Lightweight bug bounty reconnaissance pipeline that automates discovery, validation, screenshots, port scanning, and vulnerability checks.
Use this only on targets you own or have explicit permission to test.
- Enumerates subdomains with any installed supported tool:
subfinder,assetfinder, oramass. - Normalizes and deduplicates discovered subdomains.
- Checks alive HTTP services with
httpx. - Captures screenshots with
eyewitnesswhen available. - Scans ports with
nmap. - Runs HTTP nuclei templates with
nuclei. - Sends interesting-port notifications with
notify. - Supports concurrent scans for multiple domains.
- Can redirect application logs to a file with
--output-log.
- Python 3.10 or newer
urllib3- At least one subdomain enumeration tool:
subfinderassetfinderamass
- Recommended external tools:
httpxnmapnucleinotifyeyewitness
The scanner skips optional tools that are not installed where possible, but subdomain discovery requires at least one supported enumeration tool.
Install it as an isolated command with pipx:
pipx install git+https://github.com/bern-out/Tocaia.gitThen run:
tocaia -d example.comFor local development, clone the repository and install it in editable mode:
git clone https://github.com/bern-out/Tocaia.git
cd tocaia
python3 -m venv .venv
source .venv/bin/activate
python3 -m pip install -e .Install the external security tools with your preferred package manager or from each tool's official installation instructions.
Scan a single domain:
tocaia -d example.comScan domains from a file:
tocaia -f domains.txtLimit concurrent workers:
tocaia -f domains.txt --max-workers 5Skip honeypot checks:
tocaia -d example.com --ignore-honeypotRedirect application logs to a file:
tocaia -d example.com --output-log logs/tocaia.logShort options are also available:
tocaia -d example.com -mw 5 -igh -o logs/tocaia.logTocaia writes scan output under:
domains/<domain>/
Each run creates a timestamped JSON report:
domains/<domain>/<YYYYMMDD_HHMMSS>.json
When eyewitness is installed, screenshots are written under:
domains/<domain>/eyewitness/
--output-logredirects messages emitted by Tocaia's custom logger. Raw output from external tools is only included when the script captures and logs it.- Full port scans are triggered when interesting ports are found.
- Notifications use
notifywith the configured IDrecon-lab.
This project is licensed under the MIT License. See LICENSE.