A 68-dork recon arsenal across Google/Bing/DuckDuckGo, GitHub and Shodan - pre-built for sensitive data, secrets and attack surface.
Dork Builder turns a domain (or org/keyword) into 68+ ready advanced search queries that surface exposed files, login portals, sensitive directories, leaked credentials, vulnerable parameters and a target’s attack surface - no operator memorising required.
It spans three engine families: web search (Google, with the same dorks one-click-openable in Bing & DuckDuckGo), GitHub code search (API keys, .env, private keys, DB strings, kubeconfig…) and Shodan (host/cert/org recon and exposed RDP/DB/login services). Dorks are grouped into categories - recon, files, secrets, login, params, errors, API, cloud and third-party leaks - so you can filter to exactly what you need.
Each dork has copy & one-click-open buttons (plus copy-all), and queries auto-fill with your target. The Shodan favicon dork plugs in the hash from the Tech Fingerprint tool to find every host serving the same app.
.git, docs, params, errors, phpinfo..env, id_rsa, configs, DB strings, kubeconfig.Searching public indexes is legal; accessing or using exposed data you find still requires authorization. Stay within your engagement scope.
Mostly - the core operators (site:, inurl:, intitle:, ext:/filetype:) are supported, but Bing and DuckDuckGo implement a subset of Google’s syntax, so very complex dorks may need trimming.