finds.dev← search

// the find

tomnomnom/hacks

★ 2,516 · Go · updated Mar 2025

A collection of hacks and one-off scripts

This is tomnomnom's junk drawer — dozens of small, single-purpose Go (and occasional PHP/JS) scripts he wrote for bug bounty recon work. It's the original home of several tools that later graduated to their own repos and became genuinely popular (waybackurls, assetfinder, qsreplace, unfurl, kxss, fff), plus a long tail of stuff that never went anywhere. Best for security researchers who want to read small, focused recon tools or dig up the origin version of something they already use.

Several of the subfolders are the original implementations of tools that are now standalone and widely used in the recon/bug-bounty world — reading them here shows the idea in its simplest, single-file form before it accreted flags and features. Each script is small and does one Unix-philosophy thing (pipe in, transform, pipe out), so you can read most of them in under five minutes and lift just the part you need instead of depending on a framework. Written by someone who actually used these day to day on live engagements, so the logic reflects real recon workflows, not synthetic examples.

There's no root go.mod — this isn't one project, it's dozens of independent scripts at wildly different maturity levels, and several subfolders predate Go modules entirely, so nothing here builds as a whole and some individual pieces won't build at all without manual fixing. Near-zero test coverage outside a couple of folders (unfurl, inscope, kxss have a test file or two) and no CI, so correctness is whatever the author eyeballed at the time. It's effectively a graveyard now — the tools that mattered moved out to their own repos years ago, so what's left is mostly abandoned one-offs; don't expect fixes or responses to issues on anything still living here.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →