Skip to content
MasriyanPublic

About

BUCIN is an all-in-one external reconnaissance toolkit

Topics

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

2 Commits

Folders and files

Repository files navigation

Version Python License Platform

PRs Welcome Maintained Stars Forks


🔍 A powerful OSINT & External Threat Hunting toolkit for security professionals

Features • Installation • Usage • Commands • Reports • Contributing



🎯 What is BUCIN?

BUCIN is an all-in-one external reconnaissance toolkit designed for:

  • 🔴 Red Teams - Attack surface discovery and vulnerability assessment
  • � Blue Teams - External threat monitoring and exposure mapping
  • � Bug Bounty Hunters - Target enumeration and secret scanning
  • ⚪ Security Researchers - OSINT and passive reconnaissance

✨ Features

🌐 Domain Intelligence

Feature Description
🔍 Subdomains Passive enumeration via crt.sh
📧 DNS Records MX, TXT, NS, CNAME, A, AAAA
📋 WHOIS Domain registration data
⏳ Wayback Historical URL discovery

🛡️ Security Analysis

Feature Description
� Headers Security headers scoring
🌐 CORS Misconfiguration testing
⚠️ Takeover Subdomain takeover check
🔧 Tech Stack Technology detection

🕵️ Reconnaissance

Feature Description
🔎 Probe Sensitive file discovery
🕷️ Crawl Web crawling + secrets
🚪 Ports Fast port scanning
🔐 TLS Certificate inspection

📦 Asset Discovery

Feature Description
🪣 Buckets AWS/GCP/Azure checks
🔗 Social Social media profiles
� Secrets 18+ pattern detection
📊 Reports HTML, CSV, PDF, MD

🚀 Installation

# Clone the repository
git clone https://github.com/Masriyan/Bucin.git
cd Bucin

# Install dependencies
pip install -r requirements.txt

# Or install via pip (editable mode)
pip install -e .
📦 Dependencies
Package Purpose
requests HTTP library
beautifulsoup4 HTML parsing
tldextract Domain parsing
colorama Colored output
tqdm Progress bars
dnspython DNS queries
python-whois WHOIS lookups

Optional:

  • pdfkit / weasyprint - PDF reports
  • shodan - Shodan integration

📖 Usage

Quick Start

# Full reconnaissance on a target
bucin all -d example.com --report html,csv

# Just subdomains
bucin subdomains -d example.com

# Security headers check
bucin headers --host example.com

# Technology detection
bucin tech -t https://example.com

Using Target Files

# Create a targets file
echo "example.com" > targets.txt
echo "test.example.com" >> targets.txt

# Run against multiple targets
bucin probe -t targets.txt
bucin ports --host targets.txt

🎮 Commands

🌐 subdomains - Passive Subdomain Enumeration
bucin subdomains -d example.com [-o output] [--report csv,html]

Discovers subdomains via crt.sh certificate transparency logs and checks liveness.

🔎 probe - Sensitive Path Discovery
bucin probe -t example.com [-p paths.txt] [-o output]

Probes for sensitive files: .env, .git/config, swagger.json, etc.

🕷️ crawl - Web Crawler + Secret Scanner
bucin crawl -t https://example.com [--max-pages 150] [--secrets]

Crawls website and scans for exposed secrets (API keys, tokens, etc.)

🔐 tls - TLS Certificate Inspection
bucin tls --host example.com [--port 443]

Retrieves and analyzes TLS certificate information.

🪣 buckets - Cloud Bucket Enumeration
bucin buckets -n "company-name" [--wordlist words.txt]

Checks for public AWS S3, GCP Storage, and Azure Blob buckets.

📧 dns - DNS Record Enumeration
bucin dns -d example.com

Fetches A, AAAA, MX, TXT, NS, and CNAME records.

📋 whois - WHOIS Lookup
bucin whois -d example.com

Retrieves domain registration and ownership information.

🚪 ports - Port Scanning
bucin ports --host example.com [-p 80,443,8080] [-t 16]

Fast concurrent port scanning with customizable port list.

🛡️ headers - Security Headers Analysis
bucin headers --host example.com

Analyzes HTTP security headers and provides a security score.

⏳ wayback - Wayback Machine URLs
bucin wayback -d example.com [--limit 500]

Discovers historical URLs from the Wayback Machine CDX API.

🔧 tech - Technology Detection
bucin tech -t https://example.com

Detects web technologies: CMS, frameworks, libraries, CDNs, etc.

🌐 cors - CORS Misconfiguration Testing
bucin cors -t https://example.com

Tests for CORS vulnerabilities (wildcard, null origin, reflection).

⚠️ takeover - Subdomain Takeover Check
bucin takeover -d example.com

Checks subdomains for takeover vulnerabilities (dangling CNAMEs).

🔗 social - Social Media Discovery
bucin social -n "Company Name"

Searches for social media profiles across platforms.

🎯 all - Full Reconnaissance
bucin all -d example.com --report html,csv,pdf

Runs complete reconnaissance: subdomains, probe, crawl, DNS, WHOIS, headers, tech.


📊 Reports

BUCIN generates professional reports in multiple formats:

Format Command Description
📄 CSV --report csv Machine-readable spreadsheet
🌐 HTML --report html Beautiful web report
📑 PDF --report pdf Print-ready document
📝 Markdown --report md GitHub-friendly format
# Generate multiple formats at once
bucin all -d example.com --report csv,html,pdf

🔐 Secret Detection

BUCIN automatically detects 18+ types of exposed secrets:

  • 🔑 AWS Access Keys
  • 🔑 AWS Secret Keys
  • 🔑 Google API Keys
  • 🔑 Slack Tokens
  • 🔑 GitHub Tokens
  • 🔑 Discord Tokens
  • 🔑 Stripe API Keys
  • 🔑 Heroku API Keys
  • 🔑 Mailgun Keys
  • 🔑 Twilio Keys
  • 🔑 SendGrid Keys
  • 🔑 Firebase URLs
  • 🔑 Private Keys (RSA/DSA/EC)
  • 🔑 JWT Tokens
  • � Square OAuth
  • 🔑 PayPal Braintree
  • �📧 Email Addresses
  • 🔗 And more...

⚙️ Configuration

Environment Variables

# Custom user agent
export BUCIN_USER_AGENT="CustomAgent/1.0"

# Shodan API key (optional)
export SHODAN_API_KEY="your-api-key"

🤝 Contributing

Contributions are welcome! Please read CONTRIBUTING.md for guidelines.

# Fork the repo, then:
git clone https://github.com/YOUR_USERNAME/Bucin.git
cd Bucin
git checkout -b feature/your-feature
# Make changes, then:
git commit -m "feat: add your feature"
git push origin feature/your-feature
# Open a Pull Request

⚠️ Disclaimer

This tool is intended for authorized security testing and educational purposes only.

Always obtain proper authorization before scanning any systems. The authors are not responsible for misuse or damage caused by this tool.


📜 License

This project is licensed under the MIT License - see the LICENSE file for details.



Made with ❤️ by Masriyan

⭐ Star this repo if you find it useful!

About

BUCIN is an all-in-one external reconnaissance toolkit

Topics

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages