Frogy2.0 - An Automated External Reconnaissance And Attack Surface Management (ASM) Toolkit
Frogy 2.0 is an automated external reconnaissance and Attack Surface Management (ASM) toolkit that maps out an organization's entire internet presence, identifying assets, IP addresses, web applications, and metadata. It prioritizes assets from highest to lowest attractiveness from an attacker's perspective. The toolkit features comprehensive recon, live asset verification, in-depth web recon, smart prioritization, and professional reporting. Risk scoring is based on asset attractiveness, considering factors such as purpose, URLs found, login interfaces, HTTP status, TLS version, certificate expiry, missing security headers, open ports, and technology stack. Each factor contributes to the final risk score, helping bug bounty hunters and pentesters focus on the most promising targets. The tool generates a dynamic, color-coded HTML report with a modern design and dark/light theme toggle. The report provides a risk score for each asset, indicating a broader "attack surface" that adversaries could leverage. Frogy 2.0 helps security teams quickly prioritize which assets warrant deeper testing, focusing on those with high counts of open ports, advanced internal usage, missing headers, or login panels. The toolkit is easy to install and use, with a video demo available. The roadmap for future development includes adding security and compliance-related data, filtering column data, and enhancing prioritization for target picking.