DNSViz — A set of open-source tools for analyzing and visualizing the domain name system.
- infosniper, ip2geolocation, ip2location, ipfingerprints, whoismind — Search engines for finding the approximate geographic location of an IP address and other relevant information.
- webmeup, openlinkprofiler, Meet Link Explorer — поиск по обратным ссылкам.
- RapidDNS — same IP domains n subdomains finder .
- CTSearch, crt — search by SSL/TLS certs released for certain domain.
Utils
- IVRE — A network intelligence framework, offering an alternative to Shodan, ZoomEye, Censys, and GreyNoise.
- OWASP Amass — A network scanner that searches for information in open sources, aggregating data from various search engines and databases.
- Infoooze — An OSINT tool based on NodeJs, combining port and subdomain scanning, DNS search, URL scanning, Whois search, and other functions.
- Automater — A utility for searching URLs, IP addresses, and MD5 hashes, designed to assist information security analysts.
- Raccoon — A reconnaissance and information gathering tool utilizing Nmap for port scanning and passive data retrieval techniques.
- Mitaka — пA tool for looking up IP addresses, MD5 hashes, ASN, and Bitcoin addresses.
- Photon — A scanner for extracting information from open sources, crawling specific websites for searches, keywords, subdomains, and more.
- AttackSurfaceMapper — A scanner with open-source search capabilities, seeking subdomains and associated IP addresses.
- HostHunter — Utilizes open-source intelligence techniques to match IP addresses to hostnames, with results exportable to CSV or TXT files.
- Subfinder — A modular tool for discovering subdomains using passive reconnaissance techniques.
- Sublist3r — Designed for finding subdomains using OSINT.
- WASP Amass — erforms network mapping using open-source information.
- Anubis — Another utility for detecting subdomains and gathering information about them from open sources.
- DOME — A Python script that conducts active and/or passive scanning to discover subdomains and identify open ports.
- Belati — A tool inspired by Foca and Datasploit, designed for collecting publicly available data and documents from websites. Foca Datasploit.