RECON-NG
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Interactive tool: Recon / OSINT Helper
OVERVIEW#
Recon-ng is a full-featured web reconnaissance framework written in Python. It provides a powerful environment similar to Metasploit for conducting open source web-based reconnaissance.
LAUNCHING#
recon-ng # Start interactive console recon-ng -w <workspace> # Start with specific workspace recon-ng -r <script> # Execute resource script
WORKSPACES#
workspaces list # List workspaces workspaces create <name> # Create new workspace workspaces load <name> # Switch to workspace workspaces remove <name> # Delete workspace
MARKETPLACE (MODULES)#
marketplace search # List all available modules marketplace search <keyword> # Search for modules marketplace info <module> # Show module info marketplace install <module> # Install module marketplace remove <module> # Uninstall module
MODULE CATEGORIES#
# Discovery modules: recon/domains-hosts/ # Domain → hosts/subdomains recon/domains-contacts/ # Domain → contacts recon/hosts-hosts/ # Host → related hosts recon/netblocks-hosts/ # Netblock → hosts recon/contacts-credentials/ # Contacts → leaked credentials # Import modules: import/csv_file # Import CSV data import/list # Import list of items import/nmap # Import nmap XML output # Reporting modules: reporting/html # HTML report reporting/csv # CSV export reporting/json # JSON export reporting/xlsx # Excel export reporting/xml # XML export
USING MODULES#
modules search <keyword> # Search loaded modules modules load <module> # Load a module info # Show module info/options options list # Show all options options set <option> <value> # Set option value options unset <option> # Clear option value run # Execute module back # Return to main menu
DATABASE OPERATIONS#
db schema # Show database schema db query <sql> # Run SQL query # View collected data: show hosts # List discovered hosts show contacts # List discovered contacts show credentials # List found credentials show domains # List target domains show companies # List companies show netblocks # List network blocks show ports # List discovered ports show profiles # List social profiles # Add data manually: db insert domains <domain> # Add target domain db insert hosts <host> # Add target host db insert contacts # Add contact info db delete hosts # Delete host entries
API KEYS#
keys list # Show configured API keys keys add <name> <value> # Add API key keys remove <name> # Remove API key # Common API keys needed: # bing_api - Bing search # builtwith_api - BuiltWith technology lookup # censysio_id/secret - Censys.io # fullcontact_api - FullContact # github_api - GitHub search # google_api - Google search # hashes_api - Hashes.org # hunter_api - Hunter.io email search # ipinfodb_api - IP geolocation # shodan_api - Shodan search # twitter_api/secret - Twitter # virustotal_api - VirusTotal
COMMON WORKFLOWS#
# Subdomain enumeration: modules load recon/domains-hosts/hackertarget options set SOURCE example.com run # Contact/email harvesting: modules load recon/domains-contacts/whois_pocs options set SOURCE example.com run # DNS brute force: modules load recon/domains-hosts/brute_hosts options set SOURCE example.com run # Check for credential leaks: modules load recon/contacts-credentials/hibp_breach run
SNAPSHOTS#
snapshots take # Save current database state snapshots list # List saved snapshots snapshots load <name> # Restore snapshot
RESOURCE SCRIPTS#
# Save commands to a file and replay: spool start /tmp/recon-output.txt # Start logging # ... run commands ... spool stop # Stop logging
EXAMPLES#
# Full domain recon workflow workspaces create target_recon db insert domains example.com modules load recon/domains-hosts/hackertarget options set SOURCE example.com run show hosts modules load reporting/html options set FILENAME /tmp/report.html run
NOTES#
- Modular framework - install only needed modules - Persistent database stores all findings - API keys improve results significantly - Workspaces keep different engagements separate - Resource scripts enable automation - Data persists between sessions - Export reports for documentation