🔍 A powerful OSINT & External Threat Hunting toolkit for security professionals
Features • Installation • Usage • Commands • Reports • Contributing
BUCIN is an all-in-one external reconnaissance toolkit designed for:
- 🔴 Red Teams - Attack surface discovery and vulnerability assessment
- � Blue Teams - External threat monitoring and exposure mapping
- � Bug Bounty Hunters - Target enumeration and secret scanning
- ⚪ Security Researchers - OSINT and passive reconnaissance
|
|
||||||||||||||||||||
|
|
# Clone the repository
git clone https://github.com/Masriyan/Bucin.git
cd Bucin
# Install dependencies
pip install -r requirements.txt
# Or install via pip (editable mode)
pip install -e .📦 Dependencies
| Package | Purpose |
|---|---|
requests |
HTTP library |
beautifulsoup4 |
HTML parsing |
tldextract |
Domain parsing |
colorama |
Colored output |
tqdm |
Progress bars |
dnspython |
DNS queries |
python-whois |
WHOIS lookups |
Optional:
pdfkit/weasyprint- PDF reportsshodan- Shodan integration
# Full reconnaissance on a target
bucin all -d example.com --report html,csv
# Just subdomains
bucin subdomains -d example.com
# Security headers check
bucin headers --host example.com
# Technology detection
bucin tech -t https://example.com# Create a targets file
echo "example.com" > targets.txt
echo "test.example.com" >> targets.txt
# Run against multiple targets
bucin probe -t targets.txt
bucin ports --host targets.txt🌐 subdomains - Passive Subdomain Enumeration
bucin subdomains -d example.com [-o output] [--report csv,html]Discovers subdomains via crt.sh certificate transparency logs and checks liveness.
🔎 probe - Sensitive Path Discovery
bucin probe -t example.com [-p paths.txt] [-o output]Probes for sensitive files: .env, .git/config, swagger.json, etc.
🕷️ crawl - Web Crawler + Secret Scanner
bucin crawl -t https://example.com [--max-pages 150] [--secrets]Crawls website and scans for exposed secrets (API keys, tokens, etc.)
🔐 tls - TLS Certificate Inspection
bucin tls --host example.com [--port 443]Retrieves and analyzes TLS certificate information.
🪣 buckets - Cloud Bucket Enumeration
bucin buckets -n "company-name" [--wordlist words.txt]Checks for public AWS S3, GCP Storage, and Azure Blob buckets.
📧 dns - DNS Record Enumeration
bucin dns -d example.comFetches A, AAAA, MX, TXT, NS, and CNAME records.
📋 whois - WHOIS Lookup
bucin whois -d example.comRetrieves domain registration and ownership information.
🚪 ports - Port Scanning
bucin ports --host example.com [-p 80,443,8080] [-t 16]Fast concurrent port scanning with customizable port list.
🛡️ headers - Security Headers Analysis
bucin headers --host example.comAnalyzes HTTP security headers and provides a security score.
⏳ wayback - Wayback Machine URLs
bucin wayback -d example.com [--limit 500]Discovers historical URLs from the Wayback Machine CDX API.
🔧 tech - Technology Detection
bucin tech -t https://example.comDetects web technologies: CMS, frameworks, libraries, CDNs, etc.
🌐 cors - CORS Misconfiguration Testing
bucin cors -t https://example.comTests for CORS vulnerabilities (wildcard, null origin, reflection).
⚠️ takeover - Subdomain Takeover Check
bucin takeover -d example.comChecks subdomains for takeover vulnerabilities (dangling CNAMEs).
🔗 social - Social Media Discovery
bucin social -n "Company Name"Searches for social media profiles across platforms.
🎯 all - Full Reconnaissance
bucin all -d example.com --report html,csv,pdfRuns complete reconnaissance: subdomains, probe, crawl, DNS, WHOIS, headers, tech.
BUCIN generates professional reports in multiple formats:
| Format | Command | Description |
|---|---|---|
| 📄 CSV | --report csv |
Machine-readable spreadsheet |
| 🌐 HTML | --report html |
Beautiful web report |
--report pdf |
Print-ready document | |
| 📝 Markdown | --report md |
GitHub-friendly format |
# Generate multiple formats at once
bucin all -d example.com --report csv,html,pdfBUCIN automatically detects 18+ types of exposed secrets:
|
|
|
# Custom user agent
export BUCIN_USER_AGENT="CustomAgent/1.0"
# Shodan API key (optional)
export SHODAN_API_KEY="your-api-key"Contributions are welcome! Please read CONTRIBUTING.md for guidelines.
# Fork the repo, then:
git clone https://github.com/YOUR_USERNAME/Bucin.git
cd Bucin
git checkout -b feature/your-feature
# Make changes, then:
git commit -m "feat: add your feature"
git push origin feature/your-feature
# Open a Pull RequestThis tool is intended for authorized security testing and educational purposes only.
Always obtain proper authorization before scanning any systems. The authors are not responsible for misuse or damage caused by this tool.
This project is licensed under the MIT License - see the LICENSE file for details.
Made with ❤️ by Masriyan