GitHub - guelfoweb/knock: Knock Subdomain Scan

一个 Python 的子域扫描程序

Knock Subdomain Scan - 图1

使用

  1. usage: knockpy [-h] [-v] [--no-local] [--no-remote] [--no-scan] [--no-http]
  2. [--no-http-code CODE [CODE ...]] [--dns DNS] [-w WORDLIST]
  3. [-o FOLDER] [-t SEC] [-th NUM] [--silent [{False,json,json-pretty,csv}]]
  4. domain
  5. --------------------------------------------------------------------------------
  6. * SCAN
  7. full scan: knockpy domain.com
  8. quick scan: knockpy domain.com --no-local
  9. faster scan: knockpy domain.com --no-local --no-http
  10. ignore code: knockpy domain.com --no-http-code 404 500 530
  11. silent mode: knockpy domain.com --silent
  12. * SUBDOMAINS
  13. show recon: knockpy domain.com --no-local --no-scan
  14. * REPORT
  15. show report: knockpy --report knockpy_report/domain.com_yyyy_mm_dd_hh_mm_ss.json
  16. plot report: knockpy --plot knockpy_report/domain.com_yyyy_mm_dd_hh_mm_ss.json
  17. csv report: knockpy --csv knockpy_report/domain.com_yyyy_mm_dd_hh_mm_ss.json
  18. --------------------------------------------------------------------------------
  19. positional arguments:
  20. domain target to scan
  21. optional arguments:
  22. -h, --help show this help message and exit
  23. -v, --version show program's version number and exit
  24. --no-local local wordlist ignore
  25. --no-remote remote wordlist ignore
  26. --no-scan scanning ignore, show wordlist and exit
  27. --no-http http requests ignore
  28. --no-http-code CODE [CODE ...]
  29. http code list to ignore
  30. --dns DNS use custom DNS ex. 8.8.8.8
  31. -w WORDLIST wordlist file to import
  32. -o FOLDER report folder to store json results
  33. -t SEC timeout in seconds
  34. -th NUM threads num
  35. --silent [{False,json,json-pretty,csv}]
  36. silent or quiet mode, default: False

Full scan

  1. $ knockpy domain.com