Skip to content

recon scan target.com

Reconnaissance to report, in one pass.

RECON plans the sweep for a target, runs the tooling, deduplicates what comes back, and writes the findings up in the format your program expects. Built for researchers who would rather read results than babysit a scan.

Go 1.22+ · MIT · self-hosted, no telemetry

Workflow

Four stages, one command.

Most recon work is glue: run a tool, parse its output, pipe it into the next one, then write it all up by hand at midnight. RECON exists to hold that glue.

bash
recon scan target.com \
    -v xss,sqli,ssrf,idor \
    -d deep
  1. 01

    plan

    The target and the vulnerability classes you care about go in. RECON returns an execution plan: which tools run, with which arguments, in which order.

  2. 02

    execute

    nuclei, httpx, ffuf and subfinder run under one orchestrator. Output is captured as structured findings instead of raw console soup.

  3. 03

    correlate

    Duplicate hits collapse, findings are scored by severity and confidence, and each one gets a proof of concept, an impact note, and a remediation line.

  4. 04

    report

    A Markdown report laid out the way bug bounty triagers read, plus JSON for anything you want to wire into a pipeline.

Capabilities

What the pipeline handles for you.

Structured findings
Every tool writes into one schema, so a nuclei hit and an ffuf hit are the same shape downstream.
Severity-aware scoring
Confidence and priority are derived from the finding itself, not from whoever shouts loudest in the channel.
Proof of concept per finding
A runnable request next to the result, so a triager can reproduce it without guessing.
Report formats that match intake
Markdown for humans, JSON for pipelines. Built around how programs actually read submissions.
No outbound telemetry
Runs on your machine or your VPS. Findings leave only when you send them.
Extensible tool layer
The executor is a thin wrapper. Add a tool, register a parser, keep the rest of the pipeline unchanged.

Coverage

Twelve vulnerability classes mapped to nuclei tags.

Pass a class name on the command line and RECON resolves it to the right template tags. Nothing here is a guarantee of coverage on your target; it is the mapping the planner starts from.

Supported vulnerability classes and their descriptions
ClassDescription
xssCross-site scripting
sqliSQL injection
ssrfServer-side request forgery
idorInsecure direct object reference
auth-bypassAuthentication bypass
rceRemote code execution
lfiLocal file inclusion
rfiRemote file inclusion
xxeXML external entity
sstiServer-side template injection
prototypePrototype pollution
deserializeInsecure deserialization

Install

Clone it and run it.

The install script pulls the tooling RECON drives. If you already have nuclei, httpx, ffuf and subfinder on your PATH, skip it and build.

Found a bug in RECON, or want to talk about a finding? Open an issue on GitHub. That is the fastest channel and it keeps a public record.

bash
git clone https://github.com/mift-enterprise/recon
cd recon
make install-tools
make build

./build/recon scan target.com \
    -v xss,sqli,ssrf,idor \
    -d normal

output/target.com-<timestamp>/report.md