awesome-hacker-search-engines
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
A curated reference list of search engines and online tools for security professionals, covering exposed-server lookup, vulnerability databases, exploit archives, DNS records, leaked credentials, and more, no code, just links.
This repository is a curated list of search engines and online tools aimed at security professionals. It covers a wide range of lookup tasks that come up during security work: finding exposed servers, researching known vulnerabilities, locating exploits, mapping the attack surface of a target, searching for leaked credentials, and more. The list is organized into roughly two dozen topic categories.
The categories include general-purpose search engines, specialized tools for querying internet-connected servers and devices (such as Shodan and Censys, which index what ports and services machines expose to the internet), vulnerability databases from organizations like NIST and MITRE, exploit archives, tools for looking up domain records, DNS history, SSL certificate details, and WiFi network information. There are also sections covering email address lookups, phone number searches, social network research, image search, cryptocurrency tracking, threat intelligence feeds, archived web pages, and searches for exposed surveillance cameras.
The project is a reference list, not a piece of software. There is no code to run or install. Each entry is a link to an external website, along with a short description of what that site does. The list is long and actively maintained, making it a practical starting point for someone who wants to know what tools exist for a particular research or testing task rather than having to discover each one independently.
The intended audience is penetration testers, bug bounty hunters, and security researchers who need to gather information about systems, services, or individuals as part of authorized security assessments. The full README is longer than what was shown.
Where it fits
- Look up what ports and services a target server exposes to the internet using Shodan or Censys.
- Search for known vulnerabilities affecting a specific software version using NIST or MITRE databases.
- Find publicly leaked credentials or email addresses during a bug bounty reconnaissance phase.
- Discover archived versions of a web page or historical DNS records for a domain under investigation.