m3n0sd0n4ld/GooFuzz
GooFuzz is a tool to perform fuzzing with an OSINT approach, managing to enumerate directories, files, subdomains or parameters without leaving evidence on the target's server and by means of advanced Google searches (Google Dorking). observed · 2026-08-28
Health v2 · maintenance only
57/100
- Activity 58
- Release rhythm 30
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 214
- age_days: 1538
- days_rel: 256
- days_push: 255
- n_releases_24m: 2
Adoption not part of the score
1585 stars · 158 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
GooFuzz is a Bash-based CLI tool that performs fuzzing-style reconnaissance using advanced Google searches (Google Dorking) via the Google Custom Search API. It enumerates directories, files, subdomains, and parameters without sending requests to the target's server, leaving no evidence on the target.
Use cases
- enumerate directories and files on a target without touching its server
- find subdomains using google dorks for bug bounty recon
- discover exposed sensitive files through osint
- fuzz for parameters without leaving traces in target logs
- passive reconnaissance for red team engagements
- find information disclosure leaks via advanced google searches
When to choose
- you need passive recon that leaves no evidence on the target's server
- you want to leverage Google's index instead of brute-forcing directories
- you're doing bug bounty or red team reconnaissance with OSINT techniques
When to avoid
- you need active scanning or fuzzing against the live server itself
- you don't want to set up a Google Cloud API key and Programmable Search Engine
- the target content isn't indexed by Google
Facets
cli-tool · maturity active
osint search-engine web-scraping security cli security osint penetration-testing crawlers cli google-dorks reconnaissance bug-bounty red-team bash-script information-disclosure subdomain-enumeration command-line linux macos
1 source
- readme: https://github.com/m3n0sd0n4ld/GooFuzz · fetched 2026-08-28 · 6136e2008a17
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| m3n0sd0n4ld/GooFuzz | main | 57 |
For agents
markdown · JSON · MCP: product_card(name="m3n0sd0n4ld/GooFuzz")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem