Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
inter-recon — Script to perform automatic initial web and vulnerability recon | Kitploit
Tools/GitHubGitHub/internon/inter-recon
ReconnaissanceVulnerability ScannersPort ScanningInformation GatheringWeb SecurityFuzzingNetwork SecurityPenetration TestingSubdomain EnumerationDNS Analysis
GitHubinternon/inter-recon
84144 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

inter-recon

Script to perform automatic initial web and vulnerability recon

View Repository

inter-recon

Script to perform automatic initial web and vulnerability recon.

It has some checks in case of errors.

There is a possibility to skip some checks, to restart them and/or to continue with the last point you stopped. (This is because sometimes there are network issues like time limit on VPN).

Remember if you copy or link the inter-recon script to bin path (ex: /usr/bin/) you can execute the script from where you want. It will create the output where you are.

IMPORTANT TO SEE WFUZZ PROBLEM AND WORKAROUND ON THE END OF THE README (Additional information section)

To use multiple known domain/IPs as eg.:

  • Create file domains.txt with all domains or different IPs
  • Execute: inter-recon -T $(pwd)/domains.txt -d $(pwd)/known-domains -w /home/kali/Desktop/tools/inter-recon/dictionaries/without-slash/dict-small-without-slash.txt -s all -a true

To use on network/IP as eg.:

  • Execute: inter-recon -t 10.11.1.1/24 -w /home/kali/Desktop/tools/inter-recon/dictionaries/without-slash/dict-small-without-slash.txt -s all -a true

How to use:

inter-recon.sh [OPTIONS] -t {NET OR IP} -T {Target PATH} -d {Dictionary Path} -w {DICT PATH} -s {scan type} -a optional is for superautomaticscan skipping all and not asking anything on wfuzz process at fisrt time execution

Scan types

  • all
    • portscan
      • nmap TCP -> full ports checking host up if they have one of the following ports open (1025,1028,1029,10443,111,135,139,1521,161,1917,21,22,23,25,2869,3306,3389,443,445,49000,497,5000,515,53,548,5985,5986,6000,79,80,8080,8081,8090,9001,9002,9100,993,995)
      • nmap UDP -> top 100 ports with default host up process
    • vulnscan
      • parse nmap UDP and TCP scan to files
      • parse nmap UDP and TCP scan on services folder by service
      • nmap UDP and TCP to open ports executing port/version related scripts
      • smbmap guest execution -> To check if without user we can write/read anything
      • enum4linux guest execution -> To check information retrieved from samba
      • smbversion execution -> To retrieve the version of samba (Sometimes in linux servers is the only way to see the samba version)
    • webscan
      • http discovery with httpx from nmap execution
      • fuzzing discovered URLs with wfuzz
      • screenshot Status 200 URLs from fuzzing with aquatone
      • 403 bypass techniques with byp4xx
    • following steps -> quick explanation of things to do after script execution
    • Documentation folder and template structure -> Make a folder to add evidences and adding .md files with information related of the scans
  • vuln
    • portscan (Same as above)
    • vulnscan (Same as above)
    • following steps (Same as above)
    • Documentation folder and template structure
  • web
    • portscan (Same as above)
    • webscan (Same as above)
    • following steps (Same as above)
    • Documentation folder and template structure

Structure:

  • First ports scan tcp and udp with version (nmap, requires sudo)
  • Vulnerability recon scan (command to parse ports into a file with fromat IP,port,service,version, parse it on services files, perform nmap with full port/version related scripts)
  • Web fuzzing recon scan if httpx finds a HTTP port (httpx, wfuzz, aquatone, byp4xx 403 files <- if exist status 403)
Download Tool