Open source2025Open source · MIT · authorised testing only

ShadowHound

A modular black-box reconnaissance and vulnerability-discovery toolkit in Python.

  • Python
  • Nmap
  • Shodan

Source

  1. The problem

    Recon for an authorised pentest is a dozen separate tools with a dozen output formats. The first hours of every engagement went to plumbing rather than looking.

  2. The approach

    • One CLI, one module per job, one place to add the next one: `python3 shadowhound.py <module> [options]`.
    • Stealth-minded defaults for the modules that touch a target directly.
  3. What shipped

    • webscan — subdomain enumeration, tech-stack and header analysis.
    • netrecon — host discovery and service enumeration over Nmap.
    • jsdig — JavaScript endpoint and API-link harvesting.
    • aslookup — Shodan-based ASN, IP and port intel for an organisation.
    • gitleaks — repository scanning for keys, tokens and credentials.
    • xssfinder — reflected and DOM XSS testing with custom fuzzing payloads.
    • dirbuster — hidden directory and endpoint discovery with wordlists.

Have something like this?

Twenty minutes to find out if it's a fit — then a fixed scope and a fixed quote. Or read what I offer first.

Book a 20-min call

Faheem Musthafa · 2025