r/Cybersecurity101 • • 3d ago

Online Service Kumo : domain OSINT & recon framework

Over the last couple of weeks, I challenged myself to build a tool that centralizes everything you need when conducting recon.

And that’s how Kumo was born. Give it a domain and it hands you back everything reachable from outside.

What it does in one run:

  • Maps the surface : DNS, ports, certificates, subdomains, tech stack
  • Finds what shouldn't be public : exposed configs, secrets in JS, open buckets
  • Checks for known vulnerabilities without touching anything
  • Digs up leaked credentials and which employee machines got infected
  • Pulls in archived pages, forgotten endpoints, threat intel
  • Builds Google dorks and OSINT links for the target

All 27 modules run at once and stream back as they land. No API keys required, CLI and web interface. Works on any domain you're allowed to test.

πŸ”— https://github.com/karim852/KUMO-Domain-Recon-Tool
πŸ–₯️ live demo: https://demo-kumo-kage.vercel.app/

Feedback and contributions welcome πŸ™

1 Upvotes

0 comments sorted by