mirror of
https://github.com/lockfale/OSINT-Framework.git
synced 2026-08-17 19:35:41 +02:00
Merge branch 'master' into feature/THE-132-domain-batch6-curation
This commit is contained in:
@@ -0,0 +1,551 @@
|
||||
# THE-127: Domain Name Tools Enrichment - Batch 1
|
||||
|
||||
Enrichment data for 25 Domain Name tools in the OSINT Framework arf.json.
|
||||
|
||||
## Whois Records Category
|
||||
|
||||
### 1. Domain Dossier
|
||||
```json
|
||||
{
|
||||
"description": "Free web-based tool that aggregates WHOIS, DNS, and network information for domains and IP addresses into a single consolidated report.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Quick domain and IP reconnaissance with DNS and WHOIS data",
|
||||
"input": "Domain name or IP address",
|
||||
"output": "WHOIS records, DNS records, IP information, registration details",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Queries public WHOIS and DNS records; does not contact the target domain directly.",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 2. domainIQ
|
||||
```json
|
||||
{
|
||||
"description": "Comprehensive domain intelligence platform offering reverse lookups, ownership history, and related domain discovery. Trusted by government agencies, domain investors, and legal firms.",
|
||||
"status": "live",
|
||||
"pricing": "freemium",
|
||||
"bestFor": "Domain ownership history, reverse analytics lookup, competitor domain research",
|
||||
"input": "Domain name",
|
||||
"output": "Domain owner information, historical ownership, similar domains, analytics data, reverse MX/IP/DNS lookups",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Queries aggregated domain data; does not probe the target directly.",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": true,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 3. DomainTools Whois
|
||||
```json
|
||||
{
|
||||
"description": "Enterprise-grade WHOIS API with decades of historical domain data and rapid query response. The industry leader for threat intelligence and domain tracking.",
|
||||
"status": "live",
|
||||
"pricing": "paid",
|
||||
"bestFor": "Historical WHOIS research, threat actor tracking, enterprise domain intelligence",
|
||||
"input": "Domain name or IP address",
|
||||
"output": "Current and historical WHOIS records, registrant details, hosting history",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Queries cached WHOIS data; no direct contact with target infrastructure.",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": true,
|
||||
"editUrl": false,
|
||||
"api": true,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 4. SWITCH Internet Domains Whois (.ch)
|
||||
```json
|
||||
{
|
||||
"description": "Official Swiss domain registry WHOIS lookup service operated by SWITCH for .ch and .li country-code domains. Public registry with all owner contact details visible.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": ".ch and .li domain ownership research, Swiss Internet infrastructure lookup",
|
||||
"input": ".ch or .li domain name",
|
||||
"output": "Registrant contact details, creation/expiry dates, nameservers, registration status",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Queries the official SWITCH registry database; does not probe the target.",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 5. Whoisology
|
||||
```json
|
||||
{
|
||||
"description": "Searchable archive of billions of current and historical domain WHOIS records with cross-referencing capabilities. Designed for InfoSec, legal, and research professionals.",
|
||||
"status": "live",
|
||||
"pricing": "freemium",
|
||||
"bestFor": "Historical domain ownership, reverse WHOIS lookups, domain connection tracking",
|
||||
"input": "Domain name, email, registrant name",
|
||||
"output": "Historical WHOIS records, ownership changes, registrant information across domains",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Accesses archived WHOIS data; no direct probing of target domains.",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 6. Whois ARIN
|
||||
```json
|
||||
{
|
||||
"description": "Official American Registry for Internet Numbers WHOIS and RDAP lookup service for IPv4, IPv6, ASNs, and organizations in the North American region.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "IP address and ASN registration data, North American internet resource tracking",
|
||||
"input": "IP address, ASN, organization name, contact information",
|
||||
"output": "IP ownership, organization details, Points of Contact (POCs), ASN information",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Queries official ARIN database; does not contact targets or perform active scanning.",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 7. DNSstuff
|
||||
```json
|
||||
{
|
||||
"description": "Suite of free DNS and network tools providing lookups, DNS checks, and WHOIS information for domain reconnaissance.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Quick DNS and WHOIS lookups, network diagnostics",
|
||||
"input": "Domain name, IP address",
|
||||
"output": "DNS records, WHOIS data, DNS propagation checks, nameserver information",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Queries public DNS and WHOIS servers; does not probe target infrastructure.",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 8. Robtex
|
||||
```json
|
||||
{
|
||||
"description": "Comprehensive free DNS lookup and network intelligence tool with decade-spanning database containing billions of documents of internet data. Useful for forensics and threat actor tracking.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "DNS reconnaissance, IP and domain relationship mapping, historical internet data lookup",
|
||||
"input": "Domain name, IP address, hostname, autonomous system",
|
||||
"output": "DNS records, IP information, SEO data, reputation scores, historical relationships",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Searches historical and cached DNS data; does not perform active probing.",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 9. Domaincrawler.com
|
||||
```json
|
||||
{
|
||||
"description": "Enterprise-grade domain database covering 1.4+ billion registered and unregistered domains with 80+ billion historical records since 2008. Used by brand protection and OSINT professionals.",
|
||||
"status": "live",
|
||||
"pricing": "paid",
|
||||
"bestFor": "Large-scale domain research, brand protection monitoring, zone file analysis, market intelligence",
|
||||
"input": "Domain name, DNS data, technology stack filters",
|
||||
"output": "Domain metadata, DNS configuration, SSL certificates, technology stack, ownership connections, historical data",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Queries aggregated domain database updated every 7 days; no active scanning of targets.",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": true,
|
||||
"editUrl": false,
|
||||
"api": true,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 10. MarkMonitor Whois Search
|
||||
```json
|
||||
{
|
||||
"description": "ICANN-accredited registrar and brand protection company offering WHOIS lookup and domain management services. Exclusively serves corporate clients including major global brands.",
|
||||
"status": "live",
|
||||
"pricing": "paid",
|
||||
"bestFor": "Corporate domain portfolio management, brand protection, trademark monitoring",
|
||||
"input": "Domain name",
|
||||
"output": "WHOIS records, registration data, brand portfolio information",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Accesses standard WHOIS records through registered domain lookups; no direct target probing.",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": true,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 11. easyWhois
|
||||
```json
|
||||
{
|
||||
"description": "Free domain WHOIS lookup and DNS tools service. Now operated under the DomainHelp platform, providing domain registration information and DNS lookups.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Quick domain WHOIS lookups and DNS checks",
|
||||
"input": "Domain name",
|
||||
"output": "WHOIS records, DNS information, registrant details, nameservers",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Queries public WHOIS and DNS data; does not contact the target domain.",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 12. Website Informer
|
||||
```json
|
||||
{
|
||||
"description": "Free domain and website information aggregator providing visitor statistics, safety status, Alexa rankings, ownership data, and technical details about websites.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Website profiling, ownership verification, traffic estimation, technical stack discovery",
|
||||
"input": "Domain name or URL",
|
||||
"output": "Visitor statistics, safety ratings, domain owner information, technology stack, Alexa rank, historical snapshots",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Aggregates public website data and statistics; does not contact the target infrastructure.",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 13. Who.is
|
||||
```json
|
||||
{
|
||||
"description": "Comprehensive WHOIS and RDAP lookup service with large database of domain registration, DNS records, and IP information. Provides both current and historical data.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Domain registration research, WHOIS lookups, RDAP queries, IP tracking",
|
||||
"input": "Domain name or IP address",
|
||||
