estorides
Open-source intelligence (OSINT) aggregator and correlation engine inspired by Palantir, Bellingcat, Maltego, and Citizen Lab workflows. A pure open-source re-imagining of the original fucklantir / osint_palantir toolchain, with a much bigger source catalogue, a proper knowledge graph, structured parsers, and a multi-backend LLM analyst.
File Explorer
- bug_report.md
- custom.md
- feature_request.md
- pull_request_template.md
- ci.yml
- dependabot.yml
- pullrequest_template.md
- analysis_cache.json
- file_hashes.json
- frame.pdf
- frame.png
- frame2.pdf
- frame2.png
- sysapp_frame.pdf
- sysapp_frame.png
- sysapp_preview.html
- estorides_monitor.sqlite
- estorides_monitor.sqlite-shm
- estorides_monitor.sqlite-wal
- README.md
- index.html
- KNOWLEDGE_BASE.md
- __init__.py
- active_recon.py
- alerter.py
- async_client.py
- audit.py
- cases.py
- change_detection.py
- cloud_asset_discovery.py
- code_exposure.py
- config.py
- discoverer.py
- entity_extraction.py
- entity_resolution.py
- entity_store.py
- feeds.py
- fusion_analytics.py
- fusion_store.py
- graph_kuzu.py
- hypothesis_engine.py
- intel_resolver.py
- job_registry.py
- knowledge_graph.py
- mitre_attack.py
- monitoring.py
- observation_models.py
- ontology.py
- orchestrator.py
- osiris_sources.py
- pagination.py
- parsers.py
- pdns_monitor.py
- people_intel.py
- pivot_engine.py
- README.md
- recon_fusion.py
- recon_pipeline.py
- relationship_inference.py
- reliability_scoring.py
- scope.py
- search_telemetry.py
- socmint.py
- source_health_monitoring.py
- source_loader.py
- ssrf_guard.py
- supply_chain.py
- system_app_sources.py
- target_management.py
- target_scoring.py
- tech_fingerprint.py
- tool_install.py
- tool_runner.py
- transforms.py
- transliteration.py
- validation.py
- vuln_correlation.py
- web_security.py
- __init__.py
- encryption.py
- misp.py
- README.md
- recon_report.py
- report.py
- stix.py
- __init__.py
- intelligence_prompts.py
- manager.py
- README.md
- README.md
- alert_27.md
- alert_38.md
- alert_39.md
- alert_40.md
- issue_1.md
- issue_10.md
- issue_11.md
- issue_12.md
- issue_13.md
- issue_14.md
- issue_15.md
- issue_16.md
- issue_17.md
- issue_18.md
- issue_19.md
- issue_2.md
- issue_20.md
- issue_21.md
- issue_22.md
- issue_23.md
- issue_24.md
- issue_25.md
- issue_26.md
- issue_27.md
- issue_28.md
- issue_29.md
- issue_3.md
- issue_30.md
- issue_31.md
- issue_32.md
- issue_33.md
- issue_34.md
- issue_35.md
- issue_36.md
- issue_37.md
- issue_38.md
- issue_39.md
- issue_4.md
- issue_40.md
- issue_41.md
- issue_42.md
- issue_43.md
- issue_44.md
- issue_45.md
- issue_46.md
- issue_47.md
- issue_48.md
- issue_49.md
- issue_5.md
- issue_50.md
- issue_6.md
- issue_7.md
- issue_8.md
- issue_9.md
- README.md
- readmenator_all.yml
- readmenator_python.yml
- README.md
- certspotter_issuances.yaml
- crt_sh_certificates.yaml
- dns_cloudflare.yaml
- dns_dumpster_subdomains.yaml
- dns_google.yaml
- hackertarget_dns.yaml
- hackertarget_findshareddns.yaml
- hackertarget_hostsearch.yaml
- hackertarget_reverse_dns.yaml
- hackertarget_reverseiplookup.yaml
- rdap_domain.yaml
- README.md
- abuseipdb_check.yaml
- censys_certificates.yaml
- fullhunt_surface.yaml
- greynoise_community.yaml
- hackertarget_aslookup.yaml
- ipapi_co_full.yaml
- ipapi_free.yaml
- ipinfo_free.yaml
- ipwho_is.yaml
- ipwhois_free.yaml
- macvendors_lookup.yaml
- rdap_ip.yaml
- README.md
- ripe_stat.yaml
- robtex_ip.yaml
- securitytrails_dns.yaml
- shodan_internetdb.yaml
- google_cache_check.yaml
- hackertarget_geoip.yaml
- hackertarget_http_headers.yaml
- hackertarget_nping.yaml
- hackertarget_traceroute.yaml
- hackertarget_whois.yaml
- pages_dev_meta.yaml
- README.md
- urlscan_public.yaml
- wayback_machine_cdx.yaml
- wayback_machine_snapshot.yaml
- dev_to_user.yaml
- discord_discovery.yaml
- github_gists.yaml
- github_repos.yaml
- github_user.yaml
- hackernews_user.yaml
- keybase_lookup.yaml
- mastodon_search.yaml
- medium_public.yaml
- pinterest_public.yaml
- README.md
- reddit_about.yaml
- reddit_posts.yaml
- telegram_tginfo.yaml
- twitch_user.yaml
- twitter_user.yaml
- whatsmyname_username.yaml
- wordpress_profile.yaml
- youtube_user.yaml
- alienvault_otx.yaml
- blocklist_de_all.yaml
- emergingthreats_compromised.yaml
- feodo_tracker.yaml
- malwarebazaar_hash.yaml
- openphish_feed.yaml
- otx_domain_passive.yaml
- otx_ip_passive.yaml
- phishtank_lookup.yaml
- README.md
- sslbl_abuse_ch.yaml
- threatfox_iocs.yaml
- urlhaus_payloads.yaml
- urlhaus_recent.yaml
- dehashed_email.yaml
- emailrep_email.yaml
- haveibeenpwned_breach.yaml
- haveibeenpwned_paste.yaml
- intelx_email.yaml
- leakix_leak.yaml
- phonebook_domain.yaml
- phonebook_email.yaml
- README.md
- scylla_email.yaml
- nominatim_reverse.yaml
- nominatim_search.yaml
- openweather_geo.yaml
- README.md
- timezoneapi.yaml
- wikidata_search.yaml
- arxiv_search.yaml
- crossref_doi.yaml
- cve_search_circl.yaml
- duckduckgo_instant.yaml
- exploitdb_search.yaml
- github_advisories.yaml
- hunter_email.yaml
- nvd_cve.yaml
- openalex_author.yaml
- openalex_work.yaml
- README.md
- reddit_subreddit.yaml
- wikipedia_search.yaml
- wikipedia_summary.yaml
- aircraft_registry.yaml
- bssid_lookups_ieee.yaml
- marine_traffic.yaml
- README.md
- satellite_pass.yaml
- wigle_search.yaml
- blockchain_btc_balance.yaml
- blockchain_btc_tx.yaml
- blockstream_btc.yaml
- ethplorer_address.yaml
- mempool_space_block.yaml
- README.md
- gists_github_search.yaml
- leakcheck_public.yaml
- psbdmp_ws.yaml
- README.md
- telegram_search_ligated.yaml
- exif_remove_lookup.yaml
- microlink.yaml
- README.md
- screenshotmachine.yaml
- tineye_reverse.yaml
- vt_domain.yaml
- vt_file.yaml
- vt_ip.yaml
- tech_fingerprint.yaml
- bucket_probe.yaml
- hunter_email.yaml
- psbdmp_search.yaml
- github_code_search.yaml
- supply_chain_dns.yaml
- pdns_certspotter.yaml
- pdns_crtsh.yaml
- kali_amass.yaml
- kali_dmitry.yaml
- kali_dnsenum.yaml
- kali_dnsrecon.yaml
- kali_fierce.yaml
- kali_holehe.yaml
- kali_maigret.yaml
- kali_mailfy.yaml
- kali_metagoofil.yaml
- kali_phonefy.yaml
- kali_phoneinfoga.yaml
- kali_searchfy.yaml
- kali_sherlock.yaml
- kali_sublist3r.yaml
- kali_theharvester.yaml
- kali_urlcrazy.yaml
- kali_usufy.yaml
- kali_wafw00f.yaml
- kali_whatweb.yaml
- README.md
- active_recon.md
- change_detection.md
- cloud_asset_discovery.md
- code_exposure.md
- csp_safe_styles.md
- entity_resolution.md
- fusion_analytics.md
- hypothesis_engine.md
- monitoring.md
- observation_models.md
- paged_results.md
- pdns_monitor.md
- people_intel.md
- probabilistic_fusion.md
- recon_fusion.md
- recon_report.md
- reliability_scoring.md
- search_telemetry.md
- security_remediation.md
- socmint.md
- source_health_monitoring.md
- supply_chain.md
- system_app_sources.md
- target_management.md
- target_scoring.md
- tech_fingerprint.md
- tool_install.md
- tool_runner.md
- ui_professional.md
- vuln_correlation.md
- estorides.css
- estorides_ui.css
- README.md
- source_manager.css
- estorides.js
- README.md
- source_manager.js
- README.md
- index.html
- README.md
- source_manager.html
- test_change_detection_properties.py
- test_csp_safe_styles_properties.py
- test_hypothesis_engine_properties.py
- test_observation_models_properties.py
- test_recon_fusion_properties.py
- test_reliability_scoring_properties.py
- test_search_telemetry_properties.py
- test_source_health_monitoring_properties.py
- test_system_app_sources_properties.py
- test_target_management_properties.py
- test_tool_runner_properties.py
- conftest.py
- test_active_recon.py
- test_audit_log.py
- test_auth_gate.py
- test_change_detection.py
- test_cloud_asset_discovery.py
- test_code_exposure.py
- test_csp_safe_styles.py
- test_encrypted_export.py
- test_entity_resolution.py
- test_fusion_analytics.py
- test_hypothesis_engine.py
- test_job_registry.py
- test_monitoring.py
- test_observation_models.py
- test_pagination.py
- test_pdns_monitor.py
- test_people_intel.py
- test_probabilistic_fusion.py
- test_recon_fusion.py
- test_recon_report.py
- test_reliability_scoring.py
- test_search_telemetry.py
- test_security_remediation.py
- test_socmint.py
- test_source_health_monitoring.py
- test_supply_chain.py
- test_system_app_sources.py
- test_target_management.py
- test_target_scoring.py
- test_tech_fingerprint.py
- test_tool_install.py
- test_tool_runner.py
- test_ui_professional.py
- test_vuln_correlation.py
- amass.yaml
- arp-scan.yaml
- binwalk.yaml
- bulk_extractor.yaml
- dirb.yaml
- dmitry.yaml
- dnsenum.yaml
- dnsrecon.yaml
- enum4linux.yaml
- feroxbuster.yaml
- ffuf.yaml
- fierce.yaml
- file.yaml
- gobuster.yaml
- hashcat.yaml
- holehe.yaml
- hydra.yaml
- john.yaml
- maigret.yaml
- mailfy.yaml
- medusa.yaml
- metagoofil.yaml
- msfconsole.yaml
- nbtscan.yaml
- ncat.yaml
- ncrack.yaml
- netcat.yaml
- netdiscover.yaml
- nikto.yaml
- nmap.yaml
- nuclei.yaml
- patator.yaml
- phonefy.yaml
- phoneinfoga.yaml
- r2.yaml
- radare2.yaml
- searchfy.yaml
- sherlock.yaml
- smbclient.yaml
- snmpwalk.yaml
- socat.yaml
- sqlmap.yaml
- sslscan.yaml
- sslyze.yaml
- strings.yaml
- sublist3r.yaml
- tcpdump.yaml
- theHarvester.yaml
- tshark.yaml
- urlcrazy.yaml
- usufy.yaml
- wafw00f.yaml
- wfuzz.yaml
- whatweb.yaml
- README.md
- split_sources.py
- .env.example
- .gitignore
- _multi_test.sh
- _test_entity_resolution.py
- _test_fusion.py
- _test_hardening.py
- _test_passive.py
- _test_people.py
- _test_proxy.py
- _test_scope.py
- _validate.py
- app.py
- CHEATSHEET.md
- CLAUDE.md
- CODE_OF_CONDUCT.md
- CONTRIBUTING.md
- ESSENTIALS.md
- estorides
- estorides_cli.py
- estorides_web.py
- install.sh
- KNOWLEDGE_BASE.md
- LICENSE
- pull_request_template.md
- pyproject.toml
- pytest.ini
- README.md
- requirements.txt
- SECURITY.md
- web.py
- wsgi.py
# Use via CDN
jsDelivrjsDelivr serves any public GitHub repository as a CDN with zero setup. Pick a version and a file to get a ready-to-paste link and snippet.
Command Glossary
Commands referenced in this DOCs, explained below.
age
View Details ▼
age
A simple, modern, and secure file encryption tool.
See also: `age-keygen`, `age-inspect`.
age {{[-p|--passphrase]}} {{[-o|--output]}} {{path/to/encrypted_file.age}} {{path/to/unencrypted_file}}
Generate an encrypted file that can be decrypted with a passphrase:
age {{[-r|--recipient]}} {{public_key}} {{[-o|--output]}} {{path/to/encrypted_file.age}} {{path/to/unencrypted_file}}
Encrypt a file with one or more public keys entered as literals (repeat the `--recipient` flag to specify multiple public keys):
age {{[-R|--recipients-file]}} {{path/to/recipients_file.txt}} {{[-o|--output]}} {{path/to/encrypted_file.age}} {{path/to/unencrypted_file}}
Encrypt a file to one or more recipients with their public keys specified in a file (one per line):
ollama
View Details ▼
ollama
A large language model runner.
For a list of available models, see <https://ollama.com/library>.
ollama serve
Start the daemon required to run other commands:
ollama run {{model}}
Run a model and chat with it (will automatically download the model if it's not downloaded):
ollama run {{model}} --think=false "{{prompt}}"
Run a model with a single prompt and thinking turned off:
pip install
View Details ▼
pip install
Install Python packages.
pip install {{package1 package2 ...}}
Install one or more packages:
pip install {{package1 package2 ...}} {{[-U|--upgrade]}}
Upgrade all specified packages to the latest version, installing any that are not already present:
pip install {{package}}=={{version}}
Install a specific version of a package:
python3
View Details ▼
python3
This command is an alias of `python`.
tldr python
View documentation for the original command:
wafw00f
View Details ▼
wafw00f
Identify and fingerprint Web Application Firewall (WAF) products protecting a website.
wafw00f {{https://www.example.com}}
Check if a website is using any WAF:
wafw00f {{[-a|--findall]}} {{https://www.example.com}}
Test for all detectable WAFs without stopping at the first match:
wafw00f {{[-p|--proxy]}} {{http://localhost:8080}} {{https://www.example.com}}
Pass requests through a proxy (such as BurpSuite):
dnsrecon
View Details ▼
dnsrecon
DNS enumeration tool.
dnsrecon {{[-d|--domain]}} {{example.com}} --db {{path/to/database.sqlite}}
Scan a domain and save the results to an SQLite database:
dnsrecon {{[-d|--domain]}} {{example.com}} {{[-n|--name_server]}} {{nameserver.example.com}} {{[-t|--type]}} axfr
Scan a domain, specifying the nameserver and performing a zone transfer:
dnsrecon {{[-d|--domain]}} {{example.com}} {{[-D|--dictionary]}} {{path/to/dictionary.txt}} {{[-t|--type]}} brt
Scan a domain, using a brute-force attack and a dictionary of subdomains and hostnames:
run0
View Details ▼
run0
Elevate privileges interactively.
Similar to `sudo`, but it's not a SUID binary, authentication takes place via polkit, and commands are invoked from a `systemd` service.
See also: `sudo`, `pkexec`, `doas`.
run0 {{command}}
Run a command as root:
run0 {{[-u|--user]}} {{username|uid}} {{[-g|--group]}} {{group_name|gid}} {{command}}
Run a command as another user and/or group:
query
View Details ▼
query
Display information about user sessions and process.
query session
Display all user sessions:
query session /server:{{hostname}}
Display the current user sessions on a remote computer:
query user
Display logged in users:
