
PhantomRecon एक CLI-आधारित, मॉड्यूलर, एजेंट-संचालित रेड टीम स्वचालन उपकरण है जिसे AI (Agent Development Kit - ADK के माध्यम से Google के Gemini) द्वारा संचालित स्वायत्त आक्रामक सुरक्षा वर्कफ़्लो को प्रदर्शित करने के लिए डिज़ाइन किया गया है।
PhantomRecon एक CLI-आधारित, मॉड्यूलर, एजेंट-संचालित रेड टीम स्वचालन उपकरण है जिसे AI (एजेंट डेवलपमेंट किट - ADK के माध्यम से Google के Gemini) द्वारा संचालित स्वायत्त आक्रामक सुरक्षा वर्कफ़्लो का प्रदर्शन करने के लिए डिज़ाइन किया गया है।
python -m phantomrecon
python -m phantomrecon --target example.com --auto \
--nmap-timeout 30 --nmap-top-ports 100 --nmap-args "-sV -Pn"
--target <domain|ip>: आकलन करने का लक्ष्य--auto: रीकॉन → योजना → रूट → रिपोर्ट चलाएँ--nmap-timeout <seconds>: NMAP_TIMEOUT को ओवरराइड करता है--nmap-top-ports <N>: NMAP_TOP_PORTS को ओवरराइड करता है--nmap-args "...": Nmap तