Sign inSign up

ctdc/spiderfoot

By ctdc

Updated about 6 years ago

Spiderfoot docker container

Image
9

100K+

ctdc/spiderfoot repository overview

SpiderFoot

Travis CI Docker Pulls Docker Stars Docker Build

ABOUT

SpiderFoot is an open source intelligence (OSINT) automation tool. It integrates with just about every data source available and utilises a range of methods for data analysis, making that data easy to navigate.

SpiderFoot has an embedded web-server for providing a clean and intuitive web-based interface but can also be used completely via the command-line. It's written in Python 3 and GPL-licensed.

FEATURES
  • Web based UI or CLI
  • Over 190 modules (see below)
  • Python 3
  • CSV/JSON/GEXF export
  • API key export/import
  • SQLite back-end for custom querying
  • Highly configurable
  • Fully documented
  • Visualisations
  • TOR integration for dark web searching
  • Dockerfile for Docker-based deployments
  • Can call other tools like DNSTwist, Whatweb, Nmap and CMSeeK
  • Actively developed since 2012!
USES

SpiderFoot can be used offensively (e.g. in a red team exercise or penetration test) for reconnaissance of your target or defensively to gather information about what you or your organisation might have exposed over the Internet.

You can target the following entities in a SpiderFoot scan:

  • IP address
  • Domain/sub-domain name
  • Hostname
  • Network subnet (CIDR)
  • ASN
  • E-mail address
  • Phone number
  • Username
  • Person's name

SpiderFoot's 190+ modules feed each other in a publisher/subscriber model to ensure maximum data extraction to do things like:

INSTALLING & RUNNING

To install and run SpiderFoot, you need at least Python 3.6 and a number of Python libraries which you can install with pip. We recommend you install a packaged release since master will often have bleeding edge features and modules that aren't fully tested.

Stable build (packaged release):
$ wget https://github.com/smicallef/spiderfoot/archive/v3.2.tar.gz
$ tar zxvf v3.2.tar.gz
$ cd spiderfoot
~/spiderfoot$ pip3 install -r requirements.txt
~/spiderfoot$ python3 ./sf.py -l 127.0.0.1:5001
Development build (cloning git master branch):
$ git clone https://github.com/smicallef/spiderfoot.git
$ cd spiderfoot
$ pip3 install -r requirements.txt
~/spiderfoot$ python3 ./sf.py -l 127.0.0.1:5001

Check out the documentation and our asciinema videos for more tutorials.

MODULES / INTEGRATIONS

SpiderFoot has over 190 modules, most of which don't require API keys, and many of those that do require API keys have a free tier.

