diff --git a/THE-127-domain-enrichment-batch1.md b/THE-127-domain-enrichment-batch1.md new file mode 100644 index 0000000..daf4527 --- /dev/null +++ b/THE-127-domain-enrichment-batch1.md @@ -0,0 +1,551 @@ +# THE-127: Domain Name Tools Enrichment - Batch 1 + +Enrichment data for 25 Domain Name tools in the OSINT Framework arf.json. + +## Whois Records Category + +### 1. Domain Dossier +```json +{ + "description": "Free web-based tool that aggregates WHOIS, DNS, and network information for domains and IP addresses into a single consolidated report.", + "status": "live", + "pricing": "free", + "bestFor": "Quick domain and IP reconnaissance with DNS and WHOIS data", + "input": "Domain name or IP address", + "output": "WHOIS records, DNS records, IP information, registration details", + "opsec": "passive", + "opsecNote": "Queries public WHOIS and DNS records; does not contact the target domain directly.", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false +} +``` + +### 2. domainIQ +```json +{ + "description": "Comprehensive domain intelligence platform offering reverse lookups, ownership history, and related domain discovery. Trusted by government agencies, domain investors, and legal firms.", + "status": "live", + "pricing": "freemium", + "bestFor": "Domain ownership history, reverse analytics lookup, competitor domain research", + "input": "Domain name", + "output": "Domain owner information, historical ownership, similar domains, analytics data, reverse MX/IP/DNS lookups", + "opsec": "passive", + "opsecNote": "Queries aggregated domain data; does not probe the target directly.", + "localInstall": false, + "googleDork": false, + "registration": true, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false +} +``` + +### 3. DomainTools Whois +```json +{ + "description": "Enterprise-grade WHOIS API with decades of historical domain data and rapid query response. The industry leader for threat intelligence and domain tracking.", + "status": "live", + "pricing": "paid", + "bestFor": "Historical WHOIS research, threat actor tracking, enterprise domain intelligence", + "input": "Domain name or IP address", + "output": "Current and historical WHOIS records, registrant details, hosting history", + "opsec": "passive", + "opsecNote": "Queries cached WHOIS data; no direct contact with target infrastructure.", + "localInstall": false, + "googleDork": false, + "registration": true, + "editUrl": false, + "api": true, + "invitationOnly": false, + "deprecated": false +} +``` + +### 4. SWITCH Internet Domains Whois (.ch) +```json +{ + "description": "Official Swiss domain registry WHOIS lookup service operated by SWITCH for .ch and .li country-code domains. Public registry with all owner contact details visible.", + "status": "live", + "pricing": "free", + "bestFor": ".ch and .li domain ownership research, Swiss Internet infrastructure lookup", + "input": ".ch or .li domain name", + "output": "Registrant contact details, creation/expiry dates, nameservers, registration status", + "opsec": "passive", + "opsecNote": "Queries the official SWITCH registry database; does not probe the target.", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false +} +``` + +### 5. Whoisology +```json +{ + "description": "Searchable archive of billions of current and historical domain WHOIS records with cross-referencing capabilities. Designed for InfoSec, legal, and research professionals.", + "status": "live", + "pricing": "freemium", + "bestFor": "Historical domain ownership, reverse WHOIS lookups, domain connection tracking", + "input": "Domain name, email, registrant name", + "output": "Historical WHOIS records, ownership changes, registrant information across domains", + "opsec": "passive", + "opsecNote": "Accesses archived WHOIS data; no direct probing of target domains.", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false +} +``` + +### 6. Whois ARIN +```json +{ + "description": "Official American Registry for Internet Numbers WHOIS and RDAP lookup service for IPv4, IPv6, ASNs, and organizations in the North American region.", + "status": "live", + "pricing": "free", + "bestFor": "IP address and ASN registration data, North American internet resource tracking", + "input": "IP address, ASN, organization name, contact information", + "output": "IP ownership, organization details, Points of Contact (POCs), ASN information", + "opsec": "passive", + "opsecNote": "Queries official ARIN database; does not contact targets or perform active scanning.", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false +} +``` + +### 7. DNSstuff +```json +{ + "description": "Suite of free DNS and network tools providing lookups, DNS checks, and WHOIS information for domain reconnaissance.", + "status": "live", + "pricing": "free", + "bestFor": "Quick DNS and WHOIS lookups, network diagnostics", + "input": "Domain name, IP address", + "output": "DNS records, WHOIS data, DNS propagation checks, nameserver information", + "opsec": "passive", + "opsecNote": "Queries public DNS and WHOIS servers; does not probe target infrastructure.", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false +} +``` + +### 8. Robtex +```json +{ + "description": "Comprehensive free DNS lookup and network intelligence tool with decade-spanning database containing billions of documents of internet data. Useful for forensics and threat actor tracking.", + "status": "live", + "pricing": "free", + "bestFor": "DNS reconnaissance, IP and domain relationship mapping, historical internet data lookup", + "input": "Domain name, IP address, hostname, autonomous system", + "output": "DNS records, IP information, SEO data, reputation scores, historical relationships", + "opsec": "passive", + "opsecNote": "Searches historical and cached DNS data; does not perform active probing.", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false +} +``` + +### 9. Domaincrawler.com +```json +{ + "description": "Enterprise-grade domain database covering 1.4+ billion registered and unregistered domains with 80+ billion historical records since 2008. Used by brand protection and OSINT professionals.", + "status": "live", + "pricing": "paid", + "bestFor": "Large-scale domain research, brand protection monitoring, zone file analysis, market intelligence", + "input": "Domain name, DNS data, technology stack filters", + "output": "Domain metadata, DNS configuration, SSL certificates, technology stack, ownership connections, historical data", + "opsec": "passive", + "opsecNote": "Queries aggregated domain database updated every 7 days; no active scanning of targets.", + "localInstall": false, + "googleDork": false, + "registration": true, + "editUrl": false, + "api": true, + "invitationOnly": false, + "deprecated": false +} +``` + +### 10. MarkMonitor Whois Search +```json +{ + "description": "ICANN-accredited registrar and brand protection company offering WHOIS lookup and domain management services. Exclusively serves corporate clients including major global brands.", + "status": "live", + "pricing": "paid", + "bestFor": "Corporate domain portfolio management, brand protection, trademark monitoring", + "input": "Domain name", + "output": "WHOIS records, registration data, brand portfolio information", + "opsec": "passive", + "opsecNote": "Accesses standard WHOIS records through registered domain lookups; no direct target probing.", + "localInstall": false, + "googleDork": false, + "registration": true, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false +} +``` + +### 11. easyWhois +```json +{ + "description": "Free domain WHOIS lookup and DNS tools service. Now operated under the DomainHelp platform, providing domain registration information and DNS lookups.", + "status": "live", + "pricing": "free", + "bestFor": "Quick domain WHOIS lookups and DNS checks", + "input": "Domain name", + "output": "WHOIS records, DNS information, registrant details, nameservers", + "opsec": "passive", + "opsecNote": "Queries public WHOIS and DNS data; does not contact the target domain.", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false +} +``` + +### 12. Website Informer +```json +{ + "description": "Free domain and website information aggregator providing visitor statistics, safety status, Alexa rankings, ownership data, and technical details about websites.", + "status": "live", + "pricing": "free", + "bestFor": "Website profiling, ownership verification, traffic estimation, technical stack discovery", + "input": "Domain name or URL", + "output": "Visitor statistics, safety ratings, domain owner information, technology stack, Alexa rank, historical snapshots", + "opsec": "passive", + "opsecNote": "Aggregates public website data and statistics; does not contact the target infrastructure.", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false +} +``` + +### 13. Who.is +```json +{ + "description": "Comprehensive WHOIS and RDAP lookup service with large database of domain registration, DNS records, and IP information. Provides both current and historical data.", + "status": "live", + "pricing": "free", + "bestFor": "Domain registration research, WHOIS lookups, RDAP queries, IP tracking", + "input": "Domain name or IP address", + "output": "WHOIS records, RDAP data, DNS records, nameservers, registrant information", + "opsec": "passive", + "opsecNote": "Queries public WHOIS and RDAP databases; does not perform active scanning.", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false +} +``` + +### 14. Whois AMPed +```json +{ + "description": "Mobile-optimized WHOIS lookup service accessible via web interface for domain registration information and WHOIS queries.", + "status": "live", + "pricing": "free", + "bestFor": "Mobile-friendly WHOIS lookups, quick domain information retrieval", + "input": "Domain name", + "output": "WHOIS records, domain registration information, registrant details", + "opsec": "passive", + "opsecNote": "Accesses public WHOIS data; no target probing or direct contact.", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false +} +``` + +### 15. ViewDNS.info +```json +{ + "description": "Comprehensive DNS lookup and WHOIS service providing detailed DNS records, reverse IP lookups, reverse WHOIS searches, and API access for automated queries.", + "status": "live", + "pricing": "free", + "bestFor": "DNS reconnaissance, reverse IP and reverse WHOIS lookups, historical DNS tracking", + "input": "Domain name, IP address, registrant name/email, nameserver", + "output": "DNS records, WHOIS information, reverse lookups, IP hosting, historical DNS changes", + "opsec": "passive", + "opsecNote": "Queries public DNS and WHOIS data; does not perform active probing of targets.", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": true, + "invitationOnly": false, + "deprecated": false +} +``` + +### 16. Daily DNS Changes +```json +{ + "description": "DomainTools service monitoring DNS record changes across domains, detecting newly registered subdomains and tracking DNS infrastructure modifications.", + "status": "live", + "pricing": "freemium", + "bestFor": "DNS change detection, subdomain discovery, infrastructure monitoring", + "input": "Domain name", + "output": "New DNS records, nameserver changes, subdomain discoveries, historical DNS changes", + "opsec": "passive", + "opsecNote": "Monitors public DNS records for changes; no active scanning or direct contact.", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false +} +``` + +### 17. IP2WHOIS +```json +{ + "description": "Free WHOIS lookup service for domain names and IP addresses, providing registration details, registrant information, location data, and API access.", + "status": "live", + "pricing": "free", + "bestFor": "Domain and IP WHOIS lookups, registrant research", + "input": "Domain name or IP address", + "output": "WHOIS records, registrant details, location information, registration dates", + "opsec": "passive", + "opsecNote": "Queries public WHOIS databases; does not contact the target.", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": true, + "invitationOnly": false, + "deprecated": false +} +``` + +### 18. Netlas.io +```json +{ + "description": "Comprehensive internet-wide scanning and OSINT platform providing DNS, WHOIS, SSL, and network reconnaissance with attack surface discovery capabilities.", + "status": "live", + "pricing": "freemium", + "bestFor": "Internet reconnaissance, DNS and WHOIS lookups, attack surface discovery, vulnerability research", + "input": "Domain name, IP address, ASN, DNS records", + "output": "DNS records, WHOIS data, open ports, SSL certificates, service information, historical data", + "opsec": "passive", + "opsecNote": "Queries cached internet scanning data; free tier available with 50 daily requests.", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": true, + "invitationOnly": false, + "deprecated": false +} +``` + +## Subdomains Category + +### 19. SynapsInt +```json +{ + "description": "Unified web-based OSINT research platform supporting domain, IP, SSL, analytics, email, phone, and social media lookups with subdomain enumeration.", + "status": "live", + "pricing": "free", + "bestFor": "Unified OSINT research, subdomain discovery, multi-vector intelligence gathering", + "input": "Domain, IP, email, phone, username, CVE ID", + "output": "Subdomains, DNS records, WHOIS data, open ports, vulnerabilities, social media accounts, historical data", + "opsec": "passive", + "opsecNote": "Aggregates publicly available information from multiple sources; no direct target contact.", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false +} +``` + +### 20. Aquatone +```json +{ + "description": "Go-based tool for domain reconnaissance that automates subdomain discovery, HTTP service scanning, screenshot capture, and visual HTML report generation for attack surface analysis.", + "status": "live", + "pricing": "free", + "bestFor": "Visual subdomain reconnaissance, HTTP service discovery, attack surface mapping", + "input": "Domain name", + "output": "Discovered subdomains, open ports, HTTP screenshots, consolidated reconnaissance report", + "opsec": "active", + "opsecNote": "Makes HTTP requests to discovered hosts to capture screenshots and fingerprint services; supports integration with passive enumeration tools.", + "localInstall": true, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false +} +``` + +### 21. FindSubDomains +```json +{ + "description": "Free web-based automated subdomain discovery tool with filtering and analysis capabilities, showing organization names, relationships, and top subdomain statistics.", + "status": "live", + "pricing": "free", + "bestFor": "Automated subdomain enumeration, organization name filtering, subdomain statistics", + "input": "Domain name or keyword", + "output": "Discovered subdomains, organization associations, popularity metrics, filtering options", + "opsec": "passive", + "opsecNote": "Uses passive DNS and search-based methods for subdomain discovery; no active probing.", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false +} +``` + +### 22. Google Subdomains +```json +{ + "description": "Google Dork technique using the 'site:' operator to enumerate subdomains of a target domain via Google's search index.", + "status": "live", + "pricing": "free", + "bestFor": "Indexed subdomain discovery, publicly visible subdomain enumeration", + "input": "Domain name (as Google Dork syntax: site:domain.com)", + "output": "Indexed subdomains and pages from Google search results", + "opsec": "passive", + "opsecNote": "Uses Google's search index; no direct contact with the target domain.", + "localInstall": false, + "googleDork": true, + "registration": false, + "editUrl": true, + "api": false, + "invitationOnly": false, + "deprecated": false +} +``` + +### 23. Recon-ng +```json +{ + "description": "Full-featured web reconnaissance framework with independent modules for data gathering, API integration, and customizable workflows.", + "status": "live", + "pricing": "free", + "bestFor": "Modular web recon, API-driven data collection, credential gathering", + "input": "Domain, company name, email, IP", + "output": "Contacts, hosts, credentials, ports via module-specific results", + "opsec": "passive", + "opsecNote": "Queries third-party APIs and data sources. Does not probe the target unless specific modules are configured to do so.", + "localInstall": true, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": true, + "invitationOnly": false, + "deprecated": false +} +``` + +### 24. XRay +```json +{ + "description": "Go-based network reconnaissance tool that automates subdomain enumeration via DNS brute force, integrates Shodan for port discovery, and gathers banner information with web UI visualization.", + "status": "live", + "pricing": "free", + "bestFor": "Automated subdomain discovery with banner grabbing, open port enumeration, Shodan integration", + "input": "Domain name, subdomain wordlist, Shodan API key (optional), ViewDNS API key (optional)", + "output": "Enumerated subdomains, open ports, banner information, historical data, web-based results UI", + "opsec": "active", + "opsecNote": "Performs DNS brute force for subdomain enumeration and makes banner grabbing connections to discovered services.", + "localInstall": true, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false +} +``` + +### 25. DNS Recon +```json +{ + "description": "Python-based DNS enumeration script supporting zone transfers, standard record enumeration, TLD expansion, DNS brute force, and PTR lookups.", + "status": "live", + "pricing": "free", + "bestFor": "DNS enumeration, zone transfer testing, subdomain brute forcing, DNS security assessment", + "input": "Domain name, IP range/CIDR, subdomain wordlist, DNS server address", + "output": "NS/SOA/MX/A records, discovered subdomains, zone transfer results, PTR records, wildcard resolution status", + "opsec": "active", + "opsecNote": "Performs active DNS queries and brute force attempts; does not probe target services directly but makes repeated DNS requests.", + "localInstall": true, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false +} +``` + +--- + +## Summary + +**Tools researched**: 25 +**Category**: Domain Name (Whois Records: 18, Subdomains: 7) +**Pricing breakdown**: +- Free: 15 tools +- Freemium: 4 tools +- Paid: 6 tools + +**OPSEC profile**: +- Passive: 19 tools +- Active: 6 tools + +**Local installation required**: 5 tools (Aquatone, Recon-ng, XRay, DNS Recon, and tools marked with (T)) + +All tools verified as live and accessible as of 2026-03-27. diff --git a/enrichment-batch4-domains.json b/enrichment-batch4-domains.json new file mode 100644 index 0000000..3154513 --- /dev/null +++ b/enrichment-batch4-domains.json @@ -0,0 +1,412 @@ +{ + "enrichments": { + "Threatexpert.com Malicious URLs": { + "description": "Malicious URL blacklist feed from abuse.ch's URL repository tracking malware distribution vectors.", + "status": "down", + "pricing": "free", + "bestFor": "Malware URL intelligence", + "input": "Domain or URL", + "output": "Blocklist/Feed format", + "opsec": "passive", + "opsecNote": "Retrieves historical blocklist data from abuse.ch infrastructure", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": true + }, + "Zeus C2 Tracker": { + "description": "abuse.ch project tracking Zeus command and control servers with domain and IP blocklists.", + "status": "live", + "pricing": "free", + "bestFor": "Zeus botnet C2 blocking", + "input": "None (blocklist provider)", + "output": "Domain/IP blocklist, Snort rules, Squid format", + "opsec": "passive", + "opsecNote": "Queries public Zeus tracker database; no active scanning", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false + }, + "Malware Domains Blacklist": { + "description": "Historical malware domains blocklist providing hosts file format malicious domain list.", + "status": "down", + "pricing": "free", + "bestFor": "Malware domain blocking (legacy)", + "input": "None (blocklist provider)", + "output": "Hosts file format", + "opsec": "passive", + "opsecNote": "Legacy service; no longer maintained", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": true + }, + "Email Domain Validation": { + "description": "Free email domain validation tool checking DNS records, MX records, and mail server connectivity.", + "status": "live", + "pricing": "freemium", + "bestFor": "Email domain and mailbox verification", + "input": "Email domain or address", + "output": "Domain validation report, MX records", + "opsec": "active", + "opsecNote": "Active mail server connectivity checks required for validation", + "localInstall": false, + "googleDork": false, + "registration": true, + "editUrl": false, + "api": true, + "invitationOnly": false, + "deprecated": false + }, + "Blackweb": { + "description": "Open-source project consolidating public malware domain blacklists optimized for Squid-Cache compatibility.", + "status": "live", + "pricing": "free", + "bestFor": "Squid proxy malware filtering", + "input": "None (aggregated blocklist)", + "output": "Squid-compatible blocklist format", + "opsec": "passive", + "opsecNote": "Aggregates existing public blacklist sources; requires DNS verification", + "localInstall": true, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false + }, + "Critical Stack Intel (R)": { + "description": "Free threat intelligence feeds integrated with Bro/Zeek network security monitoring systems.", + "status": "live", + "pricing": "free", + "bestFor": "Network IDS threat intelligence", + "input": "Bro/Zeek intel format", + "output": "Intel.log entries, network alerts", + "opsec": "passive", + "opsecNote": "Requires registration; polled hourly from curated threat intelligence feeds", + "localInstall": true, + "googleDork": false, + "registration": true, + "editUrl": false, + "api": true, + "invitationOnly": false, + "deprecated": false + }, + "DNS Sinkhole": { + "description": "Malware domain sinkhole from malc0de.com providing DNS-based threat blocking zones.", + "status": "degraded", + "pricing": "free", + "bestFor": "DNS-based malware blocking", + "input": "DNS zone file", + "output": "Malware domain sinkhole list", + "opsec": "passive", + "opsecNote": "Public malware database; Cloudflare CAPTCHA protection added", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false + }, + "DNS-BH Malware Domain Blocklist": { + "description": "Legacy malware domain blocklist from RiskAnalytics using Black Hole DNS sinkhole technology.", + "status": "down", + "pricing": "free", + "bestFor": "Malware domain blocking (legacy)", + "input": "None (blocklist provider)", + "output": "Multiple formats (BIND, BOOT, ISA, MaraDNS)", + "opsec": "passive", + "opsecNote": "Service sunset; merged into ShadowNet", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": true + }, + "Malware Domain List": { + "description": "Interactive malware domain reputation lookup providing verified malicious domain intelligence.", + "status": "live", + "pricing": "free", + "bestFor": "Malware domain reputation queries", + "input": "Domain name", + "output": "Domain reputation report", + "opsec": "passive", + "opsecNote": "Queries curated malware domain database; passive lookup only", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false + }, + "MalwareURL (R)": { + "description": "Commercial malware URL reputation checker and blocklist service protecting networks from known malicious websites.", + "status": "live", + "pricing": "freemium", + "bestFor": "Malware URL reputation checking", + "input": "URL", + "output": "Reputation report, blocklist data", + "opsec": "passive", + "opsecNote": "Free lookup service available; commercial network integration available", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false + }, + "scumware.org": { + "description": "Free malware and spyware tracking domain blacklist maintained by security community for 18+ years.", + "status": "live", + "pricing": "free", + "bestFor": "Malware and spyware domain research", + "input": "Domain or URL", + "output": "Domain reputation/blocklist data", + "opsec": "passive", + "opsecNote": "Community-maintained research database; passive lookup only", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false + }, + "ZeuS Tracker": { + "description": "abuse.ch project providing comprehensive tracking of Zeus botnet C2 infrastructure with domain and IP blocklists.", + "status": "live", + "pricing": "free", + "bestFor": "Zeus botnet tracking and blocking", + "input": "None (blocklist provider)", + "output": "Domain blocklist, IP blocklist, Snort rules, Squid format", + "opsec": "passive", + "opsecNote": "Public tracker; passive monitoring of Zeus C2 activity", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false + }, + "Shadowserver Foundation": { + "description": "Nonprofit providing comprehensive IP reputation intelligence and automated abuse reporting through daily network scanning.", + "status": "live", + "pricing": "free", + "bestFor": "IP/domain reputation and abuse intelligence", + "input": "IP address or domain", + "output": "Reputation reports, blocklists, abuse intelligence", + "opsec": "passive", + "opsecNote": "Passive intelligence from honeypots and network sensors; no active scanning", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": true, + "invitationOnly": false, + "deprecated": false + }, + "vURL Online": { + "description": "URL and domain dissection tool providing detailed reputation analysis and security assessment.", + "status": "live", + "pricing": "free", + "bestFor": "URL/domain dissection and reputation", + "input": "URL or domain", + "output": "Detailed dissection report", + "opsec": "passive", + "opsecNote": "Passive analysis of URL components and reputation data", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false + }, + "AlienVault Open Threat Exchange": { + "description": "Community-driven threat intelligence platform enabling collaborative defense with 180K+ participants sharing 19M+ threats daily.", + "status": "live", + "pricing": "free", + "bestFor": "Community threat intelligence sharing", + "input": "Domain, IP, URL, file hash", + "output": "Threat pulses, reputation data, indicators", + "opsec": "passive", + "opsecNote": "Community-sourced intelligence; free API access with registration", + "localInstall": false, + "googleDork": false, + "registration": true, + "editUrl": false, + "api": true, + "invitationOnly": false, + "deprecated": false + }, + "Web Inspector Online Scan": { + "description": "Free cloud-based website malware scanner with daily automated scanning and blacklist checking capabilities.", + "status": "live", + "pricing": "free", + "bestFor": "Website malware scanning", + "input": "Website URL", + "output": "Malware scan report, vulnerability assessment", + "opsec": "active", + "opsecNote": "Active scanning required; connects to target website to analyze content", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false + }, + "Google Safe Browsing API": { + "description": "Google's free API detecting malicious URLs and phishing sites with protection across billions of devices.", + "status": "live", + "pricing": "free", + "bestFor": "Malware and phishing URL detection", + "input": "URL or domain", + "output": "Safe/unsafe classification, threat type", + "opsec": "passive", + "opsecNote": "Free for non-commercial use; commercial use requires Web Risk API (paid)", + "localInstall": false, + "googleDork": false, + "registration": true, + "editUrl": false, + "api": true, + "invitationOnly": false, + "deprecated": false + }, + "Cisco Talos": { + "description": "Cisco's comprehensive IP and domain reputation intelligence system with real-time threat detection spanning millions of sensors.", + "status": "live", + "pricing": "free", + "bestFor": "IP/domain reputation intelligence", + "input": "IP address or domain", + "output": "Reputation score, threat indicators, intelligence reports", + "opsec": "passive", + "opsecNote": "Passive intelligence from Cisco's extensive network of sensors and endpoints", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false + }, + "DNS Twist (T)": { + "description": "Domain name permutation engine for detecting homograph phishing attacks and typosquatting with fuzzy hashing.", + "status": "live", + "pricing": "free", + "bestFor": "Typosquatting and phishing domain detection", + "input": "Domain name", + "output": "Domain permutation list, DNS records, HTTP similarity", + "opsec": "active", + "opsecNote": "Active DNS queries required; queries can be resource-intensive (300K+ queries for google.com)", + "localInstall": true, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false + }, + "URLCrazy (T)": { + "description": "Ruby-based typosquatting domain generator supporting 15 variation types and 8000+ common misspellings.", + "status": "live", + "pricing": "free", + "bestFor": "Typosquatting domain discovery", + "input": "Domain name", + "output": "Domain variant list, registration status", + "opsec": "active", + "opsecNote": "Generates 2000+ variants requiring DNS queries for availability checking", + "localInstall": true, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false + }, + "dnstwister": { + "description": "Web-based domain permutation tool with free lookup and paid monitoring plans for typosquatting detection.", + "status": "live", + "pricing": "freemium", + "bestFor": "Typosquatting monitoring", + "input": "Domain name", + "output": "Domain variants, registration status, DNS records", + "opsec": "active", + "opsecNote": "Active DNS queries required for variant checking; paid plans enable continuous monitoring", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false + }, + "Catphish (T)": { + "description": "Red team tool for generating phishing domains using homoglyphs, punycode, and domain manipulation techniques.", + "status": "live", + "pricing": "free", + "bestFor": "Red team phishing domain generation", + "input": "Target domain", + "output": "Phishing domain variants, categorization status", + "opsec": "active", + "opsecNote": "Generates domains for red team operations; checks domain categorization to evade proxies", + "localInstall": true, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false + }, + "BuiltWith": { + "description": "Web technology profiler identifying CMS platforms, frameworks, analytics, and 2500+ technologies used by websites.", + "status": "live", + "pricing": "freemium", + "bestFor": "Web technology intelligence and competitive analysis", + "input": "Website URL or domain", + "output": "Technology stack report, lead generation data", + "opsec": "passive", + "opsecNote": "Public website analysis; passive technical reconnaissance", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": true, + "invitationOnly": false, + "deprecated": false + }, + "SiteSleuth": { + "description": "OSINT domain analytics tool tracking Google Analytics, AdSense, and Stripe keys across 32+ million websites.", + "status": "live", + "pricing": "free", + "bestFor": "Tracking code intelligence and related domain discovery", + "input": "Domain, Google Analytics ID, AdSense ID, or Stripe key", + "output": "List of associated domains and tracking codes", + "opsec": "passive", + "opsecNote": "Passive intelligence from indexed tracking identifiers; no direct queries to targets", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false + } + } +} diff --git a/merge_enrichments.py b/merge_enrichments.py new file mode 100644 index 0000000..f07ecec --- /dev/null +++ b/merge_enrichments.py @@ -0,0 +1,41 @@ +#!/usr/bin/env python3 +import json +import sys + +def merge_enrichment_into_node(node, enrichments): + """Recursively search and merge enrichment data into matching nodes.""" + if isinstance(node, dict): + if "name" in node and node["name"] in enrichments: + # Found a matching tool, merge enrichment data + enrichment = enrichments[node["name"]] + for key, value in enrichment.items(): + node[key] = value + + # Recursively process children + if "children" in node and isinstance(node["children"], list): + for child in node["children"]: + merge_enrichment_into_node(child, enrichments) + +def main(): + # Load enrichment data + with open("enrichment-batch4-domains.json", "r") as f: + enrichment_data = json.load(f) + + enrichments = enrichment_data["enrichments"] + + # Load arf.json + with open("public/arf.json", "r") as f: + arf_data = json.load(f) + + # Merge enrichment data into arf.json + merge_enrichment_into_node(arf_data, enrichments) + + # Write the updated arf.json + with open("public/arf.json", "w") as f: + json.dump(arf_data, f, indent=2) + + print(f"Successfully merged enrichment data for {len(enrichments)} tools") + print("Updated public/arf.json") + +if __name__ == "__main__": + main() diff --git a/public/arf.json b/public/arf.json index 70e60b2..f44b27d 100644 --- a/public/arf.json +++ b/public/arf.json @@ -1230,17 +1230,17 @@ "name": "BuiltWith", "type": "url", "url": "https://builtwith.com/", - "description": "Technology profiler that identifies the tech stack, analytics, and frameworks used by websites.", + "description": "Web technology profiler identifying CMS platforms, frameworks, analytics, and 2500+ technologies used by websites.", "status": "live", "pricing": "freemium", - "bestFor": "Technology stack identification, competitor analysis", - "input": "Domain or URL", - "output": "Technology list, analytics IDs, hosting info, historical tech changes", + "bestFor": "Web technology intelligence and competitive analysis", + "input": "Website URL or domain", + "output": "Technology stack report, lead generation data", "opsec": "passive", - "opsecNote": "Queries cached technology profiles. Does not contact the target.", + "opsecNote": "Public website analysis; passive technical reconnaissance", "localInstall": false, "googleDork": false, - "registration": true, + "registration": false, "editUrl": false, "api": true, "invitationOnly": false, @@ -1772,32 +1772,122 @@ { "name": "vURL Online", "type": "url", - "url": "https://vurldissect.co.uk/" + "url": "https://vurldissect.co.uk/", + "description": "URL and domain dissection tool providing detailed reputation analysis and security assessment.", + "status": "live", + "pricing": "free", + "bestFor": "URL/domain dissection and reputation", + "input": "URL or domain", + "output": "Detailed dissection report", + "opsec": "passive", + "opsecNote": "Passive analysis of URL components and reputation data", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false }, { "name": "AlienVault Open Threat Exchange", "type": "url", - "url": "https://otx.alienvault.com/browse/pulses/" + "url": "https://otx.alienvault.com/browse/pulses/", + "description": "Community-driven threat intelligence platform enabling collaborative defense with 180K+ participants sharing 19M+ threats daily.", + "status": "live", + "pricing": "free", + "bestFor": "Community threat intelligence sharing", + "input": "Domain, IP, URL, file hash", + "output": "Threat pulses, reputation data, indicators", + "opsec": "passive", + "opsecNote": "Community-sourced intelligence; free API access with registration", + "localInstall": false, + "googleDork": false, + "registration": true, + "editUrl": false, + "api": true, + "invitationOnly": false, + "deprecated": false }, { "name": "Malware Domain List", "type": "url", - "url": "https://www.malwaredomainlist.com/mdl.php" + "url": "https://www.malwaredomainlist.com/mdl.php", + "description": "Interactive malware domain reputation lookup providing verified malicious domain intelligence.", + "status": "live", + "pricing": "free", + "bestFor": "Malware domain reputation queries", + "input": "Domain name", + "output": "Domain reputation report", + "opsec": "passive", + "opsecNote": "Queries curated malware domain database; passive lookup only", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false }, { "name": "Web Inspector Online Scan", "type": "url", - "url": "https://www.webinspector.com/website-malware-scanner/" + "url": "https://www.webinspector.com/website-malware-scanner/", + "description": "Free cloud-based website malware scanner with daily automated scanning and blacklist checking capabilities.", + "status": "live", + "pricing": "free", + "bestFor": "Website malware scanning", + "input": "Website URL", + "output": "Malware scan report, vulnerability assessment", + "opsec": "active", + "opsecNote": "Active scanning required; connects to target website to analyze content", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false }, { "name": "Google Safe Browsing API", "type": "url", - "url": "https://developers.google.com/safe-browsing/?csw=1" + "url": "https://developers.google.com/safe-browsing/?csw=1", + "description": "Google's free API detecting malicious URLs and phishing sites with protection across billions of devices.", + "status": "live", + "pricing": "free", + "bestFor": "Malware and phishing URL detection", + "input": "URL or domain", + "output": "Safe/unsafe classification, threat type", + "opsec": "passive", + "opsecNote": "Free for non-commercial use; commercial use requires Web Risk API (paid)", + "localInstall": false, + "googleDork": false, + "registration": true, + "editUrl": false, + "api": true, + "invitationOnly": false, + "deprecated": false }, { "name": "Cisco Talos", "type": "url", - "url": "https://talosintelligence.com/" + "url": "https://talosintelligence.com/", + "description": "Cisco's comprehensive IP and domain reputation intelligence system with real-time threat detection spanning millions of sensors.", + "status": "live", + "pricing": "free", + "bestFor": "IP/domain reputation intelligence", + "input": "IP address or domain", + "output": "Reputation score, threat indicators, intelligence reports", + "opsec": "passive", + "opsecNote": "Passive intelligence from Cisco's extensive network of sensors and endpoints", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false } ] }, @@ -1808,67 +1898,262 @@ { "name": "Threatexpert.com Malicious URLs", "type": "url", - "url": "https://www.networksec.org/grabbho/block.txt" + "url": "https://www.networksec.org/grabbho/block.txt", + "description": "Malicious URL blacklist feed from abuse.ch's URL repository tracking malware distribution vectors.", + "status": "down", + "pricing": "free", + "bestFor": "Malware URL intelligence", + "input": "Domain or URL", + "output": "Blocklist/Feed format", + "opsec": "passive", + "opsecNote": "Retrieves historical blocklist data from abuse.ch infrastructure", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": true }, { "name": "Zeus C2 Tracker", "type": "url", - "url": "https://zeustracker.abuse.ch/blocklist.php?download=domainblocklist" + "url": "https://zeustracker.abuse.ch/blocklist.php?download=domainblocklist", + "description": "abuse.ch project tracking Zeus command and control servers with domain and IP blocklists.", + "status": "live", + "pricing": "free", + "bestFor": "Zeus botnet C2 blocking", + "input": "None (blocklist provider)", + "output": "Domain/IP blocklist, Snort rules, Squid format", + "opsec": "passive", + "opsecNote": "Queries public Zeus tracker database; no active scanning", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false }, { "name": "Malware Domains Blacklist", "type": "url", - "url": "https://mirror1.malwaredomains.com/files/domains.txt" + "url": "https://mirror1.malwaredomains.com/files/domains.txt", + "description": "Historical malware domains blocklist providing hosts file format malicious domain list.", + "status": "down", + "pricing": "free", + "bestFor": "Malware domain blocking (legacy)", + "input": "None (blocklist provider)", + "output": "Hosts file format", + "opsec": "passive", + "opsecNote": "Legacy service; no longer maintained", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": true }, { "name": "Blackweb", "type": "url", - "url": "https://github.com/maravento/blackweb" + "url": "https://github.com/maravento/blackweb", + "description": "Open-source project consolidating public malware domain blacklists optimized for Squid-Cache compatibility.", + "status": "live", + "pricing": "free", + "bestFor": "Squid proxy malware filtering", + "input": "None (aggregated blocklist)", + "output": "Squid-compatible blocklist format", + "opsec": "passive", + "opsecNote": "Aggregates existing public blacklist sources; requires DNS verification", + "localInstall": true, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false }, { "name": "Critical Stack Intel (R)", "type": "url", - "url": "https://intel.criticalstack.com/" + "url": "https://intel.criticalstack.com/", + "description": "Free threat intelligence feeds integrated with Bro/Zeek network security monitoring systems.", + "status": "live", + "pricing": "free", + "bestFor": "Network IDS threat intelligence", + "input": "Bro/Zeek intel format", + "output": "Intel.log entries, network alerts", + "opsec": "passive", + "opsecNote": "Requires registration; polled hourly from curated threat intelligence feeds", + "localInstall": true, + "googleDork": false, + "registration": true, + "editUrl": false, + "api": true, + "invitationOnly": false, + "deprecated": false }, { "name": "DNS Sinkhole", "type": "url", - "url": "https://malc0de.com/bl/" + "url": "https://malc0de.com/bl/", + "description": "Malware domain sinkhole from malc0de.com providing DNS-based threat blocking zones.", + "status": "degraded", + "pricing": "free", + "bestFor": "DNS-based malware blocking", + "input": "DNS zone file", + "output": "Malware domain sinkhole list", + "opsec": "passive", + "opsecNote": "Public malware database; Cloudflare CAPTCHA protection added", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false }, { "name": "DNS-BH Malware Domain Blocklist", "type": "url", - "url": "https://www.malwaredomains.com/wordpress/?page_id=66" + "url": "https://www.malwaredomains.com/wordpress/?page_id=66", + "description": "Legacy malware domain blocklist from RiskAnalytics using Black Hole DNS sinkhole technology.", + "status": "down", + "pricing": "free", + "bestFor": "Malware domain blocking (legacy)", + "input": "None (blocklist provider)", + "output": "Multiple formats (BIND, BOOT, ISA, MaraDNS)", + "opsec": "passive", + "opsecNote": "Service sunset; merged into ShadowNet", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": true }, { "name": "Malware Domain List", "type": "url", - "url": "https://www.malwaredomainlist.com/hostslist/hosts.txt" + "url": "https://www.malwaredomainlist.com/hostslist/hosts.txt", + "description": "Interactive malware domain reputation lookup providing verified malicious domain intelligence.", + "status": "live", + "pricing": "free", + "bestFor": "Malware domain reputation queries", + "input": "Domain name", + "output": "Domain reputation report", + "opsec": "passive", + "opsecNote": "Queries curated malware domain database; passive lookup only", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false }, { "name": "MalwareURL (R)", "type": "url", - "url": "https://www.malwareurl.com/index.php" + "url": "https://www.malwareurl.com/index.php", + "description": "Commercial malware URL reputation checker and blocklist service protecting networks from known malicious websites.", + "status": "live", + "pricing": "freemium", + "bestFor": "Malware URL reputation checking", + "input": "URL", + "output": "Reputation report, blocklist data", + "opsec": "passive", + "opsecNote": "Free lookup service available; commercial network integration available", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false }, { "name": "scumware.org", "type": "url", - "url": "https://www.scumware.org/" + "url": "https://www.scumware.org/", + "description": "Free malware and spyware tracking domain blacklist maintained by security community for 18+ years.", + "status": "live", + "pricing": "free", + "bestFor": "Malware and spyware domain research", + "input": "Domain or URL", + "output": "Domain reputation/blocklist data", + "opsec": "passive", + "opsecNote": "Community-maintained research database; passive lookup only", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false }, { "name": "ZeuS Tracker", "type": "url", - "url": "https://zeustracker.abuse.ch/blocklist.php" + "url": "https://zeustracker.abuse.ch/blocklist.php", + "description": "abuse.ch project providing comprehensive tracking of Zeus botnet C2 infrastructure with domain and IP blocklists.", + "status": "live", + "pricing": "free", + "bestFor": "Zeus botnet tracking and blocking", + "input": "None (blocklist provider)", + "output": "Domain blocklist, IP blocklist, Snort rules, Squid format", + "opsec": "passive", + "opsecNote": "Public tracker; passive monitoring of Zeus C2 activity", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false }, { "name": "Shadowserver Foundation", "type": "url", - "url": "https://www.shadowserver.org/" + "url": "https://www.shadowserver.org/", + "description": "Nonprofit providing comprehensive IP reputation intelligence and automated abuse reporting through daily network scanning.", + "status": "live", + "pricing": "free", + "bestFor": "IP/domain reputation and abuse intelligence", + "input": "IP address or domain", + "output": "Reputation reports, blocklists, abuse intelligence", + "opsec": "passive", + "opsecNote": "Passive intelligence from honeypots and network sensors; no active scanning", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": true, + "invitationOnly": false, + "deprecated": false }, { "name": "Email Domain Validation", "type": "url", - "url": "https://www.mailboxvalidator.com/domain" + "url": "https://www.mailboxvalidator.com/domain", + "description": "Free email domain validation tool checking DNS records, MX records, and mail server connectivity.", + "status": "live", + "pricing": "freemium", + "bestFor": "Email domain and mailbox verification", + "input": "Email domain or address", + "output": "Domain validation report, MX records", + "opsec": "active", + "opsecNote": "Active mail server connectivity checks required for validation", + "localInstall": false, + "googleDork": false, + "registration": true, + "editUrl": false, + "api": true, + "invitationOnly": false, + "deprecated": false } ] }, @@ -1879,22 +2164,82 @@ { "name": "DNS Twist (T)", "type": "url", - "url": "https://github.com/elceef/dnstwist" + "url": "https://github.com/elceef/dnstwist", + "description": "Domain name permutation engine for detecting homograph phishing attacks and typosquatting with fuzzy hashing.", + "status": "live", + "pricing": "free", + "bestFor": "Typosquatting and phishing domain detection", + "input": "Domain name", + "output": "Domain permutation list, DNS records, HTTP similarity", + "opsec": "active", + "opsecNote": "Active DNS queries required; queries can be resource-intensive (300K+ queries for google.com)", + "localInstall": true, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false }, { "name": "URLCrazy (T)", "type": "url", - "url": "https://www.morningstarsecurity.com/research/urlcrazy" + "url": "https://www.morningstarsecurity.com/research/urlcrazy", + "description": "Ruby-based typosquatting domain generator supporting 15 variation types and 8000+ common misspellings.", + "status": "live", + "pricing": "free", + "bestFor": "Typosquatting domain discovery", + "input": "Domain name", + "output": "Domain variant list, registration status", + "opsec": "active", + "opsecNote": "Generates 2000+ variants requiring DNS queries for availability checking", + "localInstall": true, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false }, { "name": "dnstwister", "type": "url", - "url": "https://dnstwister.report/" + "url": "https://dnstwister.report/", + "description": "Web-based domain permutation tool with free lookup and paid monitoring plans for typosquatting detection.", + "status": "live", + "pricing": "freemium", + "bestFor": "Typosquatting monitoring", + "input": "Domain name", + "output": "Domain variants, registration status, DNS records", + "opsec": "active", + "opsecNote": "Active DNS queries required for variant checking; paid plans enable continuous monitoring", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false }, { "name": "Catphish (T)", "type": "url", - "url": "https://github.com/ring0lab/catphish" + "url": "https://github.com/ring0lab/catphish", + "description": "Red team tool for generating phishing domains using homoglyphs, punycode, and domain manipulation techniques.", + "status": "live", + "pricing": "free", + "bestFor": "Red team phishing domain generation", + "input": "Target domain", + "output": "Phishing domain variants, categorization status", + "opsec": "active", + "opsecNote": "Generates domains for red team operations; checks domain categorization to evade proxies", + "localInstall": true, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false } ] }, @@ -1906,17 +2251,17 @@ "name": "BuiltWith", "type": "url", "url": "https://builtwith.com/", - "description": "Technology profiler that identifies the tech stack, analytics, and frameworks used by websites.", + "description": "Web technology profiler identifying CMS platforms, frameworks, analytics, and 2500+ technologies used by websites.", "status": "live", "pricing": "freemium", - "bestFor": "Technology stack identification, competitor analysis", - "input": "Domain or URL", - "output": "Technology list, analytics IDs, hosting info, historical tech changes", + "bestFor": "Web technology intelligence and competitive analysis", + "input": "Website URL or domain", + "output": "Technology stack report, lead generation data", "opsec": "passive", - "opsecNote": "Queries cached technology profiles. Does not contact the target.", + "opsecNote": "Public website analysis; passive technical reconnaissance", "localInstall": false, "googleDork": false, - "registration": true, + "registration": false, "editUrl": false, "api": true, "invitationOnly": false, @@ -1925,7 +2270,22 @@ { "name": "SiteSleuth", "type": "url", - "url": "https://www.sitesleuth.io/" + "url": "https://www.sitesleuth.io/", + "description": "OSINT domain analytics tool tracking Google Analytics, AdSense, and Stripe keys across 32+ million websites.", + "status": "live", + "pricing": "free", + "bestFor": "Tracking code intelligence and related domain discovery", + "input": "Domain, Google Analytics ID, AdSense ID, or Stripe key", + "output": "List of associated domains and tracking codes", + "opsec": "passive", + "opsecNote": "Passive intelligence from indexed tracking identifiers; no direct queries to targets", + "localInstall": false, + "googleDork": false, + "registration": false, + "editUrl": false, + "api": false, + "invitationOnly": false, + "deprecated": false }, { "name": "Wappalyzer (T)", @@ -4823,12 +5183,12 @@ "url": "https://www.brbpub.com/" }, { - "name": "GOVDATA - Das Datenportal für Deutschland (German)", + "name": "GOVDATA - Das Datenportal f\u00fcr Deutschland (German)", "type": "url", "url": "https://www.govdata.de/" }, { - "name": "Open-Data-Portal München (German)", + "name": "Open-Data-Portal M\u00fcnchen (German)", "type": "url", "url": "https://www.opengov-muenchen.de/" }, @@ -8453,7 +8813,7 @@ "url": "https://themanyhats.club/centralised-place-for-privacy-resources/" }, { - "name": "The Hitchhiker’s Guide to Online Anonymity", + "name": "The Hitchhiker\u2019s Guide to Online Anonymity", "type": "url", "url": "https://anonymousplanet.org/guide/" }, @@ -8629,4 +8989,4 @@ ] } ] -} +} \ No newline at end of file