loading
loading
Every tool you can run in a Trickest workflow, 311 in total. Each page covers what it does, its real inputs and outputs, the skills it belongs to, and a runnable example.
Async DNS brute force for subdomains that passive sources miss.
Multi-source subdomain discovery; hand names to httpx.
OWASP Amass intel: map an organization's root domains and ranges.
OWASP Amass enumeration that emits structured JSON.
Find related domains via shared Google Analytics IDs.
Find domains and subdomains potentially related to a given domain.
Modular OSINT recon that chains modules from a seed target.
CLI client for the BeVigil OSINT API, keyed by domain or app package.
Fingerprint the software version of a remote F5 BIG-IP management interface.
Extract URLs for a specific target from commoncrawl.org indexes.
Detect CDN, WAF, and cloud technology for a given IP or hostname.
Scrape domain names from SSL certificates of arbitrary hosts.
Pull a domain's subdomains from the crt.sh certificate transparency database.
Go client for ProjectDiscovery Chaos DB subdomain lookups.
Module-driven extractor for Wayback Machine page history.
Multi-cloud public name enumeration for AWS, Azure, and GCP.
List assets from multiple cloud providers in one inventory.
Passive LinkedIn employee enumeration through search engine results.
Discover related domains from Content-Security-Policy headers.
Permute known subdomains, then resolve what lives.
Active multi-technique DNS enumeration for assessments.
Multi-purpose DNS toolkit for resolution, record queries, and wordlist brute force.
Automate GitHub and GitLab dorking from a target list.
Hash favicons across a URL list and match them against a fingerprint dictionary.
Passive subdomain enumeration with optional resolve and HTTP checks.
Pull acquired companies for a parent domain from SecurityTrails.
GitHub Archive URLs in, unique repository and user CSVs out.
GraphQL enrichment and dedupe for archive repo and user CSVs.
Filter scraped GitHub archive CSVs by star, fork, and watcher floors.
Parse GitHub Archive logs into deduplicated repository and user CSVs.
Find endpoints for a domain in public GitHub code.
Find subdomains for a domain in public GitHub code.
Wordlist-driven subdomain permutations from known hosts.
DNS subdomain brute force with wildcard handling.
Repeatable Google dorking through a Custom Search Engine.
DNS wordlists through subdomain permutations.
Bulk reverse DNS lookups from an IP list.
CLI client for SecurityTrails subdomain, WHOIS, and DNS modes.
OSINT mapping from IP addresses to virtual hostnames.
Passive subdomain lookup against the jldc.me Anubis API.
DNS stub resolver for large domain lists.
Subdomain candidates from a wordlist for DNS resolution.
Passive Shodan enrichment for IP lists: ports and known CVEs.
Subdomain recon with passive sources, optional brute force, and alive filtering.
A fast domain resolver and subdomain bruteforcing tool that filters out wildcards and poisoned entries.
Crawler that collects second-order subdomain references for takeover review.
Passive SecurityTrails subdomain list for one root domain.
massdns wrapper for active subdomain brute force and resolution with wildcard filtering.
Automated OSINT modules for attack surface mapping.
DNS subdomain brute force routed through open resolvers.
Mine JavaScript and GitHub for subdomains, cloud URLs, and secrets.
A subdomain discovery tool that finds valid subdomains using passive online sources.
OSINT subdomain enumeration across search engines, with optional SubBrute.
Subdomain enumeration with optional probing, takeover checks, and HTML reports.
Passive OSINT for emails, names, and subdomains on a domain.
TLS grabber for certificates, SANs, and JARM or JA3 fingerprints.
Virtual host scanner with Host-header sweeps and catch-all detection.
Passive subdomain gathering from certificate logs, DNS aggregators, and archives.
Multi-archive URL harvest with optional response download.
Fingerprint web application firewalls and test tamper bypasses.
Plugin-based fingerprinting for CMS, servers, libraries, and devices.
Forward WHOIS for a hostname through RIPE.net.
Pivot one registrant detail into registered domains.
Passive subdomain discovery from curated OSINT sources.
CLI DNS lookup for bulk name lists.
zgrab2 HTTP module for structured banner grabs.
Parsed zgrab2 HTTP output: title, status, content length.
Active JARM TLS fingerprinting via zgrab2.
Multi-protocol zgrab2 grabs driven by one config file.
TLS handshake and certificate grabs for host lists.
Headless check for URLs that return 200 but render not-found.
Append lines to a file only if they are not already there.
Extract URLs and endpoints from Android APK files.
Visual inspection of websites across many hosts.
List and flag sensitive keys across many S3 buckets.
Checks live URLs for backup files and exposed version-control paths.
Crawl a domain list and scan responses for endpoints, secrets, tokens, and juicy files.
Discover the origin host behind a reverse proxy, useful when a cloud WAF hides the backend.
Spider pages and scrape linked cloud resource strings.
Browser-driven crawler that harvests requests for downstream scanners.
Web path scanner.
Regex hunt for exposed API keys with exploitation hints.
Crawl pages, harvest potential parameters, write a custom wordlist.
Recursive content discovery with smart defaults and rich response filters.
Domain-derived backup-file URL fuzzer.
Passive known-URL fetch from public web archives.
Maintained gau fork for passive archive URL collection.
Extract JavaScript file URLs from a page or URL list.
Hunt public GitHub code for leaked credential files.
Download exposed .git directories when listing is disabled.
Download an exposed .git and rebuild the working tree in one pass.
Reconstruct commits from a dumped .git folder.
Flag hosts that serve a publicly accessible .git directory.
Directory and file brute force against a live web target.
Single-URL extractor for endpoints in HTML and embedded scripts.
Go web crawler for links, forms, and JS endpoints.
Headless Chrome screenshots for web target triage.
Screenshot URLs and store capture metadata in SQLite.
Screenshot web services discovered in an nmap XML scan.
HTTP status codes for a URL list. Nothing else.
Go crawler for URLs, forms, and JavaScript locations.
Probe hosts with httpx and save a screenshot of each page.
Capture web host screenshots with httpx and export them as a zip.
Extract URLs, paths, and secrets from JavaScript with a syntax tree.
A fast crawling and spidering framework.
Schema-aware API route discovery for modern apps.
Discover endpoints and parameters inside JavaScript files.
Sweep a host list for publicly accessible .git directories.
LinkFinder over a file of JavaScript URLs, with -r filter and -c cookies.
Fetch many paths across many hosts while staying polite per host.
Routes port checks through public websites so probes do not leave your host.
Scroll SecurityTrails with an embedded query and api-key.
Reconstruct JavaScript source trees from Sourcemap files.
Audit endpoints declared in exposed Swagger and OpenAPI specs.
Passive URL collection from public discovery sources.
Search archives of URLs exposed via shortener services.
Identify CMS, frameworks, analytics, and servers on a website.
Passive historic robots.txt path enumeration from Wayback.
Go Wappalyzer port for bulk technology fingerprinting.
Browser-driven screenshots for visual host triage.
WitnessMe grab mode for links and XPath field extraction.
WitnessMe screenshot mode for visual web inventory.
Endpoints and parameters from crawls and saved traffic.
Passive known-URL discovery from archive feeds.
Import, export, and upsert workflow data against an Airtable base.
Decode Android APK files into smali sources and resources.
Check a file's values against conditions and exit with a matching code.
Authenticated Route53 hosted-zone inventory.
Extract file or folder lines by START_LINE,END_LINE batch range.
Extract a START,END batch from file lines or folder files.
Organize community Nuclei templates from across the ecosystem in one place.
Spider a URL and return a wordlist for password crackers.
Regex-clean a wordlist before the slow stage reads it.
Diff this run against a Trickest storage baseline.
Wordlist and mined-word subdomain permutation.
Execute a custom shell script inside one or more Docker images.
Filter or extract domains from URLs by subdomain level.
Deduplicate a wordlist without sorting so probability order stays intact.
Persist attack-surface files in Elasticsearch and query them later.
Run a JavaScript file between workflow stages.
Upload a file or folder to Azure Blob with a SAS token.
Filter file or folder lines by a fixed string.
Merge five scanner JSON streams into one host-keyed YAML report.
Pull named files from Trickest file storage into a workflow.
Deprecated. Downloaded Trickest workflow node outputs by id.
Named JSON patterns over grep for recon URL triage.
Make JSON greppable.
A human-friendly CLI HTTP client for APIs and servers.
Convert JSON into an HTML table for readable reports.
Cartesian join of two wordlists for fuzzing candidates.
URL path lists from a wordlist for content discovery.
Publish tool output to chat and alerting providers.
OpenAI chat responses from a file and a prompt.
Lightweight TCP port scanner for massdns-resolved hosts.
Prepend one string to each line in a file or folder.
CSS selectors over HTML, the jq counterpart for markup.
Write workflow results into Trickest file storage.
Replace every query-string value across a URL list.
Workflow utility that writes a string to a file artifact.
Append one string to each line in a folder of files.
Start a Trickest workflow run from the command line.
Download outputs from finished Trickest workflow runs.
Extract chosen URL parts from stdin into clean line lists.
Inverse file filter: keep files that lack a given string.
Deduplicate URLs by path and query-string shape.
Non-interactive downloader for HTTP, HTTPS, FTP, and FTPS transfers.
Confirm target-org owns the ranges in a whois-file.
Extract one URL component per run.
A focused Go script that probes 403 Forbidden responses for known bypasses.
Automates OS command injection detection and exploitation.
Crack weak signing secrets on stateless session cookies.
Find Cross-Origin Resource Sharing misconfigurations on a URL list.
Find HTTP response splitting in parameterized URLs.
Username enumeration against OpenSSH via CVE-2018-15473.
Version-based detection of Citrix builds exposed to CVE-2023-3519.
Parameter mining and XSS testing with headless verification.
Subdomain takeover scanner with cloud-zone intake.
Tiny SQLi check for GET and POST parameters on one URL.
Tiny XSS check for GET and POST parameters on one URL.
Automate Local/Remote File Inclusion and directory traversal checks.
Locate public CVE proof-of-concept repositories on GitHub.
Flag potential DOM-based XSS across a URL list.
Timing-based CL.TE and TE.CL desync detection for a URL or URL list.
Decode, forge, crack, and tamper JWTs for auth checks.
Triage reflected special characters on parameterized URLs.
Remote scanner for Log4Shell RCE, CVE-2021-44228.
MongoDB-focused NoSQL injection scanner and injector.
Async open-redirect fuzzer for parameterized URLs.
Python open-redirect and CRLF fuzzer for URLs and URL lists.
Confirm the RSC and Next.js RCE CVEs on a URL or host list.
Offline CLI search across the local Exploit-DB archive of exploits and shellcodes.
HTTP request smuggling and desync tester for a single endpoint.
Detect and exploit SQL injection on authorized web targets.
SSRF and CRLF fuzzer for parameterized URL lists.
Subdomain takeover checks driven by can-i-take-over-xyz response fingerprints.
Detect dangling DNS records and optionally claim them.
Detect and exploit server-side template injection on live parameters.
Host header injection and CORS checks on URL lists.
Parameter XSS analysis with optional blind callbacks.
Map an organization's network ranges from ASN data.
Merge the target's DNS servers with public resolvers into one pool.
Expand one CIDR into one IP per line.
Expand many CIDR ranges from one file.
Validate public DNS resolvers against trusted baselines.
Keep only IPv4 resolvers that match baseline answers.
Node.js TCP connect scanner for a single IP or CIDR.
evilscan wrapped to TCP-scan a whole targets file.
Service fingerprinting for open host:port pairs.
Parallel ICMP echo sweeps for CIDR ranges and host files.
Resolve one ASN to the IP prefixes it announces.
Probe a domain list for working HTTP and HTTPS servers.
A fast and multi-purpose HTTP toolkit that runs multiple probers with reliable, high-throughput results.
Official IPinfo CLI for IP geolocation and ASN lookups.
Expand, aggregate, and slice CIDR ranges into host lists.
Asynchronous SYN port scanner for wide IP ranges; bound runs with --rate and --excludefile.
Asynchronous masscan port sweep with structured JSON output.
A fast and reliable port scanner that enumerates open ports for hosts.
Authenticated network assessment across SMB, LDAP, WinRM, and more.
Simple IP or CIDR sweep for open ports.
Raw-socket SYN scanner for internet-wide port discovery, with optional banners and scripts.
SNMP community-string scanner for host lists.
Print every IP in a range or CIDR, one per line.
Portable shell expansion of IP ranges into host lists.
Port discovery that lists open ports for downstream service detection.
RustScan over a target file, with optional scripting on each open-port hit.
Passive host discovery across multiple search-engine indexes.
Stateless single-packet scanner for large port surveys.
Reflection triage for parameter URLs during recon.
Pattern-based subdomain wordlist generator from known names.
Scan software bills of materials for known-vulnerable dependencies.
Find broken links, missing images, and other dead HTML references.
Signature scanner for exposed files, folders, and services on web roots.
CMS detection and version fingerprinting.
Signature-driven web application scanner.
OWASP Joomla vulnerability scanner for CMS flaws and misconfigurations.
CVE-2025-14847 MongoDB memory disclosure scanner.
Bundled web server checks for dangerous files and outdated software.
Deprecated host-list wrapper for nikto. Prefer the nikto node.
Bypass 403/40X restrictions through smart request manipulation.
YAML template scanner for live hosts; scope runs with tags and severity.
Nuclei vulnerability scan with Markdown export for readable findings.
Modular multi-protocol credential brute forcer with response filtering.
Crawl pages for broken social links that can be hijacked.
Python SSL/TLS scanner for protocols, certs, and named weaknesses.
Opinionated web audit for headers, ports, and TLS.
Opinionated twa web audits, one pass over a domain list.
Fingerprint the WAF in front of a site before active scanning.
Black-box crawler and fuzzer for web app injection classes.
Black-box web app crawler and parameter fuzzer.
WordPress scanner for plugins, themes, users, and known vulns.
WPScan across a file of WordPress URLs.
OWASP ZAP against an API contract, not a crawlable site.
Ordered ZAP jobs from one YAML plan.
Full OWASP ZAP active scan against a target URL.
AST-based security checks for Python source.
Static review of Ruby source for security issues, CVEs, and OWASP risks.
Entropy and rules scan for hardcoded keys and passwords in large file trees.
Git ripper that reconstructs repos even when directory browsing is off.
Report which GitHub repositories use Log4J, and which files reference it.
Detect hardcoded secrets in git repos and plain directories.
Go AST security scanner for credentials, crypto, and injection.
Batch deobfuscate JavaScript folders into readable source.
Scan GitHub orgs and URL responses for leaked secrets.
Rule-based secret scanning across text and full Git history.
Entropy-based secret scan across a Git repository's commit history.
Detects JavaScript and Node library versions with published vulnerabilities.
Regex ruleset scanner for directories and GitHub repositories; matches saved as JSON.
Regex scan of JavaScript for API keys, tokens, JWTs, and similar client-side secrets.
Static analysis with rules that look like the code they match.
Hunt leaked credentials and verify which still work.
Passive DNS records from DNSDumpster.
Passive DNSDumpster host lookup by domain.
Generate lookalike domains and flag registered typosquats.
List public repositories for each GitHub username you already have.
Look up the real IP of a host from its favicon via Shodan.
Email OSINT from public sources, with optional breach checks.
Username search that collects accounts and profile data into one dossier.
OSINT paste-site search for credentials and brand terms.
Find a domain's public files via search engines and extract their metadata.
Bulk-export Shodan banner matches as json.gz.
Search and inspect internet-facing hosts through the Shodan CLI.
Check whether emails and usernames are available, taken, or invalid.
Directory and file brute forcing across many hosts.
A fast web fuzzer written in Go.
ffuf looped over a URL list in one node.
ffuf across a URL list, one results folder.
Folder-output ffuf for a single target.
Host-header fuzzing packaged for vhost discovery.
Recursive HTTP directory and file fuzzer.
Passive archive miner for parameterized URLs on a domain.
Enumerate IIS 8.3 short filenames to recover hidden paths.
Flexible web fuzzer for content, params, and auth.
Hidden parameter discovery by response comparison.
Go-based CRLF injection scanner for URLs and URL lists.
Recover source from sites that leaked their .git directory.
Batch host header injection checks against a URL list.
Find files on web servers that should not be public.
Concurrent subdomain takeover checks against dangling CNAMEs.
DNS existence check for a pre-compiled S3 bucket wordlist.
Normalize mixed S3 bucket references into one address format.
Checks candidate S3 buckets for open permissions and can dump readable contents.
Sweeps a URL list with module-based checks across multiple HTTP methods.
Social Engineering
2 toolsEmail OSINT against breach services and local dumps.
Username checks across social networks with optional CSV export.