"output": "WHOIS records, RDAP data, DNS records, nameservers, registrant information",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Queries public WHOIS and RDAP databases; does not perform active scanning.",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 14. Whois AMPed
|
||||
```json
|
||||
{
|
||||
"description": "Mobile-optimized WHOIS lookup service accessible via web interface for domain registration information and WHOIS queries.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Mobile-friendly WHOIS lookups, quick domain information retrieval",
|
||||
"input": "Domain name",
|
||||
"output": "WHOIS records, domain registration information, registrant details",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Accesses public WHOIS data; no target probing or direct contact.",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 15. ViewDNS.info
|
||||
```json
|
||||
{
|
||||
"description": "Comprehensive DNS lookup and WHOIS service providing detailed DNS records, reverse IP lookups, reverse WHOIS searches, and API access for automated queries.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "DNS reconnaissance, reverse IP and reverse WHOIS lookups, historical DNS tracking",
|
||||
"input": "Domain name, IP address, registrant name/email, nameserver",
|
||||
"output": "DNS records, WHOIS information, reverse lookups, IP hosting, historical DNS changes",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Queries public DNS and WHOIS data; does not perform active probing of targets.",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": true,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 16. Daily DNS Changes
|
||||
```json
|
||||
{
|
||||
"description": "DomainTools service monitoring DNS record changes across domains, detecting newly registered subdomains and tracking DNS infrastructure modifications.",
|
||||
"status": "live",
|
||||
"pricing": "freemium",
|
||||
"bestFor": "DNS change detection, subdomain discovery, infrastructure monitoring",
|
||||
"input": "Domain name",
|
||||
"output": "New DNS records, nameserver changes, subdomain discoveries, historical DNS changes",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Monitors public DNS records for changes; no active scanning or direct contact.",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 17. IP2WHOIS
|
||||
```json
|
||||
{
|
||||
"description": "Free WHOIS lookup service for domain names and IP addresses, providing registration details, registrant information, location data, and API access.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Domain and IP WHOIS lookups, registrant research",
|
||||
"input": "Domain name or IP address",
|
||||
"output": "WHOIS records, registrant details, location information, registration dates",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Queries public WHOIS databases; does not contact the target.",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": true,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 18. Netlas.io
|
||||
```json
|
||||
{
|
||||
"description": "Comprehensive internet-wide scanning and OSINT platform providing DNS, WHOIS, SSL, and network reconnaissance with attack surface discovery capabilities.",
|
||||
"status": "live",
|
||||
"pricing": "freemium",
|
||||
"bestFor": "Internet reconnaissance, DNS and WHOIS lookups, attack surface discovery, vulnerability research",
|
||||
"input": "Domain name, IP address, ASN, DNS records",
|
||||
"output": "DNS records, WHOIS data, open ports, SSL certificates, service information, historical data",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Queries cached internet scanning data; free tier available with 50 daily requests.",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": true,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
## Subdomains Category
|
||||
|
||||
### 19. SynapsInt
|
||||
```json
|
||||
{
|
||||
"description": "Unified web-based OSINT research platform supporting domain, IP, SSL, analytics, email, phone, and social media lookups with subdomain enumeration.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Unified OSINT research, subdomain discovery, multi-vector intelligence gathering",
|
||||
"input": "Domain, IP, email, phone, username, CVE ID",
|
||||
"output": "Subdomains, DNS records, WHOIS data, open ports, vulnerabilities, social media accounts, historical data",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Aggregates publicly available information from multiple sources; no direct target contact.",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 20. Aquatone
|
||||
```json
|
||||
{
|
||||
"description": "Go-based tool for domain reconnaissance that automates subdomain discovery, HTTP service scanning, screenshot capture, and visual HTML report generation for attack surface analysis.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Visual subdomain reconnaissance, HTTP service discovery, attack surface mapping",
|
||||
"input": "Domain name",
|
||||
"output": "Discovered subdomains, open ports, HTTP screenshots, consolidated reconnaissance report",
|
||||
"opsec": "active",
|
||||
"opsecNote": "Makes HTTP requests to discovered hosts to capture screenshots and fingerprint services; supports integration with passive enumeration tools.",
|
||||
"localInstall": true,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 21. FindSubDomains
|
||||
```json
|
||||
{
|
||||
"description": "Free web-based automated subdomain discovery tool with filtering and analysis capabilities, showing organization names, relationships, and top subdomain statistics.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Automated subdomain enumeration, organization name filtering, subdomain statistics",
|
||||
"input": "Domain name or keyword",
|
||||
"output": "Discovered subdomains, organization associations, popularity metrics, filtering options",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Uses passive DNS and search-based methods for subdomain discovery; no active probing.",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 22. Google Subdomains
|
||||
```json
|
||||
{
|
||||
"description": "Google Dork technique using the 'site:' operator to enumerate subdomains of a target domain via Google's search index.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Indexed subdomain discovery, publicly visible subdomain enumeration",
|
||||
"input": "Domain name (as Google Dork syntax: site:domain.com)",
|
||||
"output": "Indexed subdomains and pages from Google search results",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Uses Google's search index; no direct contact with the target domain.",
|
||||
"localInstall": false,
|
||||
"googleDork": true,
|
||||
"registration": false,
|
||||
"editUrl": true,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 23. Recon-ng
|
||||
```json
|
||||
{
|
||||
"description": "Full-featured web reconnaissance framework with independent modules for data gathering, API integration, and customizable workflows.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Modular web recon, API-driven data collection, credential gathering",
|
||||
"input": "Domain, company name, email, IP",
|
||||
"output": "Contacts, hosts, credentials, ports via module-specific results",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Queries third-party APIs and data sources. Does not probe the target unless specific modules are configured to do so.",
|
||||
"localInstall": true,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": true,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 24. XRay
|
||||
```json
|
||||
{
|
||||
"description": "Go-based network reconnaissance tool that automates subdomain enumeration via DNS brute force, integrates Shodan for port discovery, and gathers banner information with web UI visualization.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Automated subdomain discovery with banner grabbing, open port enumeration, Shodan integration",
|
||||
"input": "Domain name, subdomain wordlist, Shodan API key (optional), ViewDNS API key (optional)",
|
||||
"output": "Enumerated subdomains, open ports, banner information, historical data, web-based results UI",
|
||||
"opsec": "active",
|
||||
"opsecNote": "Performs DNS brute force for subdomain enumeration and makes banner grabbing connections to discovered services.",
|
||||
"localInstall": true,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
### 25. DNS Recon
|
||||
```json
|
||||
{
|
||||
"description": "Python-based DNS enumeration script supporting zone transfers, standard record enumeration, TLD expansion, DNS brute force, and PTR lookups.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "DNS enumeration, zone transfer testing, subdomain brute forcing, DNS security assessment",
|
||||
"input": "Domain name, IP range/CIDR, subdomain wordlist, DNS server address",
|
||||
"output": "NS/SOA/MX/A records, discovered subdomains, zone transfer results, PTR records, wildcard resolution status",
|
||||
"opsec": "active",
|
||||
"opsecNote": "Performs active DNS queries and brute force attempts; does not probe target services directly but makes repeated DNS requests.",
|
||||
"localInstall": true,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Summary
|
||||
|
||||
**Tools researched**: 25
|
||||
**Category**: Domain Name (Whois Records: 18, Subdomains: 7)
|
||||
**Pricing breakdown**:
|
||||
- Free: 15 tools
|
||||
- Freemium: 4 tools
|
||||
- Paid: 6 tools
|
||||
|
||||
**OPSEC profile**:
|
||||
- Passive: 19 tools
|
||||
- Active: 6 tools
|
||||
|
||||
**Local installation required**: 5 tools (Aquatone, Recon-ng, XRay, DNS Recon, and tools marked with (T))
|
||||
|
||||
All tools verified as live and accessible as of 2026-03-27.
|
||||
@@ -0,0 +1,412 @@
|
||||
{
|
||||
"enrichments": {
|
||||
"Threatexpert.com Malicious URLs": {
|
||||
"description": "Malicious URL blacklist feed from abuse.ch's URL repository tracking malware distribution vectors.",
|
||||
"status": "down",
|
||||
"pricing": "free",
|
||||
"bestFor": "Malware URL intelligence",
|
||||
"input": "Domain or URL",
|
||||
"output": "Blocklist/Feed format",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Retrieves historical blocklist data from abuse.ch infrastructure",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": true
|
||||
},
|
||||
"Zeus C2 Tracker": {
|
||||
"description": "abuse.ch project tracking Zeus command and control servers with domain and IP blocklists.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Zeus botnet C2 blocking",
|
||||
"input": "None (blocklist provider)",
|
||||
"output": "Domain/IP blocklist, Snort rules, Squid format",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Queries public Zeus tracker database; no active scanning",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
},
|
||||
"Malware Domains Blacklist": {
|
||||
"description": "Historical malware domains blocklist providing hosts file format malicious domain list.",
|
||||
"status": "down",
|
||||
"pricing": "free",
|
||||
"bestFor": "Malware domain blocking (legacy)",
|
||||
"input": "None (blocklist provider)",
|
||||
"output": "Hosts file format",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Legacy service; no longer maintained",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": true
|
||||
},
|
||||
"Email Domain Validation": {
|
||||
"description": "Free email domain validation tool checking DNS records, MX records, and mail server connectivity.",
|
||||
"status": "live",
|
||||
"pricing": "freemium",
|
||||
"bestFor": "Email domain and mailbox verification",
|
||||
"input": "Email domain or address",
|
||||
"output": "Domain validation report, MX records",
|
||||
"opsec": "active",
|
||||
"opsecNote": "Active mail server connectivity checks required for validation",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": true,
|
||||
"editUrl": false,
|
||||
"api": true,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
},
|
||||
"Blackweb": {
|
||||
"description": "Open-source project consolidating public malware domain blacklists optimized for Squid-Cache compatibility.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Squid proxy malware filtering",
|
||||
"input": "None (aggregated blocklist)",
|
||||
"output": "Squid-compatible blocklist format",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Aggregates existing public blacklist sources; requires DNS verification",
|
||||
"localInstall": true,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
},
|
||||
"Critical Stack Intel (R)": {
|
||||
"description": "Free threat intelligence feeds integrated with Bro/Zeek network security monitoring systems.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Network IDS threat intelligence",
|
||||
"input": "Bro/Zeek intel format",
|
||||
"output": "Intel.log entries, network alerts",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Requires registration; polled hourly from curated threat intelligence feeds",
|
||||
"localInstall": true,
|
||||
"googleDork": false,
|
||||
"registration": true,
|
||||
"editUrl": false,
|
||||
"api": true,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
},
|
||||
"DNS Sinkhole": {
|
||||
"description": "Malware domain sinkhole from malc0de.com providing DNS-based threat blocking zones.",
|
||||
"status": "degraded",
|
||||
"pricing": "free",
|
||||
"bestFor": "DNS-based malware blocking",
|
||||
"input": "DNS zone file",
|
||||
"output": "Malware domain sinkhole list",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Public malware database; Cloudflare CAPTCHA protection added",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
},
|
||||
"DNS-BH Malware Domain Blocklist": {
|
||||
"description": "Legacy malware domain blocklist from RiskAnalytics using Black Hole DNS sinkhole technology.",
|
||||
"status": "down",
|
||||
"pricing": "free",
|
||||
"bestFor": "Malware domain blocking (legacy)",
|
||||
"input": "None (blocklist provider)",
|
||||
"output": "Multiple formats (BIND, BOOT, ISA, MaraDNS)",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Service sunset; merged into ShadowNet",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": true
|
||||
},
|
||||
"Malware Domain List": {
|
||||
"description": "Interactive malware domain reputation lookup providing verified malicious domain intelligence.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Malware domain reputation queries",
|
||||
"input": "Domain name",
|
||||
"output": "Domain reputation report",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Queries curated malware domain database; passive lookup only",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
},
|
||||
"MalwareURL (R)": {
|
||||
"description": "Commercial malware URL reputation checker and blocklist service protecting networks from known malicious websites.",
|
||||
"status": "live",
|
||||
"pricing": "freemium",
|
||||
"bestFor": "Malware URL reputation checking",
|
||||
"input": "URL",
|
||||
"output": "Reputation report, blocklist data",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Free lookup service available; commercial network integration available",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
},
|
||||
"scumware.org": {
|
||||
"description": "Free malware and spyware tracking domain blacklist maintained by security community for 18+ years.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Malware and spyware domain research",
|
||||
"input": "Domain or URL",
|
||||
"output": "Domain reputation/blocklist data",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Community-maintained research database; passive lookup only",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
},
|
||||
"ZeuS Tracker": {
|
||||
"description": "abuse.ch project providing comprehensive tracking of Zeus botnet C2 infrastructure with domain and IP blocklists.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Zeus botnet tracking and blocking",
|
||||
"input": "None (blocklist provider)",
|
||||
"output": "Domain blocklist, IP blocklist, Snort rules, Squid format",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Public tracker; passive monitoring of Zeus C2 activity",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
},
|
||||
"Shadowserver Foundation": {
|
||||
"description": "Nonprofit providing comprehensive IP reputation intelligence and automated abuse reporting through daily network scanning.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "IP/domain reputation and abuse intelligence",
|
||||
"input": "IP address or domain",
|
||||
"output": "Reputation reports, blocklists, abuse intelligence",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Passive intelligence from honeypots and network sensors; no active scanning",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": true,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
},
|
||||
"vURL Online": {
|
||||
"description": "URL and domain dissection tool providing detailed reputation analysis and security assessment.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "URL/domain dissection and reputation",
|
||||
"input": "URL or domain",
|
||||
"output": "Detailed dissection report",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Passive analysis of URL components and reputation data",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
},
|
||||
"AlienVault Open Threat Exchange": {
|
||||
"description": "Community-driven threat intelligence platform enabling collaborative defense with 180K+ participants sharing 19M+ threats daily.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Community threat intelligence sharing",
|
||||
"input": "Domain, IP, URL, file hash",
|
||||
"output": "Threat pulses, reputation data, indicators",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Community-sourced intelligence; free API access with registration",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": true,
|
||||
"editUrl": false,
|
||||
"api": true,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
},
|
||||
"Web Inspector Online Scan": {
|
||||
"description": "Free cloud-based website malware scanner with daily automated scanning and blacklist checking capabilities.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Website malware scanning",
|
||||
"input": "Website URL",
|
||||
"output": "Malware scan report, vulnerability assessment",
|
||||
"opsec": "active",
|
||||
"opsecNote": "Active scanning required; connects to target website to analyze content",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
},
|
||||
"Google Safe Browsing API": {
|
||||
"description": "Google's free API detecting malicious URLs and phishing sites with protection across billions of devices.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Malware and phishing URL detection",
|
||||
"input": "URL or domain",
|
||||
"output": "Safe/unsafe classification, threat type",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Free for non-commercial use; commercial use requires Web Risk API (paid)",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": true,
|
||||
"editUrl": false,
|
||||
"api": true,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
},
|
||||
"Cisco Talos": {
|
||||
"description": "Cisco's comprehensive IP and domain reputation intelligence system with real-time threat detection spanning millions of sensors.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "IP/domain reputation intelligence",
|
||||
"input": "IP address or domain",
|
||||
"output": "Reputation score, threat indicators, intelligence reports",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Passive intelligence from Cisco's extensive network of sensors and endpoints",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
},
|
||||
"DNS Twist (T)": {
|
||||
"description": "Domain name permutation engine for detecting homograph phishing attacks and typosquatting with fuzzy hashing.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Typosquatting and phishing domain detection",
|
||||
"input": "Domain name",
|
||||
"output": "Domain permutation list, DNS records, HTTP similarity",
|
||||
"opsec": "active",
|
||||
"opsecNote": "Active DNS queries required; queries can be resource-intensive (300K+ queries for google.com)",
|
||||
"localInstall": true,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
},
|
||||
"URLCrazy (T)": {
|
||||
"description": "Ruby-based typosquatting domain generator supporting 15 variation types and 8000+ common misspellings.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Typosquatting domain discovery",
|
||||
"input": "Domain name",
|
||||
"output": "Domain variant list, registration status",
|
||||
"opsec": "active",
|
||||
"opsecNote": "Generates 2000+ variants requiring DNS queries for availability checking",
|
||||
"localInstall": true,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
},
|
||||
"dnstwister": {
|
||||
"description": "Web-based domain permutation tool with free lookup and paid monitoring plans for typosquatting detection.",
|
||||
"status": "live",
|
||||
"pricing": "freemium",
|
||||
"bestFor": "Typosquatting monitoring",
|
||||
"input": "Domain name",
|
||||
"output": "Domain variants, registration status, DNS records",
|
||||
"opsec": "active",
|
||||
"opsecNote": "Active DNS queries required for variant checking; paid plans enable continuous monitoring",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
},
|
||||
"Catphish (T)": {
|
||||
"description": "Red team tool for generating phishing domains using homoglyphs, punycode, and domain manipulation techniques.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Red team phishing domain generation",
|
||||
"input": "Target domain",
|
||||
"output": "Phishing domain variants, categorization status",
|
||||
"opsec": "active",
|
||||
"opsecNote": "Generates domains for red team operations; checks domain categorization to evade proxies",
|
||||
"localInstall": true,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
},
|
||||
"BuiltWith": {
|
||||
"description": "Web technology profiler identifying CMS platforms, frameworks, analytics, and 2500+ technologies used by websites.",
|
||||
"status": "live",
|
||||
"pricing": "freemium",
|
||||
"bestFor": "Web technology intelligence and competitive analysis",
|
||||
"input": "Website URL or domain",
|
||||
"output": "Technology stack report, lead generation data",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Public website analysis; passive technical reconnaissance",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": true,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
},
|
||||
"SiteSleuth": {
|
||||
"description": "OSINT domain analytics tool tracking Google Analytics, AdSense, and Stripe keys across 32+ million websites.",
|
||||
"status": "live",
|
||||
"pricing": "free",
|
||||
"bestFor": "Tracking code intelligence and related domain discovery",
|
||||
"input": "Domain, Google Analytics ID, AdSense ID, or Stripe key",
|
||||
"output": "List of associated domains and tracking codes",
|
||||
"opsec": "passive",
|
||||
"opsecNote": "Passive intelligence from indexed tracking identifiers; no direct queries to targets",
|
||||
"localInstall": false,
|
||||
"googleDork": false,
|
||||
"registration": false,
|
||||
"editUrl": false,
|
||||
"api": false,
|
||||
"invitationOnly": false,
|
||||
"deprecated": false
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,41 @@
|
||||
#!/usr/bin/env python3
|
||||
import json
|
||||
import sys
|
||||
|
||||
def merge_enrichment_into_node(node, enrichments):
|
||||
"""Recursively search and merge enrichment data into matching nodes."""
|
||||
if isinstance(node, dict):
|
||||
if "name" in node and node["name"] in enrichments:
|
||||
# Found a matching tool, merge enrichment data
|
||||
enrichment = enrichments[node["name"]]
|
||||
for key, value in enrichment.items():
|
||||
node[key] = value
|
||||
|
||||
# Recursively process children
|
||||
if "children" in node and isinstance(node["children"], list):
|
||||
for child in node["children"]:
|
||||
merge_enrichment_into_node(child, enrichments)
|
||||
|
||||
def main():
|
||||
# Load enrichment data
|
||||
with open("enrichment-batch4-domains.json", "r") as f:
|
||||
enrichment_data = json.load(f)
|
||||
|
||||
enrichments = enrichment_data["enrichments"]
|
||||
|
||||
# Load arf.json
|
||||
with open("public/arf.json", "r") as f:
|
||||
arf_data = json.load(f)
|
||||
|
||||
# Merge enrichment data into arf.json
|
||||
merge_enrichment_into_node(arf_data, enrichments)
|
||||
|
||||
# Write the updated arf.json
|
||||
with open("public/arf.json", "w") as f:
|
||||
json.dump(arf_data, f, indent=2)
|
||||
|
||||
print(f"Successfully merged enrichment data for {len(enrichments)} tools")
|
||||
print("Updated public/arf.json")
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
+3859
-310
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user