Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
Recon-Scan — Recon-Scan: open‑source passive reconnaissance with AI‑powered security analysis. Zero‑touch, developer‑first, and privacy‑focused. | Kitploit
أدوات/GitHubGitHub/aarocy/recon-scan
OSINT (Open Source Intelligence)ReconnaissanceVulnerability AnalysisDNS & Subdomain EnumerationInformation GatheringWeb SecurityThreat IntelligenceDNS AnalysisAI Security
GitHubaarocy/recon-scan

Recon-Scan

Recon-Scan: open‑source passive reconnaissance with AI‑powered security analysis. Zero‑touch, developer‑first, and privacy‑focused.

7215منذ 2 أياملم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
عرض المستودعالموقع الإلكتروني
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

Recon-Scan

image

ReconScan is a open-source passive recon scanner with a FastAPI backend, async worker pipeline, and a single-page frontend. You can check the deployed site at https://recon-scan.vercel.app/

The point is fast signal: run a scan, get module-by-module findings, and get an AI summary that can now be exported as a polished PDF report.

Note: The demo isn't live cuz I ran out of AI tokens. You can still self host.

What This Project Is (And Is Not)

  • It is passive recon. It does not brute force endpoints, fuzz, or run active exploit logic.
  • It is good for posture snapshots, triage, and reporting.
  • It is not a substitute for full penetration testing.

Features

  • 13 passive modules:
    • Security headers
    • SSL/TLS
    • DNS + email auth (SPF/DMARC/MX)
    • WHOIS
    • Robots/sitemap
    • Subdomain enumeration
    • Tech fingerprinting
    • WAF detection
    • CORS checks
    • Cookie security checks
    • JS exposure checks
    • Directory exposure checks
    • Reputation checks
  • Async execution with Redis + ARQ worker.
  • Fallback to in-process background execution if queue enqueue fails.
  • Optional AI summary via OpenRouter / Anthropic / OpenAI.
  • PDF report generation from scan + AI summary.
  • Frontend served directly by FastAPI (one URL, one app).

One-Command Start (Local Dev)

If you just want it running quickly:

./start.sh

What this does:

  • Creates .env from .env.example if missing.
  • Creates .venv if needed.
  • Installs dependencies from requirements.txt.
  • Starts FastAPI with hot reload on http://localhost:8000.
  • Forces USE_ARQ_QUEUE=false for easier no-Redis local startup.

Stop with Ctrl+C.

One-Command Start (Docker)

./start-docker.sh

What this does:

  • Creates .env from .env.example if missing.
  • Starts API + worker + Redis with Docker Compose.

Docker Start (Manual)

cp .env.example .env
docker compose up --build

Local Development (Without Docker)

  1. Install dependencies:
pip install -r requirements.txt
  1. Create env file:
cp .env.example .env
  1. Start API:
uvicorn app.main:app --host 0.0.0.0 --port 8000 --reload
  1. Start worker in another terminal (recommended):
arq app.worker.WorkerSettings
  1. Open:

http://localhost:8000

Running Tests

Install test dependencies:

pip install -r requirements-dev.txt

Run the full suite:

pytest -q

PDF Reports

After a scan completes, click Download PDF in the UI.

Backend endpoint:

  • GET /scans/{scan_id}/report.pdf

The report includes:

  • Target and scan metadata
  • AI executive summary (short + full narrative when available)
  • Severity snapshot table
  • Detailed module-by-module findings

API

  • GET /health
  • POST /scans
    • body example:
      • { "target": "example.com" }
      • { "target": "example.com", "byoapi_key": "...", "byoapi_provider": "your_provider" }
    • notes:
      • byoapi_key rejected unless ALLOW_BYO_API_KEY=true
      • private / loopback / reserved targets are blocked
      • user_id is optional and kept for compatibility
  • GET /scans/{scan_id}
  • GET /scans/{scan_id}/report.pdf

Configuration

From .env.example:

  • DATABASE_URL (default: sqlite:///./reconscan.db)
  • REDIS_URL (default: redis://localhost:6379)
  • USE_ARQ_QUEUE (default: true)
  • RATE_LIMIT_PER_MINUTE (default: 10)
  • RATE_LIMIT_PER_DAY (default: 200)
  • ALLOWED_HOSTS (default: localhost,127.0.0.1)
  • CORS_ALLOWED_ORIGINS (default: local development origins)
  • ALLOW_BYO_API_KEY (default: false)
  • OPENROUTER_API_KEY, ANTHROPIC_API_KEY, OPENAI_API_KEY (optional)
  • VIRUSTOTAL_API_KEY, GOOGLE_SAFE_BROWSING_API_KEY (optional)

Contributing

Contributions are welcome, especially around passive recon modules, reporting, frontend UX, and test coverage.

Please read the full contribution guidelines before opening a pull request:

Contributing Guide

Notes

  • If no external AI key is configured, ReconScan stores a local fallback summary.
  • SQLite is the default storage engine for easy local use.
  • This repo is intentionally lightweight and self-host friendly.

License

MIT. See LICENSE.

تنزيل الأداة