FOFA API Tools

FOFA has selected multiple tools to improve asset collection efficiency, all integrated with the FOFA API.

FOFA Open Source Support
GoFOFA
Data Processing
Information Gathering

A CLI tool for efficient metadata-to-business data conversion, with basic interface calls and data processing.

Y13ze
Source: github
fofa_viewer
Ready-to-Use
Friendly UI
1k+ stars

A JavaFX-based FOFA client that simplifies access to FOFA's powerful search engine with a concise UI.

WgpSec
Source: github
fofax
Features
Cross-Platform

A fast, simple FOFA query tool written in Go, with customizable FX syntax queries via a YAML config file.

xiecat
Source: github
FofaMap v2.0
FOFA Co-Creator
ai-agent
asset-mapping

FofaMap v2.0 is the first AI-powered red team asset intelligence agent developed in Python 3. Building on its core functions—such as FOFA data collection, host discovery, statistical aggregation, icon hashing, and batch querying—version 2.0 natively supports the MCP protocol, enabling seamless integration with AI platforms like Cursor and Claude. Its built-in AI self-reflection mechanism automatically optimizes search syntax based on query results and intelligently links with Nuclei to recommend precise scanning strategies. This evolution shifts red team operations from passive data collection to proactive, intelligent decision-making.

Hx0
Source: github
fofa-py
SDK
Python
FOFA Co-Creator

A simple Python wrapper for the FOFA API (supports Python), enabling easy integration of FOFA data into projects.

ntestoc3
Source: github
fofa-java
SDK
Java
FOFA Co-Creator

A Java SDK for FOFA Pro API, simplifying integration for Java developers.

xxxxbxxxxx
Source: github
kscan
Full Scan
Brute Force
3k+ stars

An asset mapping tool for port scanning, TCP fingerprinting, banner capture, and brute force cracking, with minimal packet usage. It is the first open-source RDP brute force tool on the Go platform.

kv2
Source: github
CyberStrikeAI
ai-cybersecurity
ai-security-tool
ai-agents

CyberStrikeAI is an AI-native security testing platform built in Go. It integrates 100+ security tools, an intelligent orchestration engine, and comprehensive lifecycle management capabilities.

Ed1s0nZ
Source: github
Space_view
Browser plugin
FOFA Co-Creator

A Tampermonkey script that displays Fofa assets, providing a quick and intuitive overview of a website's assets.

0cat
Source: github
superSearchPlus
Browser plugin
FOFA Co-Creator

A comprehensive info-gathering plugin for asset mapping, data collection, sensitive info extraction, and scanning (JS, directory, Vue), integrating popular platforms.

dark-kingA
Source: github
RongIOC
APT
Threat Intelligence
Automatic

Cyberspace Mapping APT Automated Line Extension Tool

Fkalis
Source: github
Milkyway
Comprehensive Scan
FOFA Co-Creator

Milkyway is an all-in-one scanning tool with efficient features for host discovery, port scanning, protocol identification, fingerprinting, vulnerability scanning, and more.

polite-007
Source: github
ShuiZe
Asset Mapping
3k+ stars

Assist the attacker to quickly collect information, map target assets, and find weaknesses. Simply enter the root domain name to collect all relevant assets and detect vulnerabilities.

Ske
Source: github
TestNet
Asset Management
Custom Scan Scripts
Advanced Search

The TestNet Asset Management System aims to provide comprehensive and efficient internet asset management and monitoring services, building a detailed asset information library. This system can help enterprise security teams or penetration testers conduct in-depth reconnaissance and analysis of target assets, provide continuous risk monitoring from an attacker's perspective, assist users in real-time understanding of asset dynamics, identify and fix security vulnerabilities, effectively reduce the attack surface, and enhance overall security protection capabilities.

testnet0
Source: github
reconftw
Vuln Scan
5k+ stars

ReconFTW is an automated reconnaissance tool for target domains, performing scans, vulnerability checks, and subdomain enumeration to gather maximum information.

six2dez
Source: github
OneForAll
Asset Mapping
8k+ stars

OneForAll is a powerful subdomain collection tool.

shmilylty
Source: github
uncover
Asset Mapping
2k+ stars

Quickly discover exposed hosts on the internet using multiple search engines.

ProjectDiscovery
Source: github
amass
Asset Mapping
12k+ stars

In-depth attack surface mapping and asset discovery.

OWASP Amass
Source: github