Matchboxmatchbox
← Back to match

KnockPy

Async subdomain scanner combining passive recon and bruteforce with TLS, status and IP checks

Desktopfree

KnockPy is an open-source command-line scanner that enumerates the subdomains of a target domain using passive sources, bruteforce, or both. It checks each result's HTTP status, TLS certificate and IP, detects wildcard DNS and zone-transfer exposure, and stores scans in a searchable local database with HTML export. It is aimed at penetration testers and bug bounty hunters assessing an authorised domain.

Categories
SecurityReconnaissanceSubdomain enumeration

Full match profile

Behind the summary, Matchbox keeps a richer profile of KnockPy - the signals our matcher actually reads to decide when to surface it. It stays private; claim the listing to see and control it.

  • Problem & pain-point mapping
  • Who we surface it to (audience fit)
  • What it's a strong alternative to
  • Trust & credibility signals

Try Matchbox with your own problem

Describe what is not working - we’ll show you whether KnockPy (or something else) actually fits.