Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
RXScan — Rust CLI for bounded network reconnaissance: TCP/UDP port discovery, service identification, DNS/TLS/HTTP evidence collection, and public-source username search with correlation. | Kitploit
Tools/GitHubGitHub/darkrx1/rxscan
Defensive ToolsOSINT (Open Source Intelligence)ReconnaissanceNetwork MappingPort ScanningVulnerability AnalysisDNS & Subdomain EnumerationInformation GatheringNetwork SecurityUtilities & FrameworksDNS Analysis
151 day agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
GitHub
darkrx1/rxscan

RXScan

Rust CLI for bounded network reconnaissance: TCP/UDP port discovery, service identification, DNS/TLS/HTTP evidence collection, and public-source username search with correlation.

View Repository
Share

RXScan

RXScan

Raw Excess Scan
Bounded reconnaissance and evidence correlation in Rust.

release Rust 1.85+ Linux MIT


RXScan combines network reconnaissance, public-source search, investigation, and evidence correlation in one CLI.

It can discover hosts and ports, identify observed services, collect bounded protocol and web evidence, search public providers, correlate findings, and persist results for later analysis and comparison.

RXScan is intentionally conservative about what it reports. A port number does not identify a service, an HTTP success does not by itself confirm an account, and incomplete coverage is kept distinct from a negative result.

Quick start

Build and install from the repository:

git clone https://github.com/DarkRX1/RXScan.git
cd RXScan
cargo install --path . --locked

Check the installed build:

rxscan --version
rxscan --help

Run a normal reconnaissance scan:

rxscan example.test

Search public sources:

rxscan search --username exampleuser

Investigate and correlate public findings:

rxscan investigate --username exampleuser

Those are the three main entry points:

rxscan TARGET
rxscan search ...
rxscan investigate ...

Network scanning

The default scan uses the recon workflow, level 3, and balanced execution settings.

rxscan example.test

Specify ports when you want exact port selection:

rxscan example.test --ports 22,80,443
rxscan example.test --ports 1-1024
rxscan example.test --ports 22,80,443,8000-8100

Scan the complete TCP port range:

rxscan example.test --all-ports

UDP discovery is explicit:

rxscan example.test --udp

Show the effective plan and additional execution detail:

rxscan example.test --explain

TCP scan modes

RXScan supports:

rxscan example.test --scan-mode auto
rxscan example.test --scan-mode connect
rxscan example.test --scan-mode syn

TCP connect scanning is the portable scan path currently used by RXScan on its supported platform.

Raw SYN scanning is available for IPv4 on Linux when the required capability is available. When the requested SYN path cannot be used, RXScan reports the effective fallback rather than silently presenting a connect scan as SYN.

UDP

UDP scanning uses bounded native probes and remains opt-in.

Current protocol-aware UDP discovery includes small probes for services such as DNS, NTP, and SSDP.

UDP silence is not reported as proof that a port is open or closed. RXScan preserves the resulting open|filtered uncertainty.

Service identification

RXScan identifies services from observed protocol behavior instead of assigning a service solely from its port number.

Current native identification covers common protocols including:

  • SSH
  • HTTP and HTTPS
  • TLS
  • FTP
  • SMTP
  • Redis
  • MySQL
  • PostgreSQL
  • SMB
  • RDP
  • MongoDB
  • MQTT
  • bounded unknown-service fingerprints

Depending on the protocol and available evidence, observations may include product/version information, banners, HTTP endpoints and titles, TLS certificate facts, SSH identity information, and normalized technology evidence.

Unknown services remain unknown when RXScan does not have enough evidence to identify them.

No authentication is required for these identification probes.

Public-source search

Username search is available through:

rxscan search --username exampleuser

Normal output concentrates on useful positive and uncertain findings instead of printing every negative provider result.

A finding can distinguish between an observed profile, another observed resource, and an unconfirmed candidate location.

For example:

FINDINGS

  ✓ provider / exampleuser
    Profile    https://example.test/exampleuser
    high · 94% · public profile

  ? another-provider / exampleuser
    Candidate  https://example.test/u/exampleuser
    low · 25% · weak evidence

The labels are intentional:

LabelMeaning
Profileobserved identity-specific public profile
Resourceobserved identity-specific resource that is not necessarily a public profile
Candidateidentity-specific location that has not been confirmed

Generic provider homepages or API endpoints are not presented as confirmed profile URLs.

RXScan also keeps provider outcomes such as blocked, rate-limited, unknown, error, and unscanned distinct rather than converting them into false negative results.

Show the complete human result set with:

rxscan search --username exampleuser --all

Show additional execution and classification detail with:

rxscan search --username exampleuser --explain

Investigation

Public findings can be passed through RXScan's investigation and correlation pipeline:

rxscan investigate --username exampleuser

The default view focuses on accounts, useful URLs, confidence, and meaningful relationships.

Secondary web resources such as static JavaScript, stylesheets, fonts, and images are retained when relevant to the underlying evidence but do not dominate the default human report.

Detailed views can expose more of the collected relationship data.

Investigation remains passive by default. Discovering a network target through public evidence does not automatically authorize or trigger a network scan.

Evidence and correlation

RXScan stores observations as typed evidence used by its reporting, investigation, graph, history, and analysis paths.

Several rules are deliberately enforced throughout the project:

  • port numbers alone do not establish service identity;
  • HTTP 200 alone does not establish that a public account exists;
  • UDP silence is uncertainty;
  • weak identity evidence does not automatically merge entities;
  • shared infrastructure can create relationships without implying identity;
  • incomplete coverage is not treated as proof that a previously observed entity disappeared;
  • presentation filtering does not remove the underlying machine evidence.

This distinction between observation and interpretation is a core part of RXScan's design.

HTTP, TLS, and DNS observations

For confirmed web services, RXScan can collect bounded HTTP observations such as:

  • status and headers
  • redirects
  • page title
  • content type and response size
  • cookies
  • links
  • forms
  • scripts
  • robots.txt
  • sitemap.xml

Workflow and evidence can also permit bounded crawling, baseline checks, managed content discovery, and contextual GET-query follow-ups.

DNS observation supports bounded record collection including:

  • A
  • AAAA
  • CNAME
  • MX
  • NS
  • TXT
  • PTR
  • SRV

TLS observation records handshake and certificate evidence. It is not an exhaustive TLS cipher-suite scanner.

Scope

Network activity is subject to RXScan's scope policy.

Additional permitted targets can be supplied explicitly:

rxscan example.test --scope example.test

Targets can also be excluded:

rxscan example.test --exclude api.example.test

Out-of-scope work is rejected before the corresponding network contact.

Download Tool