Enrich Domain Name tools batch 4 (25 tools) with OSINT metadata

Add comprehensive enrichment fields for the following 25 Domain Name tools:
- Threatexpert.com Malicious URLs
- Zeus C2 Tracker
- Malware Domains Blacklist
- Blackweb
- Critical Stack Intel (R)
- DNS Sinkhole
- DNS-BH Malware Domain Blocklist
- Malware Domain List
- MalwareURL (R)
- scumware.org
- ZeuS Tracker
- Shadowserver Foundation
- Email Domain Validation
- vURL Online
- AlienVault Open Threat Exchange
- Web Inspector Online Scan
- Google Safe Browsing API
- Cisco Talos
- DNS Twist (T)
- URLCrazy (T)
- dnstwister
- Catphish (T)
- BuiltWith
- SiteSleuth

Populated fields for each tool:
- description: 1-2 sentence summary
- status: live/down/degraded
- pricing: free/freemium/paid
- bestFor: primary use-case
- input/output: data format
- opsec: passive/active/Unknown
- opsecNote: OPSEC implications
- Badges: localInstall, googleDork, registration, editUrl, api, invitationOnly, deprecated

Co-Authored-By: Paperclip <noreply@paperclip.ing>
This commit is contained in:
s0lray
2026-03-27 01:49:55 -04:00
co-authored by Paperclip
parent c0fbb9a7d3
commit 0905218daa
4 changed files with 1404 additions and 40 deletions
+551
View File
@@ -0,0 +1,551 @@
# THE-127: Domain Name Tools Enrichment - Batch 1
Enrichment data for 25 Domain Name tools in the OSINT Framework arf.json.
## Whois Records Category
### 1. Domain Dossier
```json
{
"description": "Free web-based tool that aggregates WHOIS, DNS, and network information for domains and IP addresses into a single consolidated report.",
"status": "live",
"pricing": "free",
"bestFor": "Quick domain and IP reconnaissance with DNS and WHOIS data",
"input": "Domain name or IP address",
"output": "WHOIS records, DNS records, IP information, registration details",
"opsec": "passive",
"opsecNote": "Queries public WHOIS and DNS records; does not contact the target domain directly.",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
}
```
### 2. domainIQ
```json
{
"description": "Comprehensive domain intelligence platform offering reverse lookups, ownership history, and related domain discovery. Trusted by government agencies, domain investors, and legal firms.",
"status": "live",
"pricing": "freemium",
"bestFor": "Domain ownership history, reverse analytics lookup, competitor domain research",
"input": "Domain name",
"output": "Domain owner information, historical ownership, similar domains, analytics data, reverse MX/IP/DNS lookups",
"opsec": "passive",
"opsecNote": "Queries aggregated domain data; does not probe the target directly.",
"localInstall": false,
"googleDork": false,
"registration": true,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
}
```
### 3. DomainTools Whois
```json
{
"description": "Enterprise-grade WHOIS API with decades of historical domain data and rapid query response. The industry leader for threat intelligence and domain tracking.",
"status": "live",
"pricing": "paid",
"bestFor": "Historical WHOIS research, threat actor tracking, enterprise domain intelligence",
"input": "Domain name or IP address",
"output": "Current and historical WHOIS records, registrant details, hosting history",
"opsec": "passive",
"opsecNote": "Queries cached WHOIS data; no direct contact with target infrastructure.",
"localInstall": false,
"googleDork": false,
"registration": true,
"editUrl": false,
"api": true,
"invitationOnly": false,
"deprecated": false
}
```
### 4. SWITCH Internet Domains Whois (.ch)
```json
{
"description": "Official Swiss domain registry WHOIS lookup service operated by SWITCH for .ch and .li country-code domains. Public registry with all owner contact details visible.",
"status": "live",
"pricing": "free",
"bestFor": ".ch and .li domain ownership research, Swiss Internet infrastructure lookup",
"input": ".ch or .li domain name",
"output": "Registrant contact details, creation/expiry dates, nameservers, registration status",
"opsec": "passive",
"opsecNote": "Queries the official SWITCH registry database; does not probe the target.",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
}
```
### 5. Whoisology
```json
{
"description": "Searchable archive of billions of current and historical domain WHOIS records with cross-referencing capabilities. Designed for InfoSec, legal, and research professionals.",
"status": "live",
"pricing": "freemium",
"bestFor": "Historical domain ownership, reverse WHOIS lookups, domain connection tracking",
"input": "Domain name, email, registrant name",
"output": "Historical WHOIS records, ownership changes, registrant information across domains",
"opsec": "passive",
"opsecNote": "Accesses archived WHOIS data; no direct probing of target domains.",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
}
```
### 6. Whois ARIN
```json
{
"description": "Official American Registry for Internet Numbers WHOIS and RDAP lookup service for IPv4, IPv6, ASNs, and organizations in the North American region.",
"status": "live",
"pricing": "free",
"bestFor": "IP address and ASN registration data, North American internet resource tracking",
"input": "IP address, ASN, organization name, contact information",
"output": "IP ownership, organization details, Points of Contact (POCs), ASN information",
"opsec": "passive",
"opsecNote": "Queries official ARIN database; does not contact targets or perform active scanning.",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
}
```
### 7. DNSstuff
```json
{
"description": "Suite of free DNS and network tools providing lookups, DNS checks, and WHOIS information for domain reconnaissance.",
"status": "live",
"pricing": "free",
"bestFor": "Quick DNS and WHOIS lookups, network diagnostics",
"input": "Domain name, IP address",
"output": "DNS records, WHOIS data, DNS propagation checks, nameserver information",
"opsec": "passive",
"opsecNote": "Queries public DNS and WHOIS servers; does not probe target infrastructure.",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
}
```
### 8. Robtex
```json
{
"description": "Comprehensive free DNS lookup and network intelligence tool with decade-spanning database containing billions of documents of internet data. Useful for forensics and threat actor tracking.",
"status": "live",
"pricing": "free",
"bestFor": "DNS reconnaissance, IP and domain relationship mapping, historical internet data lookup",
"input": "Domain name, IP address, hostname, autonomous system",
"output": "DNS records, IP information, SEO data, reputation scores, historical relationships",
"opsec": "passive",
"opsecNote": "Searches historical and cached DNS data; does not perform active probing.",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
}
```
### 9. Domaincrawler.com
```json
{
"description": "Enterprise-grade domain database covering 1.4+ billion registered and unregistered domains with 80+ billion historical records since 2008. Used by brand protection and OSINT professionals.",
"status": "live",
"pricing": "paid",
"bestFor": "Large-scale domain research, brand protection monitoring, zone file analysis, market intelligence",
"input": "Domain name, DNS data, technology stack filters",
"output": "Domain metadata, DNS configuration, SSL certificates, technology stack, ownership connections, historical data",
"opsec": "passive",
"opsecNote": "Queries aggregated domain database updated every 7 days; no active scanning of targets.",
"localInstall": false,
"googleDork": false,
"registration": true,
"editUrl": false,
"api": true,
"invitationOnly": false,
"deprecated": false
}
```
### 10. MarkMonitor Whois Search
```json
{
"description": "ICANN-accredited registrar and brand protection company offering WHOIS lookup and domain management services. Exclusively serves corporate clients including major global brands.",
"status": "live",
"pricing": "paid",
"bestFor": "Corporate domain portfolio management, brand protection, trademark monitoring",
"input": "Domain name",
"output": "WHOIS records, registration data, brand portfolio information",
"opsec": "passive",
"opsecNote": "Accesses standard WHOIS records through registered domain lookups; no direct target probing.",
"localInstall": false,
"googleDork": false,
"registration": true,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
}
```
### 11. easyWhois
```json
{
"description": "Free domain WHOIS lookup and DNS tools service. Now operated under the DomainHelp platform, providing domain registration information and DNS lookups.",
"status": "live",
"pricing": "free",
"bestFor": "Quick domain WHOIS lookups and DNS checks",
"input": "Domain name",
"output": "WHOIS records, DNS information, registrant details, nameservers",
"opsec": "passive",
"opsecNote": "Queries public WHOIS and DNS data; does not contact the target domain.",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
}
```
### 12. Website Informer
```json
{
"description": "Free domain and website information aggregator providing visitor statistics, safety status, Alexa rankings, ownership data, and technical details about websites.",
"status": "live",
"pricing": "free",
"bestFor": "Website profiling, ownership verification, traffic estimation, technical stack discovery",
"input": "Domain name or URL",
"output": "Visitor statistics, safety ratings, domain owner information, technology stack, Alexa rank, historical snapshots",
"opsec": "passive",
"opsecNote": "Aggregates public website data and statistics; does not contact the target infrastructure.",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
}
```
### 13. Who.is
```json
{
"description": "Comprehensive WHOIS and RDAP lookup service with large database of domain registration, DNS records, and IP information. Provides both current and historical data.",
"status": "live",
"pricing": "free",
"bestFor": "Domain registration research, WHOIS lookups, RDAP queries, IP tracking",
"input": "Domain name or IP address",
"output": "WHOIS records, RDAP data, DNS records, nameservers, registrant information",
"opsec": "passive",
"opsecNote": "Queries public WHOIS and RDAP databases; does not perform active scanning.",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
}
```
### 14. Whois AMPed
```json
{
"description": "Mobile-optimized WHOIS lookup service accessible via web interface for domain registration information and WHOIS queries.",
"status": "live",
"pricing": "free",
"bestFor": "Mobile-friendly WHOIS lookups, quick domain information retrieval",
"input": "Domain name",
"output": "WHOIS records, domain registration information, registrant details",
"opsec": "passive",
"opsecNote": "Accesses public WHOIS data; no target probing or direct contact.",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
}
```
### 15. ViewDNS.info
```json
{
"description": "Comprehensive DNS lookup and WHOIS service providing detailed DNS records, reverse IP lookups, reverse WHOIS searches, and API access for automated queries.",
"status": "live",
"pricing": "free",
"bestFor": "DNS reconnaissance, reverse IP and reverse WHOIS lookups, historical DNS tracking",
"input": "Domain name, IP address, registrant name/email, nameserver",
"output": "DNS records, WHOIS information, reverse lookups, IP hosting, historical DNS changes",
"opsec": "passive",
"opsecNote": "Queries public DNS and WHOIS data; does not perform active probing of targets.",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": true,
"invitationOnly": false,
"deprecated": false
}
```
### 16. Daily DNS Changes
```json
{
"description": "DomainTools service monitoring DNS record changes across domains, detecting newly registered subdomains and tracking DNS infrastructure modifications.",
"status": "live",
"pricing": "freemium",
"bestFor": "DNS change detection, subdomain discovery, infrastructure monitoring",
"input": "Domain name",
"output": "New DNS records, nameserver changes, subdomain discoveries, historical DNS changes",
"opsec": "passive",
"opsecNote": "Monitors public DNS records for changes; no active scanning or direct contact.",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
}
```
### 17. IP2WHOIS
```json
{
"description": "Free WHOIS lookup service for domain names and IP addresses, providing registration details, registrant information, location data, and API access.",
"status": "live",
"pricing": "free",
"bestFor": "Domain and IP WHOIS lookups, registrant research",
"input": "Domain name or IP address",
"output": "WHOIS records, registrant details, location information, registration dates",
"opsec": "passive",
"opsecNote": "Queries public WHOIS databases; does not contact the target.",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": true,
"invitationOnly": false,
"deprecated": false
}
```
### 18. Netlas.io
```json
{
"description": "Comprehensive internet-wide scanning and OSINT platform providing DNS, WHOIS, SSL, and network reconnaissance with attack surface discovery capabilities.",
"status": "live",
"pricing": "freemium",
"bestFor": "Internet reconnaissance, DNS and WHOIS lookups, attack surface discovery, vulnerability research",
"input": "Domain name, IP address, ASN, DNS records",
"output": "DNS records, WHOIS data, open ports, SSL certificates, service information, historical data",
"opsec": "passive",
"opsecNote": "Queries cached internet scanning data; free tier available with 50 daily requests.",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": true,
"invitationOnly": false,
"deprecated": false
}
```
## Subdomains Category
### 19. SynapsInt
```json
{
"description": "Unified web-based OSINT research platform supporting domain, IP, SSL, analytics, email, phone, and social media lookups with subdomain enumeration.",
"status": "live",
"pricing": "free",
"bestFor": "Unified OSINT research, subdomain discovery, multi-vector intelligence gathering",
"input": "Domain, IP, email, phone, username, CVE ID",
"output": "Subdomains, DNS records, WHOIS data, open ports, vulnerabilities, social media accounts, historical data",
"opsec": "passive",
"opsecNote": "Aggregates publicly available information from multiple sources; no direct target contact.",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
}
```
### 20. Aquatone
```json
{
"description": "Go-based tool for domain reconnaissance that automates subdomain discovery, HTTP service scanning, screenshot capture, and visual HTML report generation for attack surface analysis.",
"status": "live",
"pricing": "free",
"bestFor": "Visual subdomain reconnaissance, HTTP service discovery, attack surface mapping",
"input": "Domain name",
"output": "Discovered subdomains, open ports, HTTP screenshots, consolidated reconnaissance report",
"opsec": "active",
"opsecNote": "Makes HTTP requests to discovered hosts to capture screenshots and fingerprint services; supports integration with passive enumeration tools.",
"localInstall": true,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
}
```
### 21. FindSubDomains
```json
{
"description": "Free web-based automated subdomain discovery tool with filtering and analysis capabilities, showing organization names, relationships, and top subdomain statistics.",
"status": "live",
"pricing": "free",
"bestFor": "Automated subdomain enumeration, organization name filtering, subdomain statistics",
"input": "Domain name or keyword",
"output": "Discovered subdomains, organization associations, popularity metrics, filtering options",
"opsec": "passive",
"opsecNote": "Uses passive DNS and search-based methods for subdomain discovery; no active probing.",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
}
```
### 22. Google Subdomains
```json
{
"description": "Google Dork technique using the 'site:' operator to enumerate subdomains of a target domain via Google's search index.",
"status": "live",
"pricing": "free",
"bestFor": "Indexed subdomain discovery, publicly visible subdomain enumeration",
"input": "Domain name (as Google Dork syntax: site:domain.com)",
"output": "Indexed subdomains and pages from Google search results",
"opsec": "passive",
"opsecNote": "Uses Google's search index; no direct contact with the target domain.",
"localInstall": false,
"googleDork": true,
"registration": false,
"editUrl": true,
"api": false,
"invitationOnly": false,
"deprecated": false
}
```
### 23. Recon-ng
```json
{
"description": "Full-featured web reconnaissance framework with independent modules for data gathering, API integration, and customizable workflows.",
"status": "live",
"pricing": "free",
"bestFor": "Modular web recon, API-driven data collection, credential gathering",
"input": "Domain, company name, email, IP",
"output": "Contacts, hosts, credentials, ports via module-specific results",
"opsec": "passive",
"opsecNote": "Queries third-party APIs and data sources. Does not probe the target unless specific modules are configured to do so.",
"localInstall": true,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": true,
"invitationOnly": false,
"deprecated": false
}
```
### 24. XRay
```json
{
"description": "Go-based network reconnaissance tool that automates subdomain enumeration via DNS brute force, integrates Shodan for port discovery, and gathers banner information with web UI visualization.",
"status": "live",
"pricing": "free",
"bestFor": "Automated subdomain discovery with banner grabbing, open port enumeration, Shodan integration",
"input": "Domain name, subdomain wordlist, Shodan API key (optional), ViewDNS API key (optional)",
"output": "Enumerated subdomains, open ports, banner information, historical data, web-based results UI",
"opsec": "active",
"opsecNote": "Performs DNS brute force for subdomain enumeration and makes banner grabbing connections to discovered services.",
"localInstall": true,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
}
```
### 25. DNS Recon
```json
{
"description": "Python-based DNS enumeration script supporting zone transfers, standard record enumeration, TLD expansion, DNS brute force, and PTR lookups.",
"status": "live",
"pricing": "free",
"bestFor": "DNS enumeration, zone transfer testing, subdomain brute forcing, DNS security assessment",
"input": "Domain name, IP range/CIDR, subdomain wordlist, DNS server address",
"output": "NS/SOA/MX/A records, discovered subdomains, zone transfer results, PTR records, wildcard resolution status",
"opsec": "active",
"opsecNote": "Performs active DNS queries and brute force attempts; does not probe target services directly but makes repeated DNS requests.",
"localInstall": true,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
}
```
---
## Summary
**Tools researched**: 25
**Category**: Domain Name (Whois Records: 18, Subdomains: 7)
**Pricing breakdown**:
- Free: 15 tools
- Freemium: 4 tools
- Paid: 6 tools
**OPSEC profile**:
- Passive: 19 tools
- Active: 6 tools
**Local installation required**: 5 tools (Aquatone, Recon-ng, XRay, DNS Recon, and tools marked with (T))
All tools verified as live and accessible as of 2026-03-27.
+412
View File
@@ -0,0 +1,412 @@
{
"enrichments": {
"Threatexpert.com Malicious URLs": {
"description": "Malicious URL blacklist feed from abuse.ch's URL repository tracking malware distribution vectors.",
"status": "down",
"pricing": "free",
"bestFor": "Malware URL intelligence",
"input": "Domain or URL",
"output": "Blocklist/Feed format",
"opsec": "passive",
"opsecNote": "Retrieves historical blocklist data from abuse.ch infrastructure",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": true
},
"Zeus C2 Tracker": {
"description": "abuse.ch project tracking Zeus command and control servers with domain and IP blocklists.",
"status": "live",
"pricing": "free",
"bestFor": "Zeus botnet C2 blocking",
"input": "None (blocklist provider)",
"output": "Domain/IP blocklist, Snort rules, Squid format",
"opsec": "passive",
"opsecNote": "Queries public Zeus tracker database; no active scanning",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
"Malware Domains Blacklist": {
"description": "Historical malware domains blocklist providing hosts file format malicious domain list.",
"status": "down",
"pricing": "free",
"bestFor": "Malware domain blocking (legacy)",
"input": "None (blocklist provider)",
"output": "Hosts file format",
"opsec": "passive",
"opsecNote": "Legacy service; no longer maintained",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": true
},
"Email Domain Validation": {
"description": "Free email domain validation tool checking DNS records, MX records, and mail server connectivity.",
"status": "live",
"pricing": "freemium",
"bestFor": "Email domain and mailbox verification",
"input": "Email domain or address",
"output": "Domain validation report, MX records",
"opsec": "active",
"opsecNote": "Active mail server connectivity checks required for validation",
"localInstall": false,
"googleDork": false,
"registration": true,
"editUrl": false,
"api": true,
"invitationOnly": false,
"deprecated": false
},
"Blackweb": {
"description": "Open-source project consolidating public malware domain blacklists optimized for Squid-Cache compatibility.",
"status": "live",
"pricing": "free",
"bestFor": "Squid proxy malware filtering",
"input": "None (aggregated blocklist)",
"output": "Squid-compatible blocklist format",
"opsec": "passive",
"opsecNote": "Aggregates existing public blacklist sources; requires DNS verification",
"localInstall": true,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
"Critical Stack Intel (R)": {
"description": "Free threat intelligence feeds integrated with Bro/Zeek network security monitoring systems.",
"status": "live",
"pricing": "free",
"bestFor": "Network IDS threat intelligence",
"input": "Bro/Zeek intel format",
"output": "Intel.log entries, network alerts",
"opsec": "passive",
"opsecNote": "Requires registration; polled hourly from curated threat intelligence feeds",
"localInstall": true,
"googleDork": false,
"registration": true,
"editUrl": false,
"api": true,
"invitationOnly": false,
"deprecated": false
},
"DNS Sinkhole": {
"description": "Malware domain sinkhole from malc0de.com providing DNS-based threat blocking zones.",
"status": "degraded",
"pricing": "free",
"bestFor": "DNS-based malware blocking",
"input": "DNS zone file",
"output": "Malware domain sinkhole list",
"opsec": "passive",
"opsecNote": "Public malware database; Cloudflare CAPTCHA protection added",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
"DNS-BH Malware Domain Blocklist": {
"description": "Legacy malware domain blocklist from RiskAnalytics using Black Hole DNS sinkhole technology.",
"status": "down",
"pricing": "free",
"bestFor": "Malware domain blocking (legacy)",
"input": "None (blocklist provider)",
"output": "Multiple formats (BIND, BOOT, ISA, MaraDNS)",
"opsec": "passive",
"opsecNote": "Service sunset; merged into ShadowNet",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": true
},
"Malware Domain List": {
"description": "Interactive malware domain reputation lookup providing verified malicious domain intelligence.",
"status": "live",
"pricing": "free",
"bestFor": "Malware domain reputation queries",
"input": "Domain name",
"output": "Domain reputation report",
"opsec": "passive",
"opsecNote": "Queries curated malware domain database; passive lookup only",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
"MalwareURL (R)": {
"description": "Commercial malware URL reputation checker and blocklist service protecting networks from known malicious websites.",
"status": "live",
"pricing": "freemium",
"bestFor": "Malware URL reputation checking",
"input": "URL",
"output": "Reputation report, blocklist data",
"opsec": "passive",
"opsecNote": "Free lookup service available; commercial network integration available",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
"scumware.org": {
"description": "Free malware and spyware tracking domain blacklist maintained by security community for 18+ years.",
"status": "live",
"pricing": "free",
"bestFor": "Malware and spyware domain research",
"input": "Domain or URL",
"output": "Domain reputation/blocklist data",
"opsec": "passive",
"opsecNote": "Community-maintained research database; passive lookup only",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
"ZeuS Tracker": {
"description": "abuse.ch project providing comprehensive tracking of Zeus botnet C2 infrastructure with domain and IP blocklists.",
"status": "live",
"pricing": "free",
"bestFor": "Zeus botnet tracking and blocking",
"input": "None (blocklist provider)",
"output": "Domain blocklist, IP blocklist, Snort rules, Squid format",
"opsec": "passive",
"opsecNote": "Public tracker; passive monitoring of Zeus C2 activity",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
"Shadowserver Foundation": {
"description": "Nonprofit providing comprehensive IP reputation intelligence and automated abuse reporting through daily network scanning.",
"status": "live",
"pricing": "free",
"bestFor": "IP/domain reputation and abuse intelligence",
"input": "IP address or domain",
"output": "Reputation reports, blocklists, abuse intelligence",
"opsec": "passive",
