# Dheerajmadhukar/karma_v2

⡷⠂𝚔𝚊𝚛𝚖𝚊 𝚟𝟸⠐⢾ is a Passive Open Source Intelligence (OSINT) Automated Reconnaissance (framework)

Repository: https://github.com/Dheerajmadhukar/karma_v2
Canonical: https://ross.abutalabs.com/products/karma_v2
Homepage: https://github.com/Dheerajmadhukar/karma_v2
Language: Shell
License Family: other
Topics: osint, shodan, bugbounty, automation, bash-script, reconnaissance, intelligence, infrastructure
Last push: 2025-05-21T04:27:18+00:00

## Health v2 (maintenance only)
Score: 42/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 22, release rhythm 35, longevity 100
- inputs: {"age_days": 1852, "days_push": 469, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1020, forks 187 (observed 2026-08-28T04:03:15.235232+00:00)

## What it is
karma_v2 is a Bash-based passive OSINT reconnaissance framework that automates Shodan queries to enumerate assets, exposed services, CVEs, and leaks for a target domain. It requires a Shodan Premium API key and outputs results to the screen and to files/directories.

## Use cases
- find all exposed assets and IPs for a target domain passively
- discover WAF/CDN bypassed origin IPs
- enumerate open ports, banners, and services on target infrastructure
- find publicly exposed leaks like S3 buckets, dashboards, and default credentials
- collect CVEs associated with a target's exposed technologies
- perform ASN and BGP neighbor reconnaissance
- identify technologies via favicon hashing and nuclei templates

## When to choose
- you have a Shodan Premium API key and need automated passive recon for bug bounty or pentesting
- you want a single script that aggregates Shodan dorks, SSL fingerprint matching, and leak detection
- you need in-scope/out-of-scope IP separation with SSL/TLS issuer verification

## When to avoid
- you only have a free Shodan API key
- you need active scanning rather than passive intelligence gathering
- you need a supported, licensed tool - the repo has no license file
- you work on Windows outside WSL or on macOS without adaptation

## Facets
- artifact type: cli-tool
- maturity: active
- function: osint, security, workflow-automation, web-scraping, developer-tools
- domain: security, osint, penetration-testing
- platform: cli
- tags: reconnaissance, shodan, bugbounty, passive-recon, attack-surface-discovery, bash-script, cve-lookup, favicon-hashing, command-line, automation, linux, bash

## Member repositories
- Dheerajmadhukar/karma_v2 (main) score 42

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:15.235232+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T07:08:53.150827+00:00, confidence not recorded.
  - readme: https://github.com/Dheerajmadhukar/karma_v2 (fetched 2026-08-28T04:03:15.235232+00:00, sha fa7e0267f9c7)
  - homepage: https://github.com/Dheerajmadhukar/karma_v2 (fetched 2026-08-29T13:09:08.819054+00:00, sha de44be268c69)
- Data as of 2026-08-30T08:39:29.467469+00:00.
