List of Modules

June 29, 2026 ยท View on GitHub

ModuleTypeNeeds API KeyDescriptionFlagsConsumed EventsProduced EventsAuthorCreated Date
ajaxproscanNoCheck for potentially vulnerable Ajaxpro instancesactive, safe, web-heavyHTTP_RESPONSE, URLFINDING, TECHNOLOGY@liquidsec2024-01-18
aspnet_bin_exposurescanNoCheck for ASP.NET Security Feature Bypasses (CVE-2023-36899 and CVE-2023-36560)active, safe, web-heavyURLFINDING@liquidsec2025-01-28
baddnsscanNoCheck hosts for domain/subdomain takeoversactive, baddns, cloud-enum, safe, subdomain-hijack, webDNS_NAME, DNS_NAME_UNRESOLVEDFINDING@liquidsec2024-01-18
baddns_directscanNoCheck for unusual subdomain / service takeover edge cases that require direct detectionactive, baddns, cloud-enum, safe, subdomain-enumSTORAGE_BUCKET, URLFINDING@liquidsec2024-01-29
baddns_zonescanNoCheck hosts for DNS zone transfers and NSEC walksactive, baddns, cloud-enum, safe, subdomain-enumDNS_NAMEFINDING@liquidsec2024-01-29
badsecretsscanNoLibrary for detecting known or weak secrets across many web frameworksactive, safe, webHTTP_RESPONSEFINDING, TECHNOLOGY@liquidsec2022-11-19
bucket_amazonscanNoCheck for S3 buckets related to targetactive, cloud-enum, safe, webDNS_NAME, STORAGE_BUCKETFINDING, STORAGE_BUCKET@TheTechromancer2022-11-04
bucket_digitaloceanscanNoCheck for DigitalOcean spaces related to targetactive, cloud-enum, safe, slow, web-heavyDNS_NAME, STORAGE_BUCKETFINDING, STORAGE_BUCKET@TheTechromancer2022-11-08
bucket_firebasescanNoCheck for open Firebase databases related to targetactive, cloud-enum, safe, webDNS_NAME, STORAGE_BUCKETFINDING, STORAGE_BUCKET@TheTechromancer2023-03-20
bucket_googlescanNoCheck for Google object storage related to targetactive, cloud-enum, safe, webDNS_NAME, STORAGE_BUCKETFINDING, STORAGE_BUCKET@TheTechromancer2022-11-04
bucket_hetznerscanNoCheck for Hetzner Object Storage buckets related to targetactive, cloud-enum, safe, slow, web-heavyDNS_NAME, STORAGE_BUCKETFINDING, STORAGE_BUCKET@ChrisJr4042026-05-04
bucket_microsoftscanNoCheck for Azure storage blobs related to targetactive, cloud-enum, safe, webDNS_NAME, STORAGE_BUCKETFINDING, STORAGE_BUCKET@TheTechromancer2022-11-04
bypass403scanNoCheck 403 pages for common bypassesactive, loud, web-heavyURLFINDING@liquidsec2022-07-05
dnsbrutescanNoBrute-force subdomains with massdns + static wordlistactive, loud, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2024-04-24
dnsbrute_mutationsscanNoBrute-force subdomains with massdns + target-specific mutationsactive, loud, slow, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2024-04-25
dnscommonsrvscanNoCheck for common SRV recordsactive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2022-05-15
dotnetnukescanNoScan for critical DotNetNuke (DNN) vulnerabilitiesactive, invasive, loud, web-heavyHTTP_RESPONSEFINDING, TECHNOLOGY@liquidsec2023-11-21
filedownloadscanNoDownload common filetypes such as PDF, DOCX, PPTX, etc.active, download, safe, webHTTP_RESPONSE, URL_UNVERIFIEDFILESYSTEM@TheTechromancer2023-10-11
fingerprintxscanNoFingerprint exposed services like RDP, SSH, MySQL, etc.active, safe, service-enum, slowOPEN_TCP_PORTPROTOCOL, URL_UNVERIFIED@TheTechromancer2023-01-30
generic_ssrfscanNoCheck for generic SSRFsactive, invasive, web-heavyURLFINDING@liquidsec2022-07-30
gitscanNoCheck for exposed .git repositoriesactive, code-enum, safe, webURLCODE_REPOSITORY, FINDING@TheTechromancer2023-05-30
gitlab_comscanNoEnumerate GitLab SaaS (gitlab.com/org) for projects and groupsactive, code-enum, safeSOCIALCODE_REPOSITORY@TheTechromancer2024-03-11
gitlab_onpremscanNoDetect self-hosted GitLab instances and query them for repositoriesactive, code-enum, safeHTTP_RESPONSE, SOCIAL, TECHNOLOGYCODE_REPOSITORY, FINDING, SOCIAL, TECHNOLOGY@TheTechromancer2024-03-11
gowitnessscanNoTake screenshots of webpagesactive, safe, web-screenshotsSOCIAL, URLTECHNOLOGY, URL, URL_UNVERIFIED, WEBSCREENSHOT@TheTechromancer2022-07-08
graphql_introspectionscanNoPerform GraphQL introspection on a targetactive, safe, webURLFINDING@mukesh-dream112025-07-01
host_headerscanNoTry common HTTP Host header spoofing techniquesactive, loud, web-heavyHTTP_RESPONSEFINDING@liquidsec2022-07-27
httpscanNoVisit webpages using blasthttp (native Rust HTTP engine)active, cloud-enum, safe, social-enum, subdomain-enum, webOPEN_TCP_PORT, URL, URL_UNVERIFIEDHTTP_RESPONSE, URL@liquidsec2026-03-08
huntscanNoWatch for commonly-exploitable HTTP parametersactive, safe, web-heavyWEB_PARAMETERFINDING@liquidsec2022-07-20
iis_shortnamesscanNoCheck for IIS shortname vulnerabilityactive, iis-shortnames, loud, webURLURL_HINT@liquidsec2022-04-15
legbascanNoCredential bruteforcing supporting various services.active, invasive, loudPROTOCOLFINDING@christianfl, @fuzikowski2025-07-18
lightfuzzscanNoBBOT's DAST module โ€” lightly fuzz web parameters discovered during recon for common vulnerability classesactive, invasive, loud, web-heavyURL, WEB_PARAMETERFINDING, HTTP_RESPONSE@liquidsec2024-06-28
medusascanNoMedusa SNMP bruteforcing with v1, v2c and R/W check.active, invasive, loudPROTOCOLFINDING@christianfl2025-05-16
newslettersscanNoSearches for Newsletter Submission Entry Fields on Websitesactive, safeHTTP_RESPONSEFINDING@stryker2k22024-02-02
ntlmscanNoWatch for HTTP endpoints that support NTLM authenticationactive, safe, webHTTP_RESPONSE, URLDNS_NAME, FINDING@liquidsec2022-07-25
nucleiscanNoFast and customisable vulnerability scanneractive, invasive, loudURLFINDING, TECHNOLOGY@TheTechromancer2022-03-12
oauthscanNoEnumerate OAUTH and OpenID Connect servicesactive, affiliates, cloud-enum, safe, subdomain-enum, webDNS_NAME, URL_UNVERIFIEDDNS_NAME@TheTechromancer2023-07-12
paramminer_cookiesscanNoSmart brute-force to check for common HTTP cookie parametersactive, loud, slow, web-paramminerHTTP_RESPONSE, WEB_PARAMETERWEB_PARAMETER@liquidsec2022-06-27
paramminer_getparamsscanNoUse smart brute-force to check for common HTTP GET parametersactive, loud, slow, web-paramminerHTTP_RESPONSE, WEB_PARAMETERWEB_PARAMETER@liquidsec2022-06-28
paramminer_headersscanNoUse smart brute-force to check for common HTTP header parametersactive, loud, slow, web-paramminerHTTP_RESPONSE, WEB_PARAMETERWEB_PARAMETER@liquidsec2022-04-15
portscanscanNoPort scan with masscan. By default, scans top 100 ports.active, loud, portscanDNS_NAME, IP_ADDRESS, IP_RANGEOPEN_TCP_PORT@TheTechromancer2024-05-15
reflected_parametersscanNoHighlight parameters that reflect their contents in response bodyactive, safe, web-heavyWEB_PARAMETERFINDING@liquidsec2024-10-29
retirejsscanNoDetect vulnerable/out-of-date JavaScript librariesactive, safe, web-heavyURL_UNVERIFIEDFINDING@liquidsec2025-08-19
robotsscanNoLook for and parse robots.txtactive, safe, webURLURL_UNVERIFIED@liquidsec2023-02-01
securitytxtscanNoCheck for security.txt contentactive, cloud-enum, safe, subdomain-enum, webDNS_NAMEEMAIL_ADDRESS, URL_UNVERIFIED@colin-stubbs2024-05-26
sslcertscanNoExtract hostnames and emails from TLS certificates in HTTP responsesactive, affiliates, email-enum, safe, subdomain-enum, webHTTP_RESPONSEDNS_NAME, EMAIL_ADDRESS@TheTechromancer2022-03-30
telerikscanNoScan for critical Telerik vulnerabilitiesactive, invasive, loud, web-heavyHTTP_RESPONSE, URLFINDING@liquidsec2022-04-10
url_manipulationscanNoAttempt to identify URL parsing/routing based vulnerabilitiesactive, loud, web-heavyURLFINDING@liquidsec2022-09-27
virtualhostscanNoFuzz for virtual hostsactive, loud, slowURLDNS_NAME_UNVERIFIED, HTTP_RESPONSE, VIRTUAL_HOST@liquidsec2022-05-02
waf_bypassscanNoDetects potential WAF bypassesactive, safe, web-heavyURLFINDING@liquidsec2025-09-26
wafw00fscanNoWeb Application Firewall Fingerprinting Toolactive, loudURLWAF@liquidsec2023-02-15
webbrutescanNoA fast web fuzzer powered by blasthttpactive, loudURLURL_UNVERIFIED@liquidsec2022-04-10
webbrute_shortnamesscanNoBrute-force IIS shortnames using ML-predicted wordlistsactive, iis-shortnames, loud, web-heavyURL_HINTURL_UNVERIFIED@liquidsec2022-07-05
affiliatesscanNoSummarize affiliate domains at the end of a scanaffiliates, passive, safe*@TheTechromancer2022-07-25
anubisdbscanNoQuery anubisdb.com for subdomainspassive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2022-10-04
apkpurescanNoDownload android applications from apkpure.comcode-enum, download, passive, safeMOBILE_APPFILESYSTEM@domwhewell-sage2024-10-11
asnscanNoQuery asndb for ASN informationpassive, safe, subdomain-enumIP_ADDRESSASN@TheTechromancer2022-07-25
azure_tenantscanNoQuery Azure for tenant information using multiple enumeration methodsaffiliates, cloud-enum, passive, safe, subdomain-enumDNS_NAMEAZURE_TENANT, DNS_NAME, FINDING, URL_UNVERIFIED@TheTechromancer2024-07-04
bevigilscanYesRetrieve OSINT data from mobile applications using BeVigilpassive, safe, subdomain-enumDNS_NAMEDNS_NAME, URL_UNVERIFIED@alt-glitch2022-10-26
bucket_file_enumscanNoWorks in conjunction with the filedownload module to download files from open storage buckets. Currently supported cloud providers: AWS, DigitalOceancloud-enum, passive, safeSTORAGE_BUCKETURL_UNVERIFIED@TheTechromancer2023-11-14
bufferoverrunscanYesQuery BufferOverrun's TLS API for subdomainspassive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2024-10-23
builtwithscanYesQuery Builtwith.com for subdomainsaffiliates, passive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2022-08-23
c99scanYesQuery the C99 API for subdomainspassive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2022-07-08
censys_dnsscanYesQuery the Censys API for subdomainspassive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2022-08-04
censys_ipscanYesQuery the Censys API for hosts by IP addresspassive, safeIP_ADDRESSDNS_NAME, IP_ADDRESS, OPEN_TCP_PORT, OPEN_UDP_PORT, PROTOCOL, TECHNOLOGY, URL_UNVERIFIED@TheTechromancer2026-01-26
certspotterscanNoQuery Certspotter's API for subdomainspassive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2022-07-28
chaosscanYesQuery ProjectDiscovery's Chaos API for subdomainspassive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2022-08-14
code_repositoryscanNoLook for code repository links in webpagescode-enum, passive, safeURL_UNVERIFIEDCODE_REPOSITORY@domwhewell-sage2024-05-15
credshedscanYesSend queries to your own credshed server to check for known credentials of your targetspassive, safeDNS_NAMEEMAIL_ADDRESS, HASHED_PASSWORD, PASSWORD, USERNAME@SpamFaux2023-10-12
crtscanNoQuery crt.sh (certificate transparency) for subdomainspassive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2022-05-13
crt_dbscanNoQuery crt.sh (certificate transparency) for subdomains via PostgreSQLpassive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2025-03-27
dehashedscanYesExecute queries against dehashed.com for exposed credentialsemail-enum, passive, safeDNS_NAMEEMAIL_ADDRESS, HASHED_PASSWORD, PASSWORD, USERNAME@SpamFaux2023-10-12
dnsbimiscanNoCheck DNS_NAME's for BIMI records to find image and certificate hosting URL'scloud-enum, passive, safe, subdomain-enumDNS_NAMERAW_DNS_RECORD, URL_UNVERIFIED@colin-stubbs2024-11-15
dnscaascanNoCheck for CAA recordsemail-enum, passive, safe, subdomain-enumDNS_NAMEDNS_NAME, EMAIL_ADDRESS, URL_UNVERIFIED@colin-stubbs2024-05-26
dnsdumpsterscanNoQuery dnsdumpster for subdomainspassive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2022-03-12
dnstlsrptscanNoCheck for TLS-RPT recordscloud-enum, email-enum, passive, safe, subdomain-enumDNS_NAMEEMAIL_ADDRESS, RAW_DNS_RECORD, URL_UNVERIFIED@colin-stubbs2024-07-26
docker_pullscanNoDownload images from a docker repositorycode-enum, download, passive, safe, slowCODE_REPOSITORYFILESYSTEM@domwhewell-sage2024-03-24
dockerhubscanNoSearch for docker repositories of discovered orgs/usernamescode-enum, passive, safeORG_STUB, SOCIALCODE_REPOSITORY, SOCIAL, URL_UNVERIFIED@domwhewell-sage2024-03-12
emailformatscanNoQuery email-format.com for email addressesemail-enum, passive, safeDNS_NAMEEMAIL_ADDRESS@TheTechromancer2022-07-11
fullhuntscanYesQuery the fullhunt.io API for subdomainspassive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2022-08-24
git_clonescanNoClone code github repositoriescode-enum, download, passive, safe, slowCODE_REPOSITORYFILESYSTEM@domwhewell-sage2024-03-08
gitdumperscanNoDownload a leaked .git folder recursively or by fuzzing common namescode-enum, download, passive, safe, slowCODE_REPOSITORYFILESYSTEM@domwhewell-sage2025-02-11
github_codesearchscanYesQuery Github's API for code containing the target domain namecode-enum, passive, safe, subdomain-enumDNS_NAMECODE_REPOSITORY, URL_UNVERIFIED@domwhewell-sage2023-12-14
github_orgscanNoQuery Github's API for organization and member repositoriescode-enum, passive, safe, subdomain-enumORG_STUB, SOCIALCODE_REPOSITORY@domwhewell-sage2023-12-14
github_usersearchscanYesQuery Github's API for users with emails matching in scope domains that may not be discoverable by listing members of the organization.code-enum, passive, safeDNS_NAMEEMAIL_ADDRESS, SOCIAL@domwhewell-sage2025-05-10
github_workflowsscanYesDownload a github repositories workflow logs and workflow artifactscode-enum, download, passive, safeCODE_REPOSITORYFILESYSTEM@domwhewell-sage2024-04-29
google_playstorescanNoSearch for android applications on play.google.comcode-enum, passive, safeCODE_REPOSITORY, ORG_STUBMOBILE_APP@domwhewell-sage2024-10-08
hackertargetscanNoQuery the hackertarget.com API for subdomainspassive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2022-07-28
hunterioscanYesQuery hunter.io for emailsemail-enum, passive, safe, subdomain-enumDNS_NAMEDNS_NAME, EMAIL_ADDRESS, URL_UNVERIFIED@TheTechromancer2022-04-25
ip2locationscanYesQuery IP2location.io's API for geolocation information.passive, safeIP_ADDRESSGEOLOCATION@TheTechromancer2023-09-12
ipneighborscanNoLook beside IPs in their surrounding subnetloud, passive, subdomain-enumIP_ADDRESSIP_ADDRESS@TheTechromancer2022-06-08
ipstackscanYesQuery IPStack's GeoIP APIpassive, safeIP_ADDRESSGEOLOCATION@tycoonslive2022-11-26
jadxscanNoDecompile APKs and XAPKs using JADXcode-enum, passive, safeFILESYSTEMFILESYSTEM@domwhewell-sage2024-11-04
kreuzbergscanNoModule to extract data from filespassive, safeFILESYSTEMRAW_TEXT@domwhewell-sage2024-06-03
leakixscanYesQuery leakix.net for subdomainspassive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2022-07-11
mysslscanNoQuery myssl.com's API for subdomainspassive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2023-07-10
otxscanYesQuery otx.alienvault.com for subdomainspassive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2022-08-24
pgpscanNoQuery common PGP servers for email addressesemail-enum, passive, safeDNS_NAMEEMAIL_ADDRESS@TheTechromancer2022-08-10
portfilterscanNoFilter out unwanted open ports from cloud/CDN targetspassive, safeOPEN_TCP_PORT, URL, URL_UNVERIFIED@TheTechromancer2025-01-06
postmanscanYesQuery Postman's API for related workspaces, collections, requests and download themcode-enum, passive, safe, subdomain-enumORG_STUB, SOCIALCODE_REPOSITORY@domwhewell-sage2024-09-07
postman_downloadscanYesDownload workspaces, collections, requests from Postmancode-enum, download, passive, safe, subdomain-enumCODE_REPOSITORYFILESYSTEM@domwhewell-sage2024-09-07
rapiddnsscanNoQuery rapiddns.io for subdomainspassive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2022-08-24
securitytrailsscanYesQuery the SecurityTrails API for subdomainspassive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2022-07-03
shodan_dnsscanYesQuery Shodan for subdomainspassive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2022-07-03
shodan_enterprisescanYesShodan Enterprise API integration module.passive, safeIP_ADDRESSFINDING, OPEN_TCP_PORT, OPEN_UDP_PORT, TECHNOLOGY@Control-Punk-Delete2026-01-27
shodan_idbscanNoQuery Shodan's InternetDB for open ports, hostnames, technologies, and vulnerabilitiespassive, portscan, safe, subdomain-enumDNS_NAME, IP_ADDRESSDNS_NAME, FINDING, OPEN_TCP_PORT, TECHNOLOGY@TheTechromancer2023-12-22
skymemscanNoQuery skymem.info for email addressesemail-enum, passive, safeDNS_NAMEEMAIL_ADDRESS@TheTechromancer2022-07-11
socialscanNoLook for social media links in webpagespassive, safe, social-enumURL_UNVERIFIEDSOCIAL@TheTechromancer2023-03-28
subdomaincenterscanNoQuery subdomain.center's API for subdomainspassive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2023-07-26
subdomainradarscanYesQuery the Subdomain API for subdomainspassive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2022-07-08
trajanscanNoScans GitHub, GitLab, Azure DevOps, Jenkins, and JFrog for misconfigurations using Praetorian's Trajan toolcode-enum, passive, safeCODE_REPOSITORY, TECHNOLOGY, URL_UNVERIFIEDFINDING@N7WERA2026-04-11
trickestscanYesQuery Trickest's API for subdomainsaffiliates, passive, safe, subdomain-enumDNS_NAMEDNS_NAME@amiremami2024-07-27
trufflehogscanNoTruffleHog is a tool for finding credentialscode-enum, passive, safeCODE_REPOSITORY, FILESYSTEM, HTTP_RESPONSE, RAW_TEXTFINDING@domwhewell-sage2024-03-12
urlscanscanNoQuery urlscan.io for subdomainspassive, safe, subdomain-enumDNS_NAMEDNS_NAME, URL_UNVERIFIED@TheTechromancer2022-06-09
viewdnsscanNoQuery viewdns.info's reverse whois for related domainsaffiliates, passive, safeDNS_NAMEDNS_NAME@TheTechromancer2022-07-04
virustotalscanYesQuery VirusTotal's API for subdomainspassive, safe, subdomain-enumDNS_NAMEDNS_NAME@TheTechromancer2022-08-25
waybackscanNoQuery archive.org's Wayback Machine for subdomains, URLs, parameters, and archived contentpassive, safe, subdomain-enumDNS_NAME, URLDNS_NAME, FINDING, HTTP_RESPONSE, URL_UNVERIFIED, WEB_PARAMETER@liquidsec2022-04-01
asset_inventoryoutputNoMerge hosts, open ports, technologies, findings, etc. into a single asset inventory CSVDNS_NAME, FINDING, HTTP_RESPONSE, IP_ADDRESS, OPEN_TCP_PORT, TECHNOLOGY, URL, WAFIP_ADDRESS, OPEN_TCP_PORT@liquidsec2022-09-30
csvoutputNoOutput to CSV*@TheTechromancer2022-04-07
discordoutputNoMessage a Discord channel when certain events are encountered*@TheTechromancer2023-08-14
elasticoutputNoSend scan results to Elasticsearch*@TheTechromancer2022-11-21
emailsoutputNoOutput any email addresses found belonging to the target domainemail-enum, safeEMAIL_ADDRESS@domwhewell-sage2023-12-23
jsonoutputNoOutput to Newline-Delimited JSON (NDJSON)*@TheTechromancer2022-04-07
kafkaoutputNoOutput scan data to a Kafka topic*@TheTechromancer2024-11-22
mongooutputNoOutput scan data to a MongoDB database*@TheTechromancer2024-11-17
mysqloutputNoOutput scan data to a MySQL database*@TheTechromancer2024-11-13
natsoutputNoOutput scan data to a NATS subject*@TheTechromancer2024-11-22
neo4joutputNoOutput to Neo4j*@TheTechromancer2022-04-07
nmap_xmloutputNoOutput to Nmap XMLDNS_NAME, HTTP_RESPONSE, IP_ADDRESS, OPEN_TCP_PORT, PROTOCOL@TheTechromancer2024-11-16
postgresoutputNoOutput scan data to a SQLite database*@TheTechromancer2024-11-08
rabbitmqoutputNoOutput scan data to a RabbitMQ queue*@TheTechromancer2024-11-22
slackoutputNoMessage a Slack channel when certain events are encountered*@TheTechromancer2023-08-14
splunkoutputNoSend every event to a splunk instance through HTTP Event Collector*@w0Tx2024-02-17
sqliteoutputNoOutput scan data to a SQLite database*@TheTechromancer2024-11-07
stdoutoutputNoOutput to text*@TheTechromancer2024-04-03
subdomainsoutputNoOutput only resolved, in-scope subdomainssafe, subdomain-enumDNS_NAME, DNS_NAME_UNRESOLVED@TheTechromancer2023-07-31
teamsoutputNoMessage a Teams channel when certain events are encountered*@TheTechromancer2023-08-14
txtoutputNoOutput to text*@TheTechromancer2024-04-03
web_parametersoutputNoOutput WEB_PARAMETER names to a fileWEB_PARAMETER@liquidsec2025-01-25
web_reportoutputNoCreate a markdown report with web assetsFINDING, TECHNOLOGY, URL@liquidsec2023-02-08
webhookoutputNoSend every event to a custom URL via a webhook*@TheTechromancer2022-04-13
websocketoutputNoOutput to websockets*@TheTechromancer2022-04-15
zeromqoutputNoOutput scan data to a ZeroMQ socket (PUB)*@TheTechromancer2024-11-22
cloudcheckinternalNoTag events by cloud provider, identify cloud resources like storage buckets*@TheTechromancer2024-07-07
dnsresolveinternalNoPerform DNS resolution*DNS_NAME, IP_ADDRESS, IP_RANGE, RAW_DNS_RECORD@TheTechromancer2022-04-08
pythoninternalNoOutput via Python API*@TheTechromancer2022-09-13
aggregateinternalNoSummarize statistics at the end of a scanpassive, safe@TheTechromancer2022-07-25
excavateinternalNoPassively extract juicy tidbits from scan datapassive, safeHTTP_RESPONSE, RAW_TEXTURL_UNVERIFIED, WEB_PARAMETER@liquidsec2022-06-27
speculateinternalNoDerive certain event types from others by common sensepassive, safeAZURE_TENANT, DNS_NAME, DNS_NAME_UNRESOLVED, HTTP_RESPONSE, IP_ADDRESS, IP_RANGE, SOCIAL, STORAGE_BUCKET, URL, URL_UNVERIFIED, USERNAMEDNS_NAME, FINDING, IP_ADDRESS, OPEN_TCP_PORT, ORG_STUB@liquidsec2022-05-03
unarchiveinternalNoExtract different types of files into folders on the filesystempassive, safeFILESYSTEMFILESYSTEM@domwhewell-sage2024-12-08

For a list of module config options, see Module Options.