"opsecNote": "Passive intelligence from honeypots and network sensors; no active scanning",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": true,
"invitationOnly": false,
"deprecated": false
},
"vURL Online": {
"description": "URL and domain dissection tool providing detailed reputation analysis and security assessment.",
"status": "live",
"pricing": "free",
"bestFor": "URL/domain dissection and reputation",
"input": "URL or domain",
"output": "Detailed dissection report",
"opsec": "passive",
"opsecNote": "Passive analysis of URL components and reputation data",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
"AlienVault Open Threat Exchange": {
"description": "Community-driven threat intelligence platform enabling collaborative defense with 180K+ participants sharing 19M+ threats daily.",
"status": "live",
"pricing": "free",
"bestFor": "Community threat intelligence sharing",
"input": "Domain, IP, URL, file hash",
"output": "Threat pulses, reputation data, indicators",
"opsec": "passive",
"opsecNote": "Community-sourced intelligence; free API access with registration",
"localInstall": false,
"googleDork": false,
"registration": true,
"editUrl": false,
"api": true,
"invitationOnly": false,
"deprecated": false
},
"Web Inspector Online Scan": {
"description": "Free cloud-based website malware scanner with daily automated scanning and blacklist checking capabilities.",
"status": "live",
"pricing": "free",
"bestFor": "Website malware scanning",
"input": "Website URL",
"output": "Malware scan report, vulnerability assessment",
"opsec": "active",
"opsecNote": "Active scanning required; connects to target website to analyze content",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
"Google Safe Browsing API": {
"description": "Google's free API detecting malicious URLs and phishing sites with protection across billions of devices.",
"status": "live",
"pricing": "free",
"bestFor": "Malware and phishing URL detection",
"input": "URL or domain",
"output": "Safe/unsafe classification, threat type",
"opsec": "passive",
"opsecNote": "Free for non-commercial use; commercial use requires Web Risk API (paid)",
"localInstall": false,
"googleDork": false,
"registration": true,
"editUrl": false,
"api": true,
"invitationOnly": false,
"deprecated": false
},
"Cisco Talos": {
"description": "Cisco's comprehensive IP and domain reputation intelligence system with real-time threat detection spanning millions of sensors.",
"status": "live",
"pricing": "free",
"bestFor": "IP/domain reputation intelligence",
"input": "IP address or domain",
"output": "Reputation score, threat indicators, intelligence reports",
"opsec": "passive",
"opsecNote": "Passive intelligence from Cisco's extensive network of sensors and endpoints",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
"DNS Twist (T)": {
"description": "Domain name permutation engine for detecting homograph phishing attacks and typosquatting with fuzzy hashing.",
"status": "live",
"pricing": "free",
"bestFor": "Typosquatting and phishing domain detection",
"input": "Domain name",
"output": "Domain permutation list, DNS records, HTTP similarity",
"opsec": "active",
"opsecNote": "Active DNS queries required; queries can be resource-intensive (300K+ queries for google.com)",
"localInstall": true,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
"URLCrazy (T)": {
"description": "Ruby-based typosquatting domain generator supporting 15 variation types and 8000+ common misspellings.",
"status": "live",
"pricing": "free",
"bestFor": "Typosquatting domain discovery",
"input": "Domain name",
"output": "Domain variant list, registration status",
"opsec": "active",
"opsecNote": "Generates 2000+ variants requiring DNS queries for availability checking",
"localInstall": true,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
"dnstwister": {
"description": "Web-based domain permutation tool with free lookup and paid monitoring plans for typosquatting detection.",
"status": "live",
"pricing": "freemium",
"bestFor": "Typosquatting monitoring",
"input": "Domain name",
"output": "Domain variants, registration status, DNS records",
"opsec": "active",
"opsecNote": "Active DNS queries required for variant checking; paid plans enable continuous monitoring",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
"Catphish (T)": {
"description": "Red team tool for generating phishing domains using homoglyphs, punycode, and domain manipulation techniques.",
"status": "live",
"pricing": "free",
"bestFor": "Red team phishing domain generation",
"input": "Target domain",
"output": "Phishing domain variants, categorization status",
"opsec": "active",
"opsecNote": "Generates domains for red team operations; checks domain categorization to evade proxies",
"localInstall": true,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
"BuiltWith": {
"description": "Web technology profiler identifying CMS platforms, frameworks, analytics, and 2500+ technologies used by websites.",
"status": "live",
"pricing": "freemium",
"bestFor": "Web technology intelligence and competitive analysis",
"input": "Website URL or domain",
"output": "Technology stack report, lead generation data",
"opsec": "passive",
"opsecNote": "Public website analysis; passive technical reconnaissance",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": true,
"invitationOnly": false,
"deprecated": false
},
"SiteSleuth": {
"description": "OSINT domain analytics tool tracking Google Analytics, AdSense, and Stripe keys across 32+ million websites.",
"status": "live",
"pricing": "free",
"bestFor": "Tracking code intelligence and related domain discovery",
"input": "Domain, Google Analytics ID, AdSense ID, or Stripe key",
"output": "List of associated domains and tracking codes",
"opsec": "passive",
"opsecNote": "Passive intelligence from indexed tracking identifiers; no direct queries to targets",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
}
}
}
+41
View File
@@ -0,0 +1,41 @@
#!/usr/bin/env python3
import json
import sys
def merge_enrichment_into_node(node, enrichments):
"""Recursively search and merge enrichment data into matching nodes."""
if isinstance(node, dict):
if "name" in node and node["name"] in enrichments:
# Found a matching tool, merge enrichment data
enrichment = enrichments[node["name"]]
for key, value in enrichment.items():
node[key] = value
# Recursively process children
if "children" in node and isinstance(node["children"], list):
for child in node["children"]:
merge_enrichment_into_node(child, enrichments)
def main():
# Load enrichment data
with open("enrichment-batch4-domains.json", "r") as f:
enrichment_data = json.load(f)
enrichments = enrichment_data["enrichments"]
# Load arf.json
with open("public/arf.json", "r") as f:
arf_data = json.load(f)
# Merge enrichment data into arf.json
merge_enrichment_into_node(arf_data, enrichments)
# Write the updated arf.json
with open("public/arf.json", "w") as f:
json.dump(arf_data, f, indent=2)
print(f"Successfully merged enrichment data for {len(enrichments)} tools")
print("Updated public/arf.json")
if __name__ == "__main__":
main()
+400 -40
View File
@@ -1230,17 +1230,17 @@
"name": "BuiltWith",
"type": "url",
"url": "https://builtwith.com/",
"description": "Technology profiler that identifies the tech stack, analytics, and frameworks used by websites.",
"description": "Web technology profiler identifying CMS platforms, frameworks, analytics, and 2500+ technologies used by websites.",
"status": "live",
"pricing": "freemium",
"bestFor": "Technology stack identification, competitor analysis",
"input": "Domain or URL",
"output": "Technology list, analytics IDs, hosting info, historical tech changes",
"bestFor": "Web technology intelligence and competitive analysis",
"input": "Website URL or domain",
"output": "Technology stack report, lead generation data",
"opsec": "passive",
"opsecNote": "Queries cached technology profiles. Does not contact the target.",
"opsecNote": "Public website analysis; passive technical reconnaissance",
"localInstall": false,
"googleDork": false,
"registration": true,
"registration": false,
"editUrl": false,
"api": true,
"invitationOnly": false,
@@ -1772,32 +1772,122 @@
{
"name": "vURL Online",
"type": "url",
"url": "https://vurldissect.co.uk/"
"url": "https://vurldissect.co.uk/",
"description": "URL and domain dissection tool providing detailed reputation analysis and security assessment.",
"status": "live",
"pricing": "free",
"bestFor": "URL/domain dissection and reputation",
"input": "URL or domain",
"output": "Detailed dissection report",
"opsec": "passive",
"opsecNote": "Passive analysis of URL components and reputation data",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
{
"name": "AlienVault Open Threat Exchange",
"type": "url",
"url": "https://otx.alienvault.com/browse/pulses/"
"url": "https://otx.alienvault.com/browse/pulses/",
"description": "Community-driven threat intelligence platform enabling collaborative defense with 180K+ participants sharing 19M+ threats daily.",
"status": "live",
"pricing": "free",
"bestFor": "Community threat intelligence sharing",
"input": "Domain, IP, URL, file hash",
"output": "Threat pulses, reputation data, indicators",
"opsec": "passive",
"opsecNote": "Community-sourced intelligence; free API access with registration",
"localInstall": false,
"googleDork": false,
"registration": true,
"editUrl": false,
"api": true,
"invitationOnly": false,
"deprecated": false
},
{
"name": "Malware Domain List",
"type": "url",
"url": "https://www.malwaredomainlist.com/mdl.php"
"url": "https://www.malwaredomainlist.com/mdl.php",
"description": "Interactive malware domain reputation lookup providing verified malicious domain intelligence.",
"status": "live",
"pricing": "free",
"bestFor": "Malware domain reputation queries",
"input": "Domain name",
"output": "Domain reputation report",
"opsec": "passive",
"opsecNote": "Queries curated malware domain database; passive lookup only",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
{
"name": "Web Inspector Online Scan",
"type": "url",
"url": "https://www.webinspector.com/website-malware-scanner/"
"url": "https://www.webinspector.com/website-malware-scanner/",
"description": "Free cloud-based website malware scanner with daily automated scanning and blacklist checking capabilities.",
"status": "live",
"pricing": "free",
"bestFor": "Website malware scanning",
"input": "Website URL",
"output": "Malware scan report, vulnerability assessment",
"opsec": "active",
"opsecNote": "Active scanning required; connects to target website to analyze content",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
{
"name": "Google Safe Browsing API",
"type": "url",
"url": "https://developers.google.com/safe-browsing/?csw=1"
"url": "https://developers.google.com/safe-browsing/?csw=1",
"description": "Google's free API detecting malicious URLs and phishing sites with protection across billions of devices.",
"status": "live",
"pricing": "free",
"bestFor": "Malware and phishing URL detection",
"input": "URL or domain",
"output": "Safe/unsafe classification, threat type",
"opsec": "passive",
"opsecNote": "Free for non-commercial use; commercial use requires Web Risk API (paid)",
"localInstall": false,
"googleDork": false,
"registration": true,
"editUrl": false,
"api": true,
"invitationOnly": false,
"deprecated": false
},
{
"name": "Cisco Talos",
"type": "url",
"url": "https://talosintelligence.com/"
"url": "https://talosintelligence.com/",
"description": "Cisco's comprehensive IP and domain reputation intelligence system with real-time threat detection spanning millions of sensors.",
"status": "live",
"pricing": "free",
"bestFor": "IP/domain reputation intelligence",
"input": "IP address or domain",
"output": "Reputation score, threat indicators, intelligence reports",
"opsec": "passive",
"opsecNote": "Passive intelligence from Cisco's extensive network of sensors and endpoints",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
}
]
},
@@ -1808,67 +1898,262 @@
{
"name": "Threatexpert.com Malicious URLs",
"type": "url",
"url": "https://www.networksec.org/grabbho/block.txt"
"url": "https://www.networksec.org/grabbho/block.txt",
"description": "Malicious URL blacklist feed from abuse.ch's URL repository tracking malware distribution vectors.",
"status": "down",
"pricing": "free",
"bestFor": "Malware URL intelligence",
"input": "Domain or URL",
"output": "Blocklist/Feed format",
"opsec": "passive",
"opsecNote": "Retrieves historical blocklist data from abuse.ch infrastructure",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": true
},
{
"name": "Zeus C2 Tracker",
"type": "url",
"url": "https://zeustracker.abuse.ch/blocklist.php?download=domainblocklist"
"url": "https://zeustracker.abuse.ch/blocklist.php?download=domainblocklist",
"description": "abuse.ch project tracking Zeus command and control servers with domain and IP blocklists.",
"status": "live",
"pricing": "free",
"bestFor": "Zeus botnet C2 blocking",
"input": "None (blocklist provider)",
"output": "Domain/IP blocklist, Snort rules, Squid format",
"opsec": "passive",
"opsecNote": "Queries public Zeus tracker database; no active scanning",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
{
"name": "Malware Domains Blacklist",
"type": "url",
"url": "https://mirror1.malwaredomains.com/files/domains.txt"
"url": "https://mirror1.malwaredomains.com/files/domains.txt",
"description": "Historical malware domains blocklist providing hosts file format malicious domain list.",
"status": "down",
"pricing": "free",
"bestFor": "Malware domain blocking (legacy)",
"input": "None (blocklist provider)",
"output": "Hosts file format",
"opsec": "passive",
"opsecNote": "Legacy service; no longer maintained",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": true
},
{
"name": "Blackweb",
"type": "url",
"url": "https://github.com/maravento/blackweb"
"url": "https://github.com/maravento/blackweb",
"description": "Open-source project consolidating public malware domain blacklists optimized for Squid-Cache compatibility.",
"status": "live",
"pricing": "free",
"bestFor": "Squid proxy malware filtering",
"input": "None (aggregated blocklist)",
"output": "Squid-compatible blocklist format",
"opsec": "passive",
"opsecNote": "Aggregates existing public blacklist sources; requires DNS verification",
"localInstall": true,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
{
"name": "Critical Stack Intel (R)",
"type": "url",
"url": "https://intel.criticalstack.com/"
"url": "https://intel.criticalstack.com/",
"description": "Free threat intelligence feeds integrated with Bro/Zeek network security monitoring systems.",
"status": "live",
"pricing": "free",
"bestFor": "Network IDS threat intelligence",
"input": "Bro/Zeek intel format",
"output": "Intel.log entries, network alerts",
"opsec": "passive",
"opsecNote": "Requires registration; polled hourly from curated threat intelligence feeds",
"localInstall": true,
"googleDork": false,
"registration": true,
"editUrl": false,
"api": true,
"invitationOnly": false,
"deprecated": false
},
{
"name": "DNS Sinkhole",
"type": "url",
"url": "https://malc0de.com/bl/"
"url": "https://malc0de.com/bl/",
"description": "Malware domain sinkhole from malc0de.com providing DNS-based threat blocking zones.",
"status": "degraded",
"pricing": "free",
"bestFor": "DNS-based malware blocking",
"input": "DNS zone file",
"output": "Malware domain sinkhole list",
"opsec": "passive",
"opsecNote": "Public malware database; Cloudflare CAPTCHA protection added",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
{
"name": "DNS-BH Malware Domain Blocklist",
"type": "url",
"url": "https://www.malwaredomains.com/wordpress/?page_id=66"
"url": "https://www.malwaredomains.com/wordpress/?page_id=66",
"description": "Legacy malware domain blocklist from RiskAnalytics using Black Hole DNS sinkhole technology.",
"status": "down",
"pricing": "free",
"bestFor": "Malware domain blocking (legacy)",
"input": "None (blocklist provider)",
"output": "Multiple formats (BIND, BOOT, ISA, MaraDNS)",
"opsec": "passive",
"opsecNote": "Service sunset; merged into ShadowNet",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": true
},
{
"name": "Malware Domain List",
"type": "url",
"url": "https://www.malwaredomainlist.com/hostslist/hosts.txt"
"url": "https://www.malwaredomainlist.com/hostslist/hosts.txt",
"description": "Interactive malware domain reputation lookup providing verified malicious domain intelligence.",
"status": "live",
"pricing": "free",
"bestFor": "Malware domain reputation queries",
"input": "Domain name",
"output": "Domain reputation report",
"opsec": "passive",
"opsecNote": "Queries curated malware domain database; passive lookup only",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
{
"name": "MalwareURL (R)",
"type": "url",
"url": "https://www.malwareurl.com/index.php"
"url": "https://www.malwareurl.com/index.php",
"description": "Commercial malware URL reputation checker and blocklist service protecting networks from known malicious websites.",
"status": "live",
"pricing": "freemium",
"bestFor": "Malware URL reputation checking",
"input": "URL",
"output": "Reputation report, blocklist data",
"opsec": "passive",
"opsecNote": "Free lookup service available; commercial network integration available",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
{
"name": "scumware.org",
"type": "url",
"url": "https://www.scumware.org/"
"url": "https://www.scumware.org/",
"description": "Free malware and spyware tracking domain blacklist maintained by security community for 18+ years.",
"status": "live",
"pricing": "free",
"bestFor": "Malware and spyware domain research",
"input": "Domain or URL",
"output": "Domain reputation/blocklist data",
"opsec": "passive",
"opsecNote": "Community-maintained research database; passive lookup only",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
{
"name": "ZeuS Tracker",
"type": "url",
"url": "https://zeustracker.abuse.ch/blocklist.php"
"url": "https://zeustracker.abuse.ch/blocklist.php",
"description": "abuse.ch project providing comprehensive tracking of Zeus botnet C2 infrastructure with domain and IP blocklists.",
"status": "live",
"pricing": "free",
"bestFor": "Zeus botnet tracking and blocking",
"input": "None (blocklist provider)",
"output": "Domain blocklist, IP blocklist, Snort rules, Squid format",
"opsec": "passive",
"opsecNote": "Public tracker; passive monitoring of Zeus C2 activity",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
{
"name": "Shadowserver Foundation",
"type": "url",
"url": "https://www.shadowserver.org/"
"url": "https://www.shadowserver.org/",
