recon scan target.com
Reconnaissance to report, in one pass.
RECON plans the sweep for a target, runs the tooling, deduplicates what comes back, and writes the findings up in the format your program expects. Built for researchers who would rather read results than babysit a scan.
Go 1.22+ · MIT · self-hosted, no telemetry
Workflow
Four stages, one command.
Most recon work is glue: run a tool, parse its output, pipe it into the next one, then write it all up by hand at midnight. RECON exists to hold that glue.
recon scan target.com \
-v xss,sqli,ssrf,idor \
-d deep- 01
plan
The target and the vulnerability classes you care about go in. RECON returns an execution plan: which tools run, with which arguments, in which order.
- 02
execute
nuclei, httpx, ffuf and subfinder run under one orchestrator. Output is captured as structured findings instead of raw console soup.
- 03
correlate
Duplicate hits collapse, findings are scored by severity and confidence, and each one gets a proof of concept, an impact note, and a remediation line.
- 04
report
A Markdown report laid out the way bug bounty triagers read, plus JSON for anything you want to wire into a pipeline.
Capabilities
What the pipeline handles for you.
- Structured findings
- Every tool writes into one schema, so a nuclei hit and an ffuf hit are the same shape downstream.
- Severity-aware scoring
- Confidence and priority are derived from the finding itself, not from whoever shouts loudest in the channel.
- Proof of concept per finding
- A runnable request next to the result, so a triager can reproduce it without guessing.
- Report formats that match intake
- Markdown for humans, JSON for pipelines. Built around how programs actually read submissions.
- No outbound telemetry
- Runs on your machine or your VPS. Findings leave only when you send them.
- Extensible tool layer
- The executor is a thin wrapper. Add a tool, register a parser, keep the rest of the pipeline unchanged.
Coverage
Twelve vulnerability classes mapped to nuclei tags.
Pass a class name on the command line and RECON resolves it to the right template tags. Nothing here is a guarantee of coverage on your target; it is the mapping the planner starts from.
| Class | Description |
|---|---|
| xss | Cross-site scripting |
| sqli | SQL injection |
| ssrf | Server-side request forgery |
| idor | Insecure direct object reference |
| auth-bypass | Authentication bypass |
| rce | Remote code execution |
| lfi | Local file inclusion |
| rfi | Remote file inclusion |
| xxe | XML external entity |
| ssti | Server-side template injection |
| prototype | Prototype pollution |
| deserialize | Insecure deserialization |
Install
Clone it and run it.
The install script pulls the tooling RECON drives. If you already have nuclei, httpx, ffuf and subfinder on your PATH, skip it and build.
Found a bug in RECON, or want to talk about a finding? Open an issue on GitHub. That is the fastest channel and it keeps a public record.
git clone https://github.com/mift-enterprise/recon
cd recon
make install-tools
make build
./build/recon scan target.com \
-v xss,sqli,ssrf,idor \
-d normaloutput/target.com-<timestamp>/report.md