Skip to content

DorkX

Reconnaissance CLI

I built DorkX as an open-source reconnaissance CLI for collecting and processing target URLs through search-engine dorking workflows. I designed it for security reconnaissance, OSINT and target URL discovery.

$ dorkx -q "site:target.com" -o results.txt
[+] querying search engine index endpoints
[+] parsing query operators and patterns
[+] collecting target URL candidates
[+] normalizing and filtering unique URLs
✓ target URLs collected — written to results.txt
Category
OSINT / Reconnaissance / CLI
Language
Go (Golang)
Platform
Linux
Repository
Open Source on GitHub

Problem & Purpose

Advanced search engine dorking is one of the most effective passive reconnaissance techniques for identifying exposed administrator panels, configuration files, leaked documentation, and hidden API paths. However, running dork queries manually through web browsers is tedious, rate-limited, and difficult to automate into repeatable workflows.

I developed DorkX to turn search engine dorking into a rapid, automated command-line operation. The tool automates querying, extracts results, cleans tracking parameters, dedupes URLs, and outputs clean target lists ready for security analysis.

What Was Built & Key Features

A command-line tool focused on query parsing, URL normalization, and clean output:

  • Automated search query execution supporting standard dork operators.
  • URL extraction and normalization, stripping tracking parameters and duplicates.
  • Output formatting to plaintext files or standard terminal stdout.
  • Compiled Go binary with zero external runtime dependencies.
  • Easily chained into broader reconnaissance pipelines and shell scripts.
  • Error handling and query pacing to handle request limits cleanly.

Technical Implementation

Built in Go with clean CLI argument parsing and structured network request handling:

Go (Golang)OSINTReconnaissanceCLI ToolingLinuxURL Processing