FOFA API Tools

FOFA has selected multiple tools to improve asset collection efficiency, all integrated with the FOFA API.

FOFA Open Source Support
GoFOFA
Data Processing
Information Gathering

A CLI tool for efficient metadata-to-business data conversion, with basic interface calls and data processing.

Y13ze
Source: github
fofa_viewer
Ready-to-Use
Friendly UI
1k+ stars

A JavaFX-based FOFA client that simplifies access to FOFA's powerful search engine with a concise UI.

WgpSec
Source: github
fofax
Features
Cross-Platform

A fast, simple FOFA query tool written in Go, with customizable FX syntax queries via a YAML config file.

xiecat
Source: github
FofaMap
No-Duplicate
FOFA Co-Creator

FofaMap is a cross-platform FOFA data collector in Python3, supporting query, aggregation, survival detection, and duplicate removal, with keyword filtering and Excel report generation.

Hx0
Source: github
fofa-py
SDK
Python
FOFA Co-Creator

A simple Python wrapper for the FOFA API (supports Python), enabling easy integration of FOFA data into projects.

ntestoc3
Source: github
fofa-java
SDK
Java
FOFA Co-Creator

A Java SDK for FOFA Pro API, simplifying integration for Java developers.

xxxxbxxxxx
Source: github
kscan
Full Scan
Brute Force
3k+ stars

An asset mapping tool for port scanning, TCP fingerprinting, banner capture, and brute force cracking, with minimal packet usage. It is the first open-source RDP brute force tool on the Go platform.

kv2
Source: github
Space_view
Browser plugin
FOFA Co-Creator

A Tampermonkey script that displays Fofa assets, providing a quick and intuitive overview of a website's assets.

0cat
Source: github
superSearchPlus
Browser plugin
FOFA Co-Creator

A comprehensive info-gathering plugin for asset mapping, data collection, sensitive info extraction, and scanning (JS, directory, Vue), integrating popular platforms.

dark-kingA
Source: github
ShuiZe
Asset Mapping
3k+ stars

Assist the attacker to quickly collect information, map target assets, and find weaknesses. Simply enter the root domain name to collect all relevant assets and detect vulnerabilities.

Ske
Source: github
reconftw
Vuln Scan
5k+ stars

ReconFTW is an automated reconnaissance tool for target domains, performing scans, vulnerability checks, and subdomain enumeration to gather maximum information.

six2dez
Source: github
OneForAll
Asset Mapping
8k+ stars

OneForAll is a powerful subdomain collection tool.

shmilylty
Source: github
uncover
Asset Mapping
2k+ stars

Quickly discover exposed hosts on the internet using multiple search engines.

ProjectDiscovery
Source: github
amass
Asset Mapping
12k+ stars

In-depth attack surface mapping and asset discovery.

OWASP Amass
Source: github