"description": "Nonprofit providing comprehensive IP reputation intelligence and automated abuse reporting through daily network scanning.",
"status": "live",
"pricing": "free",
"bestFor": "IP/domain reputation and abuse intelligence",
"input": "IP address or domain",
"output": "Reputation reports, blocklists, abuse intelligence",
"opsec": "passive",
"opsecNote": "Passive intelligence from honeypots and network sensors; no active scanning",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": true,
"invitationOnly": false,
"deprecated": false
},
{
"name": "Email Domain Validation",
"type": "url",
"url": "https://www.mailboxvalidator.com/domain"
"url": "https://www.mailboxvalidator.com/domain",
"description": "Free email domain validation tool checking DNS records, MX records, and mail server connectivity.",
"status": "live",
"pricing": "freemium",
"bestFor": "Email domain and mailbox verification",
"input": "Email domain or address",
"output": "Domain validation report, MX records",
"opsec": "active",
"opsecNote": "Active mail server connectivity checks required for validation",
"localInstall": false,
"googleDork": false,
"registration": true,
"editUrl": false,
"api": true,
"invitationOnly": false,
"deprecated": false
}
]
},
@@ -1879,22 +2164,82 @@
{
"name": "DNS Twist (T)",
"type": "url",
"url": "https://github.com/elceef/dnstwist"
"url": "https://github.com/elceef/dnstwist",
"description": "Domain name permutation engine for detecting homograph phishing attacks and typosquatting with fuzzy hashing.",
"status": "live",
"pricing": "free",
"bestFor": "Typosquatting and phishing domain detection",
"input": "Domain name",
"output": "Domain permutation list, DNS records, HTTP similarity",
"opsec": "active",
"opsecNote": "Active DNS queries required; queries can be resource-intensive (300K+ queries for google.com)",
"localInstall": true,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
{
"name": "URLCrazy (T)",
"type": "url",
"url": "https://www.morningstarsecurity.com/research/urlcrazy"
"url": "https://www.morningstarsecurity.com/research/urlcrazy",
"description": "Ruby-based typosquatting domain generator supporting 15 variation types and 8000+ common misspellings.",
"status": "live",
"pricing": "free",
"bestFor": "Typosquatting domain discovery",
"input": "Domain name",
"output": "Domain variant list, registration status",
"opsec": "active",
"opsecNote": "Generates 2000+ variants requiring DNS queries for availability checking",
"localInstall": true,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
{
"name": "dnstwister",
"type": "url",
"url": "https://dnstwister.report/"
"url": "https://dnstwister.report/",
"description": "Web-based domain permutation tool with free lookup and paid monitoring plans for typosquatting detection.",
"status": "live",
"pricing": "freemium",
"bestFor": "Typosquatting monitoring",
"input": "Domain name",
"output": "Domain variants, registration status, DNS records",
"opsec": "active",
"opsecNote": "Active DNS queries required for variant checking; paid plans enable continuous monitoring",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
{
"name": "Catphish (T)",
"type": "url",
"url": "https://github.com/ring0lab/catphish"
"url": "https://github.com/ring0lab/catphish",
"description": "Red team tool for generating phishing domains using homoglyphs, punycode, and domain manipulation techniques.",
"status": "live",
"pricing": "free",
"bestFor": "Red team phishing domain generation",
"input": "Target domain",
"output": "Phishing domain variants, categorization status",
"opsec": "active",
"opsecNote": "Generates domains for red team operations; checks domain categorization to evade proxies",
"localInstall": true,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
}
]
},
@@ -1906,17 +2251,17 @@
"name": "BuiltWith",
"type": "url",
"url": "https://builtwith.com/",
"description": "Technology profiler that identifies the tech stack, analytics, and frameworks used by websites.",
"description": "Web technology profiler identifying CMS platforms, frameworks, analytics, and 2500+ technologies used by websites.",
"status": "live",
"pricing": "freemium",
"bestFor": "Technology stack identification, competitor analysis",
"input": "Domain or URL",
"output": "Technology list, analytics IDs, hosting info, historical tech changes",
"bestFor": "Web technology intelligence and competitive analysis",
"input": "Website URL or domain",
"output": "Technology stack report, lead generation data",
"opsec": "passive",
"opsecNote": "Queries cached technology profiles. Does not contact the target.",
"opsecNote": "Public website analysis; passive technical reconnaissance",
"localInstall": false,
"googleDork": false,
"registration": true,
"registration": false,
"editUrl": false,
"api": true,
"invitationOnly": false,
@@ -1925,7 +2270,22 @@
{
"name": "SiteSleuth",
"type": "url",
"url": "https://www.sitesleuth.io/"
"url": "https://www.sitesleuth.io/",
"description": "OSINT domain analytics tool tracking Google Analytics, AdSense, and Stripe keys across 32+ million websites.",
"status": "live",
"pricing": "free",
"bestFor": "Tracking code intelligence and related domain discovery",
"input": "Domain, Google Analytics ID, AdSense ID, or Stripe key",
"output": "List of associated domains and tracking codes",
"opsec": "passive",
"opsecNote": "Passive intelligence from indexed tracking identifiers; no direct queries to targets",
"localInstall": false,
"googleDork": false,
"registration": false,
"editUrl": false,
"api": false,
"invitationOnly": false,
"deprecated": false
},
{
"name": "Wappalyzer (T)",
@@ -4823,12 +5183,12 @@
"url": "https://www.brbpub.com/"
},
{
"name": "GOVDATA - Das Datenportal für Deutschland (German)",
"name": "GOVDATA - Das Datenportal f\u00fcr Deutschland (German)",
"type": "url",
"url": "https://www.govdata.de/"
},
{
"name": "Open-Data-Portal München (German)",
"name": "Open-Data-Portal M\u00fcnchen (German)",
"type": "url",
"url": "https://www.opengov-muenchen.de/"
},
@@ -8453,7 +8813,7 @@
"url": "https://themanyhats.club/centralised-place-for-privacy-resources/"
},
{
"name": "The Hitchhikers Guide to Online Anonymity",
"name": "The Hitchhiker\u2019s Guide to Online Anonymity",
"type": "url",
"url": "https://anonymousplanet.org/guide/"
},
@@ -8629,4 +8989,4 @@
]
}
]
}
}