{"categories":[{"label":"Security","url":"https://skillfed.io/packages/category/security/3"}],"enrichment":{"capability":"BBOT is a multipurpose reconnaissance and vulnerability scanner that automates subdomain enumeration, web crawling, email discovery, and security scanning across targets ranging from domains to IP ranges to URLs.","skillfed_tags":["osint-framework","attack-surface-mapping","security-automation"],"use_cases":["Enumerate subdomains of a target domain using passive APIs and recursive DNS brute-force with target-specific mutations.","Crawl a website to extract emails, URLs, and other reconnaissance data while respecting session integrity.","Scan an entire IP range or multiple targets in parallel to map an organization's attack surface.","Integrate reconnaissance into a security workflow via Python API for synchronous or asynchronous event processing.","Output scan results directly to Neo4j, Elasticsearch, or messaging platforms for real-time analysis and alerting."],"what_it_does":"BBOT is a modular security scanner designed for reconnaissance, bug bounties, and attack surface management. It combines passive API sources with active techniques like DNS brute-forcing and web crawling to discover subdomains, email addresses, web vulnerabilities, and other reconnaissance data. The tool accepts multiple target types\u2014domains, IPs, IP ranges, URLs, emails, and more\u2014and can run preset scanning profiles (subdomain-enum, spider, email-enum, web, kitchen-sink) or be customized with individual modules.\n\nAs a Python library or CLI tool, BBOT outputs findings to multiple formats including Neo4j, databases, messaging platforms, and standard files. It emphasizes automation and scale: recursive DNS mutations, NLP-powered subdomain generation, web screenshots, and integration with Ansible for dependency management. The active maintenance, large dependency footprint, and AGPL license reflect its role as a comprehensive framework rather than a lightweight utility.","worth_installing":"Yes, if you need comprehensive reconnaissance automation for security testing or bug bounties. BBOT is actively maintained, has low install friction, and offers a large module ecosystem. However, verify that AGPL-3.0 licensing aligns with your use case, and be aware that the 36 runtime dependencies add complexity. Not suitable for minimal, lightweight scanning\u2014consider simpler tools if you only need basic subdomain enumeration."},"id":"bbot","links":{"html":"https://skillfed.io/packages/bbot","md":"https://skillfed.io/packages/bbot.md","pypi":"https://pypi.org/project/bbot/"},"maintenance":{"status":"active"},"meta":{"latest_release":"2026-07-21","license_spdx":"AGPL-3.0","license_treatment":"agpl","name":"bbot","python_support":"supports_current","summary":"OSINT automation for hackers."},"popularity":{"monthly_downloads":77007,"position":14560,"tier":"top_15000"},"security":{"n_vulnerabilities":0},"version":"3.0.1"}
