Use case: geolocate an IP or domain and identify the owning network (ASN / org) for scoping and attribution.
Use case: enumerate A / AAAA / MX / NS / TXT / CNAME records to map infrastructure and mail handlers.
Use case: passively discover subdomains from certificate-transparency logs — no packets touch the target.
Use case: check whether an email address appears in known public data breaches (requires HIBP API key above).
Use case: pull Shodan's passive host profile — open ports, running services, org and ISP (requires Shodan API key above).
Use case: retrieve domain registration data — registrar, creation / expiry dates, nameservers and status codes.
Use case: pivot a username across social platforms. No public API exists, so this generates direct check links.
Use case: active service & version detection against an authorized target. Runs locally — command is generated for your terminal.
Requires nmap installed locally. Only scan hosts you own or have written permission to test.
Use case: extract hidden metadata (GPS, device, author, timestamps) from images and documents.
Requires exiftool installed locally. Point it at a file on your machine.
Use case: authorized phishing-simulation and social-engineering exercises (credential-harvester site clones).
For authorized security-awareness testing only.
Use case: run and track internal phishing-awareness campaigns with landing pages, templates and reporting.
For authorized security-awareness testing only.