NameDescriptionLink
abuse.chCheck if a host/domain, IP or netblock is malicious according to abuse.ch.https://www.abuse.ch
AbuseIPDBCheck if an IP address is malicious according to AbuseIPDB.com.https://www.abuseipdb.com
Account FinderLook for possible associated accounts on nearly 200 websites like Ebay, Slashdot, reddit, etc.
AdBlock CheckCheck if linked pages would be blocked by AdBlock Plus.https://adblockplus.org/
AhmiaSearch Tor 'Ahmia' search engine for mentions of the target domain.https://ahmia.fi/
AlienVault IP ReputationCheck if an IP or netblock is malicious according to the AlienVault IP Reputation database.https://cybersecurity.att.com/
AlienVault OTXObtain information from AlienVault Open Threat Exchange (OTX)https://otx.alienvault.com/
Amazon S3 Bucket FinderSearch for potential Amazon S3 buckets associated with the target and attempt to list their contents.https://aws.amazon.com/s3/
api.recon.devSearch api.recon.dev for subdomains.
ApilitySearch Apility API for IP address and domain reputation.https://auth0.com/signals
Archive.orgIdentifies historic versions of interesting files/pages from the Wayback Machine.https://archive.org/
ARINQueries ARIN registry for contact information.https://www.arin.net/
Azure Blob FinderSearch for potential Azure blobs associated with the target and attempt to list their contents.https://azure.microsoft.com/en-in/services/storage/blobs/
Bad PacketsObtain information about any malicious activities involving IP addresses foundhttps://badpackets.net
badips.comCheck if an IP address is malicious according to BadIPs.com.https://www.badips.com/
Bambenek C&C ListCheck if a host/domain or IP appears on Bambenek Consulting's C&C tracker lists.http://www.bambenekconsulting.com/
Base64 DecoderIdentify Base64-encoded strings in any content and URLs, often revealing interesting hidden information.
BGPViewObtain network information from BGPView API.https://bgpview.io/
Binary String ExtractorAttempt to identify strings in binary content.
BinaryEdgeObtain information from BinaryEdge.io's Internet scanning systems about breaches, vulerabilities, torrents and passive DNS.https://www.binaryedge.io/
Bing (Shared IPs)Search Bing for hosts sharing the same IP.https://www.bing.com/
BingObtain information from bing to identify sub-domains and links.https://www.bing.com/
Bitcoin FinderIdentify bitcoin addresses in scraped webpages.
BlockchainQueries blockchain.info to find the balance of identified bitcoin wallet addresses.https://www.blockchain.com/
blocklist.deCheck if a netblock or IP is malicious according to blocklist.de.http://www.blocklist.de/en/index.html
BotScoutSearches botscout.com's database of spam-bot IPs and e-mail addresses.http://botscout.com/
botvrij.euCheck if a domain is malicious according to botvrij.eu.
BuiltWithQuery BuiltWith.com's Domain API for information about your target's web technology stack, e-mail addresses and more.https://builtwith.com/
CallerNameLookup US phone number location and reputation information.http://callername.com/
CensysObtain information from Censys.iohttps://censys.io/
Certificate TransparencyGather hostnames from historical certificates in crt.sh.https://crt.sh/
CINS Army ListCheck if a netblock or IP address is malicious according to cinsscore.com's Army List.
CIRCL.LUObtain information from CIRCL.LU's Passive DNS and Passive SSL databases.https://www.circl.lu/
Cleanbrowsing.orgCheck if a host would be blocked by Cleanbrowsing.org DNShttps://cleanbrowsing.org/
CleanTalk Spam ListCheck if a netblock or IP address is on CleanTalk.org's spam IP list.https://cleantalk.org
ClearbitCheck for names, addresses, domains and more based on lookups of e-mail addresses on clearbit.com.https://clearbit.com/
CloudFlare Malware DNSCheck if a host would be blocked by CloudFlare Malware-blocking DNShttps://www.cloudflare.com/
CoinBlocker ListsCheck if a host/domain or IP appears on CoinBlocker lists.https://zerodot1.gitlab.io/CoinBlockerListsWeb/
CommonCrawlSearches for URLs found through CommonCrawl.org.http://commoncrawl.org/
ComodoCheck if a host would be blocked by Comodo DNShttps://www.comodo.com/secure-dns/
Company Name ExtractorIdentify company names in any obtained data.
Cookie ExtractorExtract Cookies from HTTP headers.
Country Name ExtractorIdentify country names in any obtained data.
Credit Card Number ExtractorIdentify Credit Card Numbers in any data
Crobat APISearch Crobat API for subdomains.
Cross-ReferencerIdentify whether other domains are associated ('Affiliates') of the target.
Custom Threat FeedCheck if a host/domain, netblock, ASN or IP is malicious according to your custom feed.
cybercrime-tracker.netCheck if a host/domain or IP is malicious according to cybercrime-tracker.net.http://cybercrime-tracker.net/
DarksearchSearch the Darksearch.io Tor search engine for mentions of the target domain.https://darksearch.io/
Digital Ocean Space FinderSearch for potential Digital Ocean Spaces associated with the target and attempt to list their contents.https://www.digitalocean.com/products/spaces/
DNS Brute-forcerAttempts to identify hostnames through brute-forcing common names and iterations.
DNS Common SRVAttempts to identify hostnames through common SRV.
DNS Look-asideAttempt to reverse-resolve the IP addresses next to your target to see if they are related.
DNS Raw RecordsRetrieves raw DNS records such as MX, TXT and others.
DNS ResolverResolves Hosts and IP Addresses identified, also extracted from raw content.
DNS Zone TransferAttempts to perform a full DNS zone transfer.
DNSGrepObtain Passive DNS information from Rapid7 Sonar Project using DNSGrep API.https://opendata.rapid7.com/
DroneBLQuery the DroneBL database for open relays, open proxies, vulnerable servers, etc.https://dronebl.org/
DuckDuckGoQuery DuckDuckGo's API for descriptive information about your target.https://duckduckgo.com/
E-Mail Address ExtractorIdentify e-mail addresses in any obtained data.
EmailCrawlrSearch EmailCrawlr for email addresses and phone numbers associated with a domain.https://emailcrawlr.com/
EmailFormatLook up e-mail addresses on email-format.com.https://www.email-format.com/
EmailRepSearch EmailRep.io for email address reputation.https://emailrep.io/
Emerging ThreatsCheck if a netblock or IP is malicious according to emergingthreats.net.https://rules.emergingthreats.net/
Error String ExtractorIdentify common error messages in content like SQL errors, etc.
Ethereum Address ExtractorIdentify ethereum addresses in scraped webpages.
F-Secure Riddler.ioObtain network information from F-Secure Riddler.io API.https://riddler.io/
File Metadata ExtractorExtracts meta data from documents and images.
FlickrSearch Flickr for domains, URLs and emails related to the specified domain.https://www.flickr.com/
Fortiguard.comCheck if an IP is malicious according to Fortiguard.com.https://fortiguard.com/
FraudguardObtain threat information from Fraudguard.iohttps://fraudguard.io/
Fringe ProjectObtain network information from Fringe Project API.https://fringeproject.com/
FullContactGather domain and e-mail information from fullcontact.com.https://www.fullcontact.com
GithubIdentify associated public code repositories on Github.https://github.com/
Google MapsIdentifies potential physical addresses and latitude/longitude coordinates.https://cloud.google.com/maps-platform/
Google Object Storage FinderSearch for potential Google Object Storage buckets associated with the target and attempt to list their contents.https://cloud.google.com/storage
Google SafeBrowsingCheck if the URL is included on any of the Safe Browsing lists.https://developers.google.com/safe-browsing/v4/lookup-api
GoogleObtain information from the Google Custom Search API to identify sub-domains and links.https://developers.google.com/custom-search
GravatarRetrieve user information from Gravatar API.https://secure.gravatar.com/
GreensnowCheck if a netblock or IP address is malicious according to greensnow.co.https://greensnow.co/
grep.appSearch grep.app API for links and emails related to the specified domain.https://grep.app/
GreynoiseObtain information from Greynoise.io's Enterprise API.https://greynoise.io/
HackerOne (Unofficial)Check external vulnerability scanning/reporting service h1.nobbd.de to see if the target is listed.http://www.nobbd.de/
HackerTargetSearch HackerTarget.com for hosts sharing the same IP.https://hackertarget.com/
Hash ExtractorIdentify MD5 and SHA hashes in web content, files and more.
HaveIBeenPwnedCheck HaveIBeenPwned.com for hacked e-mail addresses identified in breaches.https://haveibeenpwned.com/
Honeypot CheckerQuery the projecthoneypot.org database for entries.https://www.projecthoneypot.org/
Host.ioObtain information about domain names from host.io.https://host.io
Hosting Provider IdentifierFind out if any IP addresses identified fall within known 3rd party hosting ranges, e.g. Amazon, Azure, etc.
Human Name ExtractorAttempt to identify human names in fetched content.
Hunter.ioCheck for e-mail addresses and names on hunter.io.https://hunter.io/
Hybrid AnalysisSearch Hybrid Analysis for domains and URLs related to the target.https://www.hybrid-analysis.com
IBAN Number ExtractorIdentify IBAN Numbers in any data
Iknowwhatyoudownload.comCheck iknowwhatyoudownload.com for IP addresses that have been using BitTorrent.https://iknowwhatyoudownload.com/en/peer/
InstagramGather information from Instagram profiles.https://www.instagram.com/
IntelligenceXObtain information from IntelligenceX about identified IP addresses, domains, e-mail addresses and phone numbers.https://intelx.io/
Interesting File FinderIdentifies potential files of interest, e.g. office documents, zip files.
Internet Storm CenterCheck if an IP is malicious according to SANS ISC.https://isc.sans.edu
IPInfo.ioIdentifies the physical location of IP addresses identified using ipinfo.io.https://ipinfo.io
ipstackIdentifies the physical location of IP addresses identified using ipstack.com.https://ipstack.com/
JsonWHOIS.comSearch JsonWHOIS.com for WHOIS records associated with a domain.https://jsonwhois.com
Junk File FinderLooks for old/temporary and other similar files.
KeybaseObtain additional information about target usernamehttps://keybase.io/
Leak-LookupSearches Leak-Lookup.com's database of breaches.https://leak-lookup.com/
LeakIXSearch LeakIX for host data leaks, open ports, software and geoip.https://leakix.net/
MaltiverseObtain information about any malicious activities involving IP addresseshttps://maltiverse.com
malwaredomainlist.comCheck if a host/domain, IP or netblock is malicious according to malwaredomainlist.com.http://www.malwaredomainlist.com/
malwaredomains.comCheck if a host/domain is malicious according to malwaredomains.com.http://www.malwaredomains.com/
MalwarePatrolSearches malwarepatrol.net's database of malicious URLs/IPs.https://www.malwarepatrol.net/
MetaDefenderSearch MetaDefender API for IP address and domain IP reputation.https://metadefender.opswat.com/
Mnemonic PassiveDNSObtain Passive DNS information from PassiveDNS.mnemonic.no.https://www.mnemonic.no
multiproxy.org Open ProxiesCheck if an IP is an open proxy according to multiproxy.org' open proxy list.https://multiproxy.org/
MySpaceGather username and location from MySpace.com profiles.https://myspace.com/
NetworksDBSearch NetworksDB.io API for IP address and domain information.https://networksdb.io/
NeutrinoAPISearch NeutrinoAPI for IP address info and check IP reputation.https://www.neutrinoapi.com/
Norton ConnectSafeCheck if a host would be blocked by Norton ConnectSafe DNS
numverifyLookup phone number location and carrier information from numverify.com.http://numverify.com/
Onion.linkSearch Tor 'Onion City' search engine for mentions of the target domain.https://onion.link/
Onionsearchengine.comSearch Tor onionsearchengine.com for mentions of the target domain.https://as.onionsearchengine.com
OnypheCheck Onyphe data (threat list, geo-location, pastries, vulnerabilities) about a given IP.https://www.onyphe.io
Open Bug BountyCheck external vulnerability scanning/reporting service openbugbounty.org to see if the target is listed.https://www.openbugbounty.org/
Open Passive DNS DatabaseObtain passive DNS information from pdns.daloo.de Open passive DNS database.http://pdns.daloo.de/
OpenCorporatesLook up company information from OpenCorporates.https://opencorporates.com
OpenDNSCheck if a host would be blocked by OpenDNS DNShttps://www.opendns.com/
OpenPhishCheck if a host/domain is malicious according to OpenPhish.com.https://openphish.com/
OpenStreetMapRetrieves latitude/longitude coordinates for physical addresses from OpenStreetMap API.https://www.openstreetmap.org/
Page InformationObtain information about web pages (do they take passwords, do they contain forms, etc.)
PasteBinPasteBin scraping (via Google) to identify related content.https://pastebin.com/
PGP Key ServersLook up e-mail addresses in PGP public key servers.
PhishStatsDetermine if an IP Address is malicioushttps://phishstats.info/
PhishTankCheck if a host/domain is malicious according to PhishTank.https://phishtank.com/
Phone Number ExtractorIdentify phone numbers in scraped webpages.
Port Scanner - TCPScans for commonly open TCP ports on Internet-facing systems.
PsbdmpCheck psbdmp.cc (PasteBin Dump) for potentially hacked e-mails and domains.https://psbdmp.cc/
PulsediveObtain information from Pulsedive's API.https://pulsedive.com/
Quad9Check if a host would be blocked by Quad9https://quad9.net/
RIPEQueries the RIPE registry (includes ARIN data) to identify netblocks and other info.https://www.ripe.net/
RiskIQObtain information from RiskIQ's (formerly PassiveTotal) Passive DNS and Passive SSL databases.https://community.riskiq.com/
RobtexSearch Robtex.com for hosts sharing the same IP.https://www.robtex.com/
ScyllaGather breach data from Scylla API.https://scylla.sh/
SecurityTrailsObtain Passive DNS and other information from SecurityTrailshttps://securitytrails.com/
SHODANObtain information from SHODAN about identified IP addresses.https://www.shodan.io/
Similar Domain FinderSearch various sources to identify similar looking domain names, for instance squatted domains.
SkymemLook up e-mail addresses on Skymem.http://www.skymem.info/
SlideShareGather name and location from SlideShare profiles.https://www.slideshare.net
SnovGather available email IDs from identified domainshttps://snov.io/
Social Media Profile FinderTries to discover the social media profiles for human names identified.https://developers.google.com/custom-search
Social Network IdentifierIdentify presence on social media networks such as LinkedIn, Twitter and others.
SORBSQuery the SORBS database for open relays, open proxies, vulnerable servers, etc.http://www.sorbs.net/
SpamCopQuery various spamcop databases for open relays, open proxies, vulnerable servers, etc.https://www.spamcop.net/
SpamhausQuery the Spamhaus databases for open relays, open proxies, vulnerable servers, etc.https://www.spamhaus.org/
spur.usObtain information about any malicious activities involving IP addresses foundhttps://spur.us/
SpyOnWebSearch SpyOnWeb for hosts sharing the same IP address, Google Analytics code, or Google Adsense code.http://spyonweb.com/
SpyseSpiderFoot plug-in to search Spyse API for IP address and domain information.https://spyse.com
SSL Certificate AnalyzerGather information about SSL certificates used by the target's HTTPS sites.
Strange Header IdentifierObtain non-standard HTTP headers returned by web servers.
Subdomain Takeover CheckerCheck if affiliated subdomains are vulnerable to takeover.
Talos IntelligenceCheck if a netblock or IP is malicious according to talosintelligence.com.https://talosintelligence.com/
ThreatCrowdObtain information from ThreatCrowd about identified IP addresses, domains and e-mail addresses.https://www.threatcrowd.org
ThreatMinerObtain information from ThreatMiner's database for passive DNS and threat intelligence.https://www.threatminer.org/
TLD SearcherSearch all Internet TLDs for domains with the same name as the target (this can be very slow.)
Tool - CMSeeKIdentify what Content Management System (CMS) might be used.
Tool - DNSTwistIdentify bit-squatting, typo and other similar domains to the target using a local DNSTwist installation.
Tool - NmapIdentify what Operating System might be used.
Tool - WhatWebIdentify what software is in use on the specified website.
TOR Exit NodesCheck if an IP or netblock appears on the torproject.org exit node list.
TORCHSearch Tor 'TORCH' search engin

Tag summary

Content type

Image

Digest

Size

59.8 MB

Last updated

about 6 years ago

docker pull ctdc/spiderfoot