Apify Toolkits
Cyber Recon Toolkit icon

Cyber Recon Toolkit

OSINT, attack-surface recon, and vulnerability intelligence — twelve Actors covering bug bounty programs, TLS/DNS/BGP recon, and web-page fingerprinting.

The problem

NVD's own CVE API is rate-limited to 5 requests per 30 seconds unauthenticated (50 with a free key) — tight enough that real dependency-scanning pipelines break on it, and tight enough that at least one vendor (VulnCheck) sells a paid tier whose entire pitch is removing that limit. Bug bounty researchers face a different problem: no platform shows you scope across Bugcrowd, HackerOne, and Intigriti at once, which is exactly why community tools like bbscope exist — built by researchers tired of checking four platforms separately. This toolkit pulls from a dozen public data sources — bug bounty disclosure feeds, CVE records, TLS/BGP/DNS routing info, and whatever a target website gives away in its tech stack and contact pages — because attack-surface mapping genuinely needs this many angles, and consolidates them into Actors instead of a pile of CLI tools each with their own setup curve.

Who it's for

What's inside

Bug bounty & vulnerability intel
Infrastructure & network recon
Web-target fingerprinting

Why run them together

A typical recon pass: fingerprint the target's tech stack (Wappalyzer) and known URLs (gau), pull contact and repo-commit emails (Universal Contact Extractor, Git Email Extractor), check its TLS/BGP footprint (TLSX, BGP.HE.NET), then cross-reference any exposed software against CVE records and see whether the target already runs a bug bounty program (Bugcrowd/HackerOne/Intigriti) before reporting anything found. Twelve narrow Actors, one attack-surface picture — no NVD rate-limit wall, no juggling four bounty platforms by hand.

FAQ

Do I need accounts on Bugcrowd, HackerOne, and Intigriti to use this toolkit?

No — these Actors read each platform's publicly disclosed data (Hacktivity feeds, program directories, leaderboards); you don't need a researcher account on any of them.

How is this billed?

Pay-per-result, no subscription — no NVD-style rate limit to pay around, and no per-platform bug-bounty API fee.

Can I use just one Actor instead of the whole toolkit?

Yes. Each Actor is independent — run CVE Scraper alone for vulnerability lookups, or add the recon and fingerprinting Actors only when mapping a full attack surface.

Does this replace tools like Amass, Subfinder, or bbscope?

It complements them — these Actors give you the same category of public data (recon, scope aggregation, CVE records) as a hosted, no-setup Apify run instead of a locally installed CLI tool.

Browse all twelve on Apify

Pay-per-result. No subscription. Start with the one you need.

See the Actors ↗