Repository navigation
This script automates several key steps in reconnaissance for bug bounty and penetration testing tasks. It is designed to discover, resolve, and analyze domains efficiently, making it a powerful tool for security researchers and bug bounty hunters.
Features
1. Domain Input Flexibility
- Single Domain or Multiple Domains: Supports both a single domain input or a list of domains in a file. The script will handle batch processing for larger lists, making it scalable for broad recon.
- Domain Cleaning: Automatically sanitizes and formats domains provided in a file by:
- Removing wildcards (
*.prefixes). - Stripping URLs to just the domain.
- Filtering out empty lines and comments.
- Removing duplicates.
- Removing wildcards (
2. Subdomain Discovery
- Subfinder Integration: Uses Subfinder to discover subdomains for each root domain, storing results in organized output folders.
3. Domain Categorization
- Sensitive Root Domains Filtering: Automatically filters out subdomains with sensitive keywords (e.g.,
api,dev,internal) to identify potentially interesting targets. - HTTP Probing: Ensures only live domains are added to further recon steps.
4. Content Discovery
- Meg Integration: Uses
megfor endpoint discovery to identify valid URLs and status codes for each discovered subdomain.
5. Screenshot Capture
- Eyewitness or Aquatone: Compatible with Aquatone or similar tools to capture screenshots of live hosts for visual inspection and reporting.