Skip to main content

Kumo : domain OSINT & recon framework

0
Medium
Published: 10/05/2026 (10/05/2026, 21:08:12 UTC)
Source: Reddit Cybersecurity

Description

Kumo is an open-source domain OSINT and reconnaissance framework designed to automate and centralize external domain reconnaissance. It runs 27 modules in parallel to gather DNS, port, certificate, subdomain, technology stack, leaked credentials, vulnerability checks, and other publicly available information about a target domain. It requires no API keys or elevated privileges and provides both CLI and web interfaces for scanning and reporting. Kumo is intended for use on domains the user is authorized to test and does not itself represent a vulnerability or exploit.

Reddit Discussion

r/cybersecurity·posted by u/k0r1mk
00

Over the last couple of weeks, I challenged myself to build a tool that centralizes everything you need when conducting recon.

And that’s how Kumo was born. Give it a domain and it hands you back everything reachable from outside.

What it does in one run:

  • Maps the surface : DNS, ports, certificates, subdomains, tech stack
  • Finds what shouldn't be public : exposed configs, secrets in JS, open buckets
  • Checks for known vulnerabilities without touching anything
  • Digs up leaked credentials and which employee machines got infected
  • Pulls in archived pages, forgotten endpoints, threat intel
  • Builds Google dorks and OSINT links for the target

All 27 modules run at once and stream back as they land. No API keys required, CLI and web interface. Works on any domain you're allowed to test.

🔗 https://github.com/karim852/KUMO-Domain-Recon-Tool
🖥️ live demo: https://demo-kumo-kage.vercel.app

🎥 2-min walkthrough: https://www.youtube.com/watch?v=dM-KbBU93ZM

Feedback and contributions welcome 🙏

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/05/2026, 21:20:28 UTC

Technical Analysis

Kumo is a reconnaissance tool that aggregates multiple OSINT and scanning techniques into a single framework. It performs DNS enumeration, port scanning, certificate analysis, subdomain discovery (both passive and brute force), technology fingerprinting, leaked credential checks, vulnerability scanning against known exposures, and threat intelligence gathering. The tool runs 27 modules concurrently, streaming results live to the terminal or web dashboard. It requires no API keys or root privileges and relies solely on publicly accessible data sources. Kumo is designed for authorized external reconnaissance and does not introduce new vulnerabilities or exploits.

Potential Impact

Kumo itself does not introduce a security vulnerability or exploit. It is a reconnaissance tool that can be used by security professionals to identify publicly exposed information and potential security weaknesses in a domain's external footprint. The impact depends on how the tool is used; it can aid in security assessments but also could be leveraged by attackers for information gathering if used maliciously. There are no known exploits or vulnerabilities associated with Kumo itself.

Defensive Guidance

No remediation or patching is required as Kumo is a security tool, not a vulnerability. Users should ensure they have proper authorization before scanning domains to avoid legal or ethical issues. Organizations should monitor for unauthorized reconnaissance activity and secure publicly exposed assets accordingly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Threat ID: 6ac4148c2cdf04f6563b1ae6

Added to database: 10/05/2026, 21:20:12 UTC

Last enriched: 10/05/2026, 21:20:28 UTC

Last updated: 10/06/2026, 03:48:13 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses