hacktricks/todo/online-platforms-with-api.md
2024-04-16 03:52:03 +00:00

6.1 KiB

Online Platforms with API

Learn AWS hacking from zero to hero with htARTE (HackTricks AWS Red Team Expert)!

Other ways to support HackTricks:

ProjectHoneypot

You can ask if an IP is related to suspicious/malicious activities. Completely free.

BotScout

Check if the IP address is related to a bot that register accounts. It can also check usernames and emails. Initially free.

Hunter

Find and verify emails.
Some free API requests free, for more you need to pay.
Commercial?

AlientVault

Find Malicious activities related to IPs and Domains. Free.

Clearbit

Find related personal data to a email (profiles on other platforms), domain (basic company info ,mails and people working) and companies (get company info from mail).
You need to pay to access all the possibilities.
Commercial?

BuiltWith

Technologies used by webs. Expensive...
Commercial?

Fraudguard

Check if a host (domain or IP) is related with suspicious/malicious activities. Have some free API access.
Commercial?

FortiGuard

Check if a host (domain or IP) is related with suspicious/malicious activities. Have some free API access.

SpamCop

Indicates if host is related to spam activity. Have some free API access.

mywot

Based on opinions and other metrics get if a domain is related with suspicious/malicious information.

ipinfo

Obtains basic info from an IP address. You can test up to 100K/month.

securitytrails

This platform give information about domains and IP addresses like domains inside an IP or inside a domain server, domains owned by an email (find related domains), IP history of domains (find the host behind CloudFlare), all domains using a nameserver....
You have some free access.

fullcontact

Allows to search by email, domain or company name and retrieve "personal" information related. It can also verify emails. There is some free access.

RiskIQ

A lot of information from domains and IPs even in the free/community version.

_IntelligenceX

Search Domains, IPs and emails and get info from dumps. Have some free access.

IBM X-Force Exchange

Search by IP and gather information related to suspicions activities. There is some free access.

Greynoise

Search by IP or IP range and get information about IPs scanning the Internet. 15 days free access.

Shodan

Get scan information of an IP address. Have some free api access.

Censys

Very similar to shodan

buckets.grayhatwarfare.com

Find open S3 buckets searching by keyword.

Dehashed

Find leaked credentials of emails and even domains
Commercial?

psbdmp

Search pastebins where a email appeared. Commercial?

emailrep.io

Get reputation of a mail. Commercial?

ghostproject

Get passwords from leaked emails. Commercial?

Binaryedge

Obtain interesting info from IPs

haveibeenpwned

Search by domain and email and get if it was pwned and passwords. Commercial?

IP2Location.io

It detects IP geolocation, data center, ASN and even VPN information. It offers free 30K queries per month.

https://dnsdumpster.com/(in a commercial tool?)

https://www.netcraft.com/ (in a commercial tool?)

https://www.nmmapper.com/sys/tools/subdomainfinder/ (in a commercial tool?)

Learn AWS hacking from zero to hero with htARTE (HackTricks AWS Red Team Expert)!

Other ways to support HackTricks: