Skip to content

Latest commit

Β 

History

19 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

Red_Hawk

Image

cat << 'READMEEOF' > README.md

πŸ”΄ RED HAWK v3.0

Ultimate OSINT Reconnaissance Framework

Developer: Maxod anonmoty πŸ”°
GitHub: github.com/anonmoty/Red_Hawk

Typing SVG

---

Typing SVG



β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—     β–ˆβ–ˆβ•—  β–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•—    β–ˆβ–ˆβ•—β–ˆβ–ˆβ•—  β–ˆβ–ˆβ•—
β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•”β•β•β•β•β•β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—    β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘    β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ•”β•
β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘    β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘ β–ˆβ•— β–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β• 
β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•”β•β•β•  β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘    β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•— 
β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•    β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β•šβ–ˆβ–ˆβ–ˆβ•”β–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•—
β•šβ•β•  β•šβ•β•β•šβ•β•β•β•β•β•β•β•šβ•β•β•β•β•β•     β•šβ•β•  β•šβ•β•β•šβ•β•  β•šβ•β• β•šβ•β•β•β•šβ•β•β• β•šβ•β•  β•šβ•β•

                [ Recon | Scan | Hunt ]

⚠️ Legal Disclaimer

╔══════════════════════════════════════════════════════════════════════╗
β•‘                                                                      β•‘
β•‘   RED_HAWK is an information gathering and vulnerability scanning    β•‘
β•‘   tool built for EDUCATIONAL and AUTHORIZED testing purposes only.   β•‘
β•‘                                                                      β•‘
β•‘   β–Έ Use ONLY on targets you have permission to test.                 β•‘
β•‘   β–Έ Unauthorized scanning is ILLEGAL.                                β•‘
β•‘   β–Έ Always follow the bug bounty program's scope and rules.          β•‘
β•‘   β–Έ The author is NOT responsible for any misuse.                    β•‘
β•‘                                                                      β•‘
β•‘   Hack responsibly. Hunt ethically. Report responsibly.              β•‘
β•‘                                                                      β•‘
β•šβ•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•

🎯 Overview

RED_HAWK is a powerful information gathering and vulnerability scanning tool written in PHP. It is designed for penetration testers, bug bounty hunters, and security researchers who need to collect intelligence about a target before exploitation.

Whether you're mapping a target's infrastructure or hunting for misconfigurations β€” RED_HAWK gives you the recon advantage you need.


✨ Core Features

Feature Description
πŸ•ΈοΈ Information Gathering Collects target intel efficiently
πŸ” Vulnerability Scanner Detects common security misconfigurations
🌐 Site Crawling Maps internal and external links
πŸ›‘οΈ Header Analysis Inspects HTTP response headers
πŸ“‘ DNS Lookup Resolves and maps DNS records
πŸ§ͺ XSS Detection Scans for cross-site scripting flaws
πŸ’‰ SQLi Detection Checks for injection vulnerabilities
πŸ“Š Structured Output Clean, readable scan results
🎨 Hacker Terminal UI Red-on-black aesthetic
⚑ Fast Execution Lightweight and quick

🧠 How It Works

graph TD
    A[Start] --> B[Input Target]
    B --> C[Information Gathering]
    C --> D[DNS & Header Analysis]
    D --> E[Site Crawling]
    E --> F{Vulnerability Check}
    F -->|XSS| G[Log Finding]
    F -->|SQLi| H[Log Finding]
    F -->|Safe| I[Next Endpoint]
    G --> J[Generate Report]
    H --> J
    I --> F
    J --> K[Done]

    style A fill:#1a0000,stroke:#CC0000,color:#FF4500
    style G fill:#1a0000,stroke:#CC0000,color:#FF4500
    style H fill:#1a0000,stroke:#CC0000,color:#FF4500
    style K fill:#1a0000,stroke:#CC0000,color:#FF4500
Loading
  1. Input β€” Takes the target URL
  2. Gather β€” Collects all available information
  3. Analyze β€” Checks DNS, headers, and responses
  4. Crawl β€” Maps the site's internal structure
  5. Scan β€” Tests for XSS, SQLi, and misconfigurations
  6. Report β€” Displays structured findings

πŸ“ Project Structure

RED_HAWK/
β”œβ”€β”€ redhawk.php               # Main entry point
β”œβ”€β”€ core/
β”‚   β”œβ”€β”€ info.php              # Information gathering
β”‚   β”œβ”€β”€ scanner.php           # Vulnerability scanner
β”‚   β”œβ”€β”€ crawler.php           # Site crawler
β”‚   └── reporter.php          # Report generator
β”œβ”€β”€ payloads/
β”‚   β”œβ”€β”€ xss.txt               # XSS payloads
β”‚   └── sqli.txt              # SQLi payloads
β”œβ”€β”€ reports/                  # Generated reports
β”œβ”€β”€ LICENSE
└── README.md

πŸ“Έ Demo

╔═════════════════════════════════════════════════════════════╗
β•‘  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—     β–ˆβ–ˆβ•—  β–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•—    β–ˆβ–ˆβ•—β–ˆβ–ˆβ•—  β–ˆβ–ˆβ•— β•‘
β•‘  β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•”β•β•β•β•β•β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—    β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘    β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ•”β• β•‘
β•‘  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘    β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘ β–ˆβ•— β–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•  β•‘
β•‘  β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•”β•β•β•  β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘    β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•—  β•‘
β•‘  β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•    β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β•šβ–ˆβ–ˆβ–ˆβ•”β–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•— β•‘
β•‘  β•šβ•β•  β•šβ•β•β•šβ•β•β•β•β•β•β•β•šβ•β•β•β•β•β•     β•šβ•β•  β•šβ•β•β•šβ•β•  β•šβ•β• β•šβ•β•β•β•šβ•β•β• β•šβ•β•  β•šβ•β• β•‘
β•šβ•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•

[βœ“] Target: https://target.com
[βœ“] Modules: Info | Scan | Crawl
[β†’] Gathering intel...

[β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘β–‘] 80% | 800/1000 checks
[!] XSS Found: /search?q=
[!] SQLi Found: /login?id=
[βœ“] Scan complete in 6.12s
[βœ“] Report: reports/redhawk_2024.json

        Happy Hunting! 🎯

🎨 Hacker Terminal Theme

RED_HAWK uses a deep red + neon orange theme by default:

THEME = {
    "primary":   "\033[38;5;196m",  # Bright Red
    "secondary": "\033[38;5;202m",  # Orange
    "accent":    "\033[38;5;214m",  # Amber
    "error":     "\033[38;5;196m",  # Red
    "warning":   "\033[38;5;220m",  # Yellow
    "info":      "\033[38;5;202m",  # Orange
    "reset":     "\033[0m",         # Reset
}

πŸ”₯ Power User Tips

Combine with Other Tools

# Red_Hawk + subdomain enumeration
subfinder -d target.com | httpx | while read url; do
    php redhawk.php -u "$url"
done

# Red_Hawk + nuclei
php redhawk.php -u https://target.com -o recon.json
nuclei -u https://target.com -t ~/nuclei-templates/

Speed Optimization

# Stealth mode (slower but safer)
php redhawk.php -u https://target.com --delay 2

# Full power mode
php redhawk.php -u https://target.com --threads 20

πŸ› Bug Bounty Workflow

RED_HAWK fits perfectly into your recon pipeline:

1. Subdomain Enumeration  β†’  amass / subfinder
2. Live Host Detection    β†’  httpx
3. Information Gathering  β†’  RED_HAWK  ← you are here
4. Endpoint Analysis      β†’  grep, waybackurls
5. Vulnerability Scanning β†’  nuclei, XSStrike
6. Manual Testing         β†’  Burp Suite

Use Cases for Hunters

  • πŸ” Information gathering on any target
  • πŸ“œ DNS and header analysis for recon
  • πŸ—ΊοΈ Site crawling for hidden endpoints
  • πŸ§ͺ XSS and SQLi detection in one tool
  • πŸ“Š Structured reports for documentation

πŸ—ΊοΈ Roadmap

  • Information gathering
  • Vulnerability scanning
  • Site crawling
  • Hacker terminal UI
  • JavaScript secret scanner
  • Wayback Machine integration
  • Subdomain auto-discovery
  • Docker image
  • Web dashboard

🀝 Contributing

Contributions are welcome. Please follow these steps:

  1. Fork the repository
  2. Create your branch (git checkout -b feature/amazing-feature)
  3. Commit your changes (git commit -m 'Add amazing feature')
  4. Push to the branch (git push origin feature/amazing-feature)
  5. Open a Pull Request

πŸ“œ License

Distributed under the MIT License. See LICENSE for more information.


πŸ™ Credits

  • Author: @anonmoty
  • Inspired by: The original RED_HAWK by Tuhinshubhra
  • Built with: PHP, caffeine, and curiosity β˜•

Footer



⭐ If this tool helped you in your hunt, drop a star!

πŸ“– Description

RED HAWK is a powerful, multi-threaded OSINT (Open Source Intelligence) reconnaissance framework designed for security professionals, penetration testers, bug bounty hunters, and cybersecurity students.

It automates the information gathering phase of security assessments by collecting publicly available data about a target domain through 18+ integrated modules β€” all from a single interactive terminal interface.

⚠️ DISCLAIMER: This tool is built for educational and authorized security testing purposes only. The developer is NOT responsible for any misuse or illegal activity. Always obtain written permission before testing any target.


✨ Key Features

Feature Description
🎯 18+ OSINT Modules WHOIS, DNS, Subdomains, Headers, GeoIP, Ports, SSL, and more
⚑ Multi-Threaded Scanning Port scanner & subdomain brute-force with 50 concurrent threads
πŸ“Š Auto Report Generation Exports results in JSON, HTML, and TXT formats
πŸ” Subdomain Enumeration 4 methods: DNS Brute, crt.sh, HackerTarget, RapidDNS
πŸ›‘οΈ Security Headers Audit HSTS, CSP, XFO, XCTO scoring with grade (A+ to F)
πŸ” SSL/TLS Analysis Certificate details, expiry check, cipher suite info
πŸ—οΈ CMS Detection WordPress, Joomla, Drupal, Magento, Shopify, PrestaShop
πŸ›‘οΈ WAF Detection 14+ firewall signatures (Cloudflare, AWS, Akamai, etc.)
πŸ”— CORS Misconfiguration 5 origin-based tests for CORS vulnerabilities
πŸ–±οΈ Clickjacking Test X-Frame-Options & CSP check with PoC generation
πŸ“§ Email Harvester Scraping + pattern-based email discovery
πŸ“œ Wayback Machine Historical URLs from Archive.org CDX API
πŸ•·οΈ Link Crawler Internal/External links + resources + forms
πŸ”„ Reverse IP Lookup Find all domains hosted on same IP
πŸ“± Social Media Finder 11 platforms (Twitter, GitHub, LinkedIn, etc.)
πŸ€– Robots.txt Analysis Disallowed paths + sitemap extraction
🌍 IP Geolocation Country, City, ISP, Coordinates, Maps link
🎨 Beautiful CLI Colored output, progress bars, interactive menu
πŸ“± Termux Compatible Fully optimized for Android/Termux

πŸ“ Project Structure

πŸ”° About Developer Info Details Name Maxod anonmoty GitHub @anonmoty Tool RED HAWK v3.0 Purpose Educational & Authorized Security Testing


πŸš€ Installation

Termux (Android)

# Update packages
pkg update && pkg upgrade -y

# Install dependencies
pkg install python git

# Clone the repository
git clone https://github.com/anonmoty/Red_Hawk.git

# Navigate to directory
cd Red_Hawk
#fikw.list 

ls

# Install Python packages
pip install -r requirements.txt

# Run the tool
python start.py

About

RED_HAWK - Information Gathering, Vulnerability Scanning & Crawling Tool. PHP based XSS/SQLi scanner for penetration testers

Topics

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages