← All cheat sheets

RECON-NG

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Interactive tool: Recon / OSINT Helper

OVERVIEW#

Recon-ng is a full-featured web reconnaissance framework written in
Python. It provides a powerful environment similar to Metasploit for
conducting open source web-based reconnaissance.

LAUNCHING#

recon-ng                         # Start interactive console
recon-ng -w <workspace>          # Start with specific workspace
recon-ng -r <script>             # Execute resource script

WORKSPACES#

workspaces list                  # List workspaces
workspaces create <name>         # Create new workspace
workspaces load <name>           # Switch to workspace
workspaces remove <name>         # Delete workspace

MARKETPLACE (MODULES)#

marketplace search               # List all available modules
marketplace search <keyword>     # Search for modules
marketplace info <module>        # Show module info
marketplace install <module>     # Install module
marketplace remove <module>      # Uninstall module

MODULE CATEGORIES#

# Discovery modules:
recon/domains-hosts/             # Domain → hosts/subdomains
recon/domains-contacts/          # Domain → contacts
recon/hosts-hosts/               # Host → related hosts
recon/netblocks-hosts/           # Netblock → hosts
recon/contacts-credentials/      # Contacts → leaked credentials

# Import modules:
import/csv_file                  # Import CSV data
import/list                      # Import list of items
import/nmap                      # Import nmap XML output

# Reporting modules:
reporting/html                   # HTML report
reporting/csv                    # CSV export
reporting/json                   # JSON export
reporting/xlsx                   # Excel export
reporting/xml                    # XML export

USING MODULES#

modules search <keyword>         # Search loaded modules
modules load <module>            # Load a module
info                             # Show module info/options
options list                     # Show all options
options set <option> <value>     # Set option value
options unset <option>           # Clear option value
run                              # Execute module
back                             # Return to main menu

DATABASE OPERATIONS#

db schema                        # Show database schema
db query <sql>                   # Run SQL query

# View collected data:
show hosts                       # List discovered hosts
show contacts                    # List discovered contacts
show credentials                 # List found credentials
show domains                     # List target domains
show companies                   # List companies
show netblocks                   # List network blocks
show ports                       # List discovered ports
show profiles                    # List social profiles

# Add data manually:
db insert domains <domain>       # Add target domain
db insert hosts <host>           # Add target host
db insert contacts               # Add contact info
db delete hosts                  # Delete host entries

API KEYS#

keys list                        # Show configured API keys
keys add <name> <value>          # Add API key
keys remove <name>               # Remove API key

# Common API keys needed:
# bing_api              - Bing search
# builtwith_api         - BuiltWith technology lookup
# censysio_id/secret    - Censys.io
# fullcontact_api       - FullContact
# github_api            - GitHub search
# google_api            - Google search
# hashes_api            - Hashes.org
# hunter_api            - Hunter.io email search
# ipinfodb_api          - IP geolocation
# shodan_api            - Shodan search
# twitter_api/secret    - Twitter
# virustotal_api        - VirusTotal

COMMON WORKFLOWS#

# Subdomain enumeration:
modules load recon/domains-hosts/hackertarget
options set SOURCE example.com
run

# Contact/email harvesting:
modules load recon/domains-contacts/whois_pocs
options set SOURCE example.com
run

# DNS brute force:
modules load recon/domains-hosts/brute_hosts
options set SOURCE example.com
run

# Check for credential leaks:
modules load recon/contacts-credentials/hibp_breach
run

SNAPSHOTS#

snapshots take                   # Save current database state
snapshots list                   # List saved snapshots
snapshots load <name>            # Restore snapshot

RESOURCE SCRIPTS#

# Save commands to a file and replay:
spool start /tmp/recon-output.txt  # Start logging
# ... run commands ...
spool stop                          # Stop logging

EXAMPLES#

# Full domain recon workflow
workspaces create target_recon
db insert domains example.com
modules load recon/domains-hosts/hackertarget
options set SOURCE example.com
run
show hosts
modules load reporting/html
options set FILENAME /tmp/report.html
run

NOTES#

- Modular framework - install only needed modules
- Persistent database stores all findings
- API keys improve results significantly
- Workspaces keep different engagements separate
- Resource scripts enable automation
- Data persists between sessions
- Export reports for documentation