Ross ROSS = Recommend OSS · open-source software intelligence for agents

Dheerajmadhukar/karma_v2

⡷⠂𝚔𝚊𝚛𝚖𝚊 𝚟𝟸⠐⢾ is a Passive Open Source Intelligence (OSINT) Automated Reconnaissance (framework) observed · 2026-08-28

github.com/Dheerajmadhukar/karma_v2 · homepage · Shell observed · 2026-08-28

Health v2 · maintenance only

42/100

  • Activity 22
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1852
  • days_rel: n/a
  • days_push: 469
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1020 stars · 187 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

karma_v2 is a Bash-based passive OSINT reconnaissance framework that automates Shodan queries to enumerate assets, exposed services, CVEs, and leaks for a target domain. It requires a Shodan Premium API key and outputs results to the screen and to files/directories.

Use cases

  • find all exposed assets and IPs for a target domain passively
  • discover WAF/CDN bypassed origin IPs
  • enumerate open ports, banners, and services on target infrastructure
  • find publicly exposed leaks like S3 buckets, dashboards, and default credentials
  • collect CVEs associated with a target's exposed technologies
  • perform ASN and BGP neighbor reconnaissance
  • identify technologies via favicon hashing and nuclei templates

When to choose

  • you have a Shodan Premium API key and need automated passive recon for bug bounty or pentesting
  • you want a single script that aggregates Shodan dorks, SSL fingerprint matching, and leak detection
  • you need in-scope/out-of-scope IP separation with SSL/TLS issuer verification

When to avoid

  • you only have a free Shodan API key
  • you need active scanning rather than passive intelligence gathering
  • you need a supported, licensed tool - the repo has no license file
  • you work on Windows outside WSL or on macOS without adaptation

Facets

cli-tool · maturity active

osint security workflow-automation web-scraping developer-tools security osint penetration-testing cli reconnaissance shodan bugbounty passive-recon attack-surface-discovery bash-script cve-lookup favicon-hashing command-line automation linux bash

2 sources

Member repositories

RepositoryRoleHealth v2
Dheerajmadhukar/karma_v2main42

For agents

markdown · JSON · MCP: product_card(name="Dheerajmadhukar/karma_v2")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem