Skip to content
DnsLister Forum

Where domain hunters compare notes

Kumo : domain OSINT & recon framework

Give it a domain and it hands you back everything reachable from outside.

What it does in one run:

  • Maps the surface : DNS, ports, certificates, subdomains, tech stack
  • Finds what shouldn't be public : exposed configs, secrets in JS, open buckets
  • Checks for known vulnerabilities without touching anything
  • Digs up leaked credentials and which employee machines got infected
  • Pulls in archived pages, forgotten endpoints, threat intel
  • Builds Google dorks and OSINT links for the target

All 27 modules run at once and stream back as they land. No API keys required, CLI and web interface. Works on any domain you're allowed to test.

🔗 https://github.com/karim852/KUMO-Domain-Recon-Tool
🖥️ live demo: https://demo-kumo-kage.vercel.app/

Feedback and contributions welcome 🙏

Source: r/netsecstudents · by /u/k0r1mk

Leave a Reply

Your email address will not be published. Required fields are marked *