Recon Dork Generator for Google, GitHub and Shodan

Enter a target domain and, optionally, the organization name and extra keywords. This tool composes correctly-escaped, URL-encoded search queries across Google, Bing, GitHub code search and Shodan, grouped by recon objective, with ready-to-click links and copyable raw strings.

Root or apex domain. Protocol and path are stripped automatically.
Used for GitHub org: and Shodan org:/title filters.
Appended to a keyword-targeted dork in each engine.
Use only against assets you are explicitly authorized to test. Passive search-engine recon is legal, but acting on found data can cross into unauthorized access.

How the dorks are built

Every query is assembled from real search-engine operators, then run through encodeURIComponent() so spaces, quotes, colons and pipes survive as a valid URL. Each engine uses its own endpoint: Google google.com/search?q=, Bing bing.com/search?q=, GitHub code search github.com/search?q=&type=code, and Shodan shodan.io/search?query=. Multi-word values such as an org name or a keyword are wrapped in double quotes before encoding so the operator binds to the whole phrase, not just the first token.

Google and Bing dorks combine site:, inurl:, intitle: and filetype:/ext: to surface exposed configs (.env, .yml, .ini), database and log dumps (.sql, .bak, .log), login panels, open directory listings (intitle:"index of"), exposed VCS folders (.git, .svn), and cloud buckets on s3.amazonaws.com and storage.googleapis.com. Subdomain discovery uses site:*.domain -www to list indexed hosts beyond the apex. GitHub dorks pair the literal domain string or org: with high-signal secret markers: filename:.env, AWS_SECRET, api_key, password, and extension:pem. Shodan filters pivot on infrastructure metadata: hostname:, ssl.cert.subject.cn:, http.title: and org:.

The counters are plain arithmetic. The tool tallies how many valid queries it produced (total), splits that by engine, and computes an input coverage score as coverage = round(fieldsProvided / 3 * 100), where the three fields are domain, org and keywords. Org- and keyword-gated dorks are only emitted when their input is non-empty, so filling more fields unlocks more queries and raises both the total and the coverage percentage. An empty or malformed domain field falls back to a neutral placeholder so the page never throws.

Related Tools

Subdomain Finder DNS Lookup Tool Nmap Command Generator