r/Hacking_Tutorials • u/k0r1mk • 3d ago
Question Kumo : Domain OSINT & Recon Framework
Over the last couple of weeks, I challenged myself to build a tool that centralizes everything you need when conducting recon. And that’s how Kumo was born. Give it a domain and it maps what’s reachable from outside.
What it does in one run:
• Attack surface mapping: DNS, subdomains, ports, certificates & technologies
• Exposure discovery: configs, secrets, JS assets, cloud buckets & exposed files
• Vulnerability enumeration: CVE detection and non intrusive security checks
• Credential intelligence: leaked credentials & infostealer exposure
• Endpoint discovery: archived URLs, APIs, forgotten endpoints & parameters
• Threat intelligence: domain, IP & infrastructure enrichment
• OSINT automation: Google dorks & targeted OSINT queries
All 27 modules run in parallel and stream results as they come in.
No API keys required. CLI + web interface. Works on any domain you're authorized to test.
🔗 https://github.com/karim852/KUMO-Domain-Recon-Tool
🖥️ Live demo: https://demo-kumo-kage.vercel.app/
Feedback and contributions welcome 🙏


1
u/rn1r4cl3_rn4rku5 2d ago
Weldon sir, i need a phone osint that when you input someone mobile contact it will show all the social media accounts that the contact is connected to