What problem does it solve?
Network reconnaissance is a foundational security activity that helps teams understand exposure and risk. Recon automates the mapping of domains, IPs, netblocks, and assets to reveal attack surfaces, relationships, and potential blind spots.
Core Features & Use Cases
- Passive reconnaissance: WHOIS lookups, DNS enumeration, certificate transparency, IPInfo data, reverse DNS, historical DNS, and public database queries to build a baseline asset map.
- Active reconnaissance: Authorized port scanning, service fingerprinting, TLS/SSL analysis, live-host discovery, and asset validation to identify in-scope targets for assessment.
- OSINT integration and workflows: orchestration of OSINT results with infrastructure mapping, domain/netblock discovery, and cross-skill coordination for bug-bounty and threat-intelligence tasks.
Quick Start
Invoke Recon with a target to begin passive reconnaissance and map the infrastructure.