Ross ROSS = Recommend OSS · open-source software intelligence for agents

m3n0sd0n4ld/GooFuzz

GooFuzz is a tool to perform fuzzing with an OSINT approach, managing to enumerate directories, files, subdomains or parameters without leaving evidence on the target's server and by means of advanced Google searches (Google Dorking). observed · 2026-08-28

github.com/m3n0sd0n4ld/GooFuzz · Shell · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

57/100

  • Activity 58
  • Release rhythm 30
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 214
  • age_days: 1538
  • days_rel: 256
  • days_push: 255
  • n_releases_24m: 2

Full methodology

Adoption not part of the score

1585 stars · 158 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

GooFuzz is a Bash-based CLI tool that performs fuzzing-style reconnaissance using advanced Google searches (Google Dorking) via the Google Custom Search API. It enumerates directories, files, subdomains, and parameters without sending requests to the target's server, leaving no evidence on the target.

Use cases

  • enumerate directories and files on a target without touching its server
  • find subdomains using google dorks for bug bounty recon
  • discover exposed sensitive files through osint
  • fuzz for parameters without leaving traces in target logs
  • passive reconnaissance for red team engagements
  • find information disclosure leaks via advanced google searches

When to choose

  • you need passive recon that leaves no evidence on the target's server
  • you want to leverage Google's index instead of brute-forcing directories
  • you're doing bug bounty or red team reconnaissance with OSINT techniques

When to avoid

  • you need active scanning or fuzzing against the live server itself
  • you don't want to set up a Google Cloud API key and Programmable Search Engine
  • the target content isn't indexed by Google

Facets

cli-tool · maturity active

osint search-engine web-scraping security cli security osint penetration-testing crawlers cli google-dorks reconnaissance bug-bounty red-team bash-script information-disclosure subdomain-enumeration command-line linux macos

1 source

Member repositories

RepositoryRoleHealth v2
m3n0sd0n4ld/GooFuzzmain57

For agents

markdown · JSON · MCP: product_card(name="m3n0sd0n4ld/GooFuzz")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem