GasMask alternatives

Looking for an alternative tool to replace GasMask? During the review of GasMask we looked at other open source tools. Based on their category, tags, and text, these are the ones that have the best match.

Top 3

  1. DataSploit (OSINT framework)
  2. OSINT Framework (collection of OSINT resources)
  3. OSINT-SPY (open source intelligence gathering tool)

These tools are ranked as the best alternatives to GasMask.

Alternatives (by score)

74

DataSploit

Introduction

DataSploit is a framework to perform intelligence gathering to discover credentials, domain information, and other information related to the target. It uses various reconnaissance techniques on companies, people, phone numbers, and even cryptocoin technology. It allows aggregating all raw data and return it in multiple formats.

Project details

DataSploit is written in Python.

Strengths and weaknesses

  • + More than 10 contributors
  • + More than 1000 GitHub stars
  • + The source code of this software is available

    Typical usage

    • OSINT research
    • Information gathering
    • Security monitoring

    DataSploit review

    74

    OSINT Framework

    Introduction

    The OSINT framework provides a collection of tools to gather and parse public data. The tool is web-based and makes it easy to find tools for a particular task.

    Project details

    OSINT Framework is written in JavaScript.

    Strengths and weaknesses

    • + More than 10 contributors
    • + More than 500 GitHub stars
    • + The source code of this software is available
    • - No releases on GitHub available

    Typical usage

    • OSINT research
    • Footprinting
    • Intelligence gathering
    • Reconnaissance

    OSINT Framework review

    64

    OSINT-SPY

    Introduction

    OSINT-SPY is a modular tool to query information on different subjects like an IP address, domain, email address, or even Bitcoin address. This tool can be valuable during the reconnaissance phase of a penetration test. It can be used also for defenses purpose, like learning what information is publically available about your organization and its assets.

    Project details

    OSINT-SPY is written in Python.

    Strengths and weaknesses

    • + The source code is easy to read and understand
    • + The source code of this software is available
    • - No releases on GitHub available

    Typical usage

    • Information gathering
    • Penetration testing
    • Reconnaissance

    OSINT-SPY review

    74

    SpiderFoot

    Introduction

    SpiderFoot can be used offensively during penetration tests, or defensively to learn what information is available about your organization.

    Project details

    SpiderFoot is written in Python.

    Strengths and weaknesses

    • + The source code of this software is available

      Typical usage

      • Information gathering

      SpiderFoot review

      64

      XRay

      Introduction

      XRay is a security tool for reconnaissance, mapping, and OSINT gathering from public networks.

      Project details

      XRay is written in Golang.

      Strengths and weaknesses

      • + The source code of this software is available

        Typical usage

        • Information gathering
        • Reconnaissance

        XRay review

        60

        Gitem

        Introduction

        Gitem is a reconnaissance tool to extract information about organizations on GitHub. It can be used to find the leaking of sensitive data.

        Project details

        Gitem is written in Python.

        Strengths and weaknesses

        • + The source code of this software is available

          Typical usage

          • Information gathering
          • Security assessment
          • Security monitoring
          • Self-assessment

          Gitem review

          78

          Intrigue Core

          Introduction

          Intrigue Core provides a framework to measure the attack surface of an environment. This includes discovering infrastructure and applications, performing security research, and doing vulnerability discovery.

          Intrigue also allows enriching available data and perform OSINT research (open source intelligence). The related scans include DNS subdomain brute-forcing, email harvesting, IP geolocation, port scanning, and using public search engines like Censys, Shodan, and Bing.

          Project details

          Intrigue Core is written in Ruby.

          Strengths and weaknesses

          • + More than 500 GitHub stars
          • + The source code of this software is available

            Typical usage

            • OSINT research
            • Asset discovery
            • Attack surface measurement
            • Intelligence gathering
            • Penetration testing
            • Security assessment

            Intrigue Core review

            63

            DMitry

            Introduction

            This small utility can retrieve information from the WHOIS database, to see who owns an IP address or domain name. Besides that, it can obtain information from the system itself, like the uptime. DMitry also has the option to search for email addresses, perform a TCP port scan, and use modules specified by the user.

            Project details

            DMitry is written in C.

            Strengths and weaknesses

            • + The source code of this software is available

              DMitry review

              64

              Domain Analyzer

              Introduction

              Domain Analyzer is an information gathering tool and comes in handy for reconnaissance. This can be useful for doing penetration testing or evaluating what information is publically available about your own domains. Some pieces of information that can be discovered include DNS servers, IP addresses, mail servers, SPF information, open ports, and more.

              Project details

              Domain Analyzer is written in Python.

              Strengths and weaknesses

              • + More than 1000 GitHub stars
              • + Very low number of dependencies
              • + The source code of this software is available

                Typical usage

                • Information gathering
                • Penetration testing

                Domain Analyzer review

                60

                GitMiner

                Introduction

                GitMiner is a tool to scan for sensitive data that is leaked via software repositories. Examples of sensitive data are authentication details such as passwords or connection settings.

                Project details

                GitMiner is written in Python.

                Strengths and weaknesses

                • + More than 1000 GitHub stars
                • + The source code of this software is available

                  Typical usage

                  • Asset discovery
                  • Discovery of sensitive information
                  • Information leak detection

                  GitMiner review

                  60

                  Gitmails

                  Introduction

                  This tool can be used to perform reconnaissance on a company or individual target by looking into software repositories. Meta-data like commit activity can reveal who is working for a particular company. This tool helps to extract emails from software repositories.

                  Project details

                  Gitmails is written in Python.

                  Strengths and weaknesses

                  • + Very low number of dependencies
                  • + The source code of this software is available

                    Typical usage

                    • Email harvesting
                    • Information gathering
                    • Reconnaissance

                    Gitmails review

                    60

                    RTA (Red Team Arsenal)

                    Introduction

                    RTA is helpful to automate scanning public resources of a company. As the project name implies, this may be used during red teaming, like a penetration test. That obviously does not limit its use, as it is similarly useful by the blue team.

                    With its integration with Nessus and other tools, RTA is more of a toolkit. This can be seen in its functionality, like subdomain enumeration and information gathering capabilities.

                    Project details

                    RTA is written in Python.

                    Strengths and weaknesses

                    • + The source code of this software is available
                    • - No releases on GitHub available

                    Typical usage

                    • Information gathering
                    • Penetration testing
                    • Security assessment
                    • System enumeration

                    RTA review

                    64

                    Th3inspector

                    Introduction

                    This tool can be called a true 'inspector tool' as it helps to discover many types of data.

                    • Website information
                    • Domain and subdomain information
                    • Mail server information and email
                    • Phone details
                    • IP addresses
                    • Detection of used CMS

                    Project details

                    Th3inspector is written in Perl.

                    Strengths and weaknesses

                    • + The source code of this software is available
                    • - No releases on GitHub available

                    Typical usage

                    • Discovery of sensitive information
                    • Information gathering

                    Th3inspector review

                    85

                    Wappalyzer

                    Introduction

                    Wappalyzer can be a useful asset when performing reconnaissance on a particular target like a web application or website. It helps to find what software is used to run a particular page. Components that can be detected are the content management system (CMS), JavaScript framework, e-commerce software, web server, and more.

                    Project details

                    Wappalyzer is written in Node.js.

                    Strengths and weaknesses

                    • + Has 300+ contributors
                    • + More than 4000 GitHub stars
                    • + Many releases available
                    • + The source code of this software is available

                      Typical usage

                      • Information gathering
                      • Reconnaissance
                      • Software identification

                      Wappalyzer review

                      60

                      Belati

                      Introduction

                      Belati is security tool to collect public data and information and calls itself a Swiss army knife for OSINT purposes.

                      Project details

                      Belati is written in Python.

                      Strengths and weaknesses

                      • + The source code of this software is available
                      • - Full name of author is unknown

                      Typical usage

                      • Information gathering

                      Belati review

                      60

                      Gitrob

                      Introduction

                      Especially open source developers may share their code in a public repository like GitHub. This is a great way to collaborate between the developer(s) and the community. The risk of sharing code is that sensitive data is part of the repository and uploaded by accident. GitRob helps to detect this kind of accidental leaks.

                      Project details

                      Gitrob is written in Ruby.

                      Strengths and weaknesses

                      • + More than 1000 GitHub stars
                      • + The source code of this software is available

                        Typical usage

                        • Data leak prevention
                        • Information gathering
                        • Penetration testing
                        • Security assessment

                        Gitrob review

                        60

                        OSRFramework

                        Introduction

                        This OSINT framework allows combining sources and provide data in different formats (web interface, API, command line).

                        Project details

                        OSRFramework is written in Python.

                        Strengths and weaknesses

                        • + Available as package (simplified installation)
                        • + The source code of this software is available
                        • - No releases on GitHub available

                        Typical usage

                        • Information gathering

                        OSRFramework review

                        60

                        ThreatPinch Lookup

                        Introduction

                        ThreatPinch helps to speed up collecting information from common resources like CVE databases or public WHOIS data. As it works from the browser, it is a helpful addition for people who have to perform forensics, security monitoring, or system administration. For example, getting the owner of a domain and IP address becomes almost instant knowledge.

                        Project details

                        ThreatPinch Lookup is written in JavaScript.

                        Strengths and weaknesses

                        • + Many integration possibilities available
                        • - Unknown project license

                        Typical usage

                        • Information gathering
                        • Threat hunting

                        ThreatPinch Lookup review

                        52

                        theHarvester

                        Introduction

                        This tool is a typical information collection tool to retrieve public data and get it all into one place. It is useful for penetration tests, or if you want to see what is available for your company.

                        Project details

                        Some relevant tool missing as an alternative to GasMask? Please contact us with your suggestion.