Ross ROSS = Recommend OSS · open-source software intelligence for agents

guelfoweb/knockpy

Knock Subdomain Scan observed · 2026-08-28

github.com/guelfoweb/knockpy · homepage · Python · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

64/100

  • Activity 68
  • Release rhythm 38
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 226.5
  • age_days: 4586
  • days_rel: 200
  • days_push: 195
  • n_releases_24m: 3

Full methodology

Adoption not part of the score

4178 stars · 873 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

KnockPy is a modular Python 3 CLI tool for enumerating subdomains of a target domain using passive reconnaissance sources and DNS bruteforce, with async scanning via httpx. It validates HTTP/HTTPS status, TLS certificates, and IPs, detects wildcard DNS and legacy TLS, and stores results in SQLite with exportable reports.

Use cases

  • enumerate subdomains of a domain for a bug bounty recon
  • bruteforce subdomains with a wordlist
  • run passive subdomain discovery via VirusTotal and Shodan
  • check AXFR zone transfer vulnerabilities on a domain
  • detect wildcard DNS and legacy TLS 1.0/1.1 support
  • export subdomain scan results to HTML or SQLite reports

When to choose

  • you need a fast async Python subdomain scanner for pentest or bug bounty recon
  • you want passive recon plus bruteforce in one tool with SQLite reporting
  • you need TLS, wildcard DNS, and AXFR checks during subdomain enumeration

When to avoid

  • you need a full vulnerability scanner rather than subdomain enumeration
  • you require a GUI or web dashboard instead of a CLI
  • you need non-DNS asset discovery like port scanning or screenshotting

Facets

cli-tool · maturity active

security penetration-testing http-client cli security penetration-testing developer-tools python cli windows cross-platform subdomain-enumeration recon bugbounty dns bruteforce osint async command-line linux macos

2 sources

Member repositories

RepositoryRoleHealth v2
guelfoweb/knockpymain64

For agents

markdown · JSON · MCP: product_card(name="guelfoweb/knockpy")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem