# Tools, OSINT & Open Source

## 🔎 OSINT & Data Discovery Tools

These tools are useful for uncovering publicly accessible information, exposed data, malware indicators, code leaks, documents, and file indexing across the internet.

---

### 🔍 Privacy Search Engines

- **[DuckDuckGo](https://start.duckduckgo.com/)** – Privacy-focused search engine that doesn’t track users.  
- **[Startpage](https://startpage.com/)** – Google results with privacy protection and no tracking.  

---

### 🗃️ Paste, Code, and Source Scanning

- **[psbdmp](https://psbdmp.ws/)** – Largest archive of leaked {paste} dumps from pastebin-style sites.  
- **[Search-Pastebin](https://search-pastebin.vercel.app/)** – Google CSE-powered meta-search across 33 paste sites.  
- **[RedHuntlabs Online IDE Search](https://redhuntlabs.com/online-ide-search/)** – Search keywords across online IDEs, code sharing platforms, and pastebins.  
- **[NerdyData](https://www.nerdydata.com/reports/new)** – Find websites using specific technologies or HTML/JavaScript code.  
- **[Publicwww](https://publicwww.com/)** – Source code search engine indexing 480+ million pages.  
- **[CybDetective Code Search](https://cybdetective.com/codesearch.html)** – Custom search across 20+ code hosting platforms.  
- **[grep.app](https://grep.app/)** – Fast regex-capable search engine for 500k+ Git repos.  
- **[searchcode](https://searchcode.com/)** – Search 75 billion lines of code from 40 million public projects.  

---

### 📁 File & Directory Indexing

- **[Open Directory Search Tool](https://opendirsearch.abifog.com/)** – Search files in unprotected open directories.  
- **[Mamont FTP](https://www.mmnt.ru/int/)** – Largest public FTP search engine.  
- **[NAPALM FTP Indexer](https://www.searchftps.net/)** – Index of over 894 million FTP files across thousands of servers.  
- **[DeDigger](https://www.dedigger.com/#gsc.tab=0)** – Discover publicly shared files in Google Drive.  
- **[UVRX](http://uvrx.com/)** – Search files from older hosting sites (e.g., Mega, Mediafire, Zshare).  

---

### 📚 Document & Content Discovery

- **[PDF Drive](https://www.pdfdrive.com/)** – Download from a library of over 75 million free PDFs.  
- **[SlideShare](https://www.slideshare.net/)** – Explore millions of user-submitted presentations.  
- **[Scribd](https://www.scribd.com/)** – Document repository with 195+ million user-uploaded files.  

---

### 🧪 Threat Intelligence & IOC Lookup

- **[VirusTotal](https://www.virustotal.com/gui/home/search)** – Multi-engine scanner and IOC search platform for files, hashes, domains, and URLs.  
- **[Hybrid Analysis](https://www.hybrid-analysis.com/)** – Free malware sandbox that performs hybrid static/dynamic analysis.  
- **[Sucuri SiteCheck](https://sitecheck.sucuri.net/)** – Website malware and security scanner.  
- **[URLhaus](https://urlhaus.abuse.ch/)** – Malicious URL tracker and database.  
- **[Feodo Tracker](https://feodotracker.abuse.ch/)** – Monitor and block IPs related to Feodo/Bugat/Dridex botnets.  
- **[SSL Blacklist](https://sslbl.abuse.ch/)** – Collection of blacklisted SSL certificates and JA3 fingerprints.  
- **[MalwareBazaar](https://bazaar.abuse.ch/)** – Repository for sharing malware samples.  
- **[Talos Reputation Center](https://www.talosintelligence.com/reputation_center)** – IP, domain, and file reputation check.  
- **[PaloAlto URL Filtering](https://urlfiltering.paloaltonetworks.com/)** – Link classification and reputation check.  
- **[OTX AlienVault](https://otx.alienvault.com/)** – Threat sharing platform with global IOC and pulse feeds.  
- **[URLScan](https://urlscan.io/)** – Scan and analyze websites in a sandboxed environment.  
- **[McAfee Threat Center](https://www.mcafee.com/enterprise/en-us/threat-center.html)** – Threat intelligence and malware information.  
- **[National Vulnerability Database (NVD)](https://nvd.nist.gov/)** – US government vulnerability database with CVSS scores.  
- **[CVE Database](https://cve.mitre.org/)** – Public list of common vulnerabilities and exposures.  
- **[Website Reputation Checker (URLVoid)](https://www.urlvoid.com/)** – Checks domain/IP reputation using multiple sources.  
- **[Google Safe Browsing Status](https://transparencyreport.google.com/safe-browsing/search)** – Checks if a site is flagged by Google Safe Browsing.
- **[Looky Luu](https://lookyloo.circl.lu/capture)** - Online Sandbox for Domain Checks
- **[URLscan](https://urlscan.io/)** - Online Sandbox for Domain Checks

---

### 🌐 Network, Routing, and Metadata Tools

- **[Nmap](https://nmap.org/)** – Network scanner and host discovery tool.  
- **[Yersinia](https://sectools.org/tool/yersinia/)** – Penetration testing tool for attacking network protocols.  
- **[Passive OS Fingerprinter (p0f)](https://lcamtuf.coredump.cx/p0f3/)** – Passive network OS fingerprinting tool.  

---

### 🛡️ Offensive Security & Exploitation

- **[Kali Linux](https://www.kali.org/)** – Penetration testing and security auditing Linux distribution.  
- **[Metasploit](https://www.metasploit.com/)** – Exploit development and penetration testing framework.  
- **[Aircrack-ng](https://www.aircrack-ng.org/)** – Wireless network security auditing tool.  
- **[Powerfuzzer](https://www.powerfuzzer.com/)** – Automated web application vulnerability scanner.  
- **[ShellNoob](https://github.com/reyammer/shellnoob)** – Shellcode writing toolkit.  
- **[Backdoor Factory](https://github.com/secretsquirrel/the-backdoor-factory)** – Patch binaries with custom backdoors.  
- **[Capstone Engine](https://www.capstone-engine.org/)** – Multi-architecture disassembly framework.  

---

### 🧰 Analysis & Development Utilities

- **[CyberChef](https://gchq.github.io/CyberChef/)** – Web-based data transformation and analysis toolkit.  
- **[CyberChef (Offline)](file:///opt/cyberchef/index.html)** – Local instance for offline data analysis and transformation.  
- **[JavaScript Beautifier](https://beautifier.io/)** – Formats and beautifies JavaScript code for readability.  
- **[UnPacker](https://matthewfl.com/unPacker.html)** – JavaScript deobfuscation/unpacking tool.  
- **[Awesome Malware Analysis](https://github.com/rshipp/awesome-malware-analysis/blob/main/README.md)** – Curated list of malware analysis tools and resources.  

---

### 📰 News & Security Feeds

- **[Inside-IT](https://www.inside-it.ch/de/find/)** – Swiss IT and tech news.  
- **[Heise Security – 7-Tage-News](https://www.heise.de/security/news/7_tage_news/)** – German IT security news overview (last 7 days).  
- **[CERT-EU News Monitor](https://cert.europa.eu/cert/filteredition/en/CERT-LatestNews.html)** – EU cybersecurity news and advisories.  

---

### 📬 Disposable Email Services

- **[Trash-Mail](https://www.trash-mail.com/posteingang/)** – Temporary disposable email inbox.  
- **[Mailinator](https://www.mailinator.com/)** – Public temporary email service.  

---

### 🖥️ Internal/Local Resources

- **[Sandbox](https://sandbox/)** – Likely internal sandbox environment for testing malware or files.  
- **[DPI (NetWitness)](https://netwitness/)** – Network analysis and deep packet inspection tool (internal link).  
---