Frogy 2.0 is an automated external reconnaissance and Attack Surface Management (ASM) toolkit designed to map an organization's entire internet presence. It identifies assets, IP addresses, web applications, and other metadata across the public internet, then smartly prioritizes them from an attacker's perspective.
Key Features:
1. Aggregates subdomains using multiple tools (CHAOS, Subfinder, Assetfinder, crt.sh) to map an organization's entire digital footprint.
2. Validates assets with live DNS resolution and port scanning (using DNSX and Naabu) to confirm what is publicly reachable.
3. Collects detailed HTTP response data (via HTTPX) including metadata, technology stack, status codes, content lengths, and more.
4. Uses a composite scoring system that considers homepage status, login identification, technology stack, and DNS data to generate a risk score for each asset.
5. Generates a dynamic HTML report with a modern design.
https://github.com/iamthefrogy/frogy2.0
#bugbountytips
Post #555
1.99K

- ❤ 9
- 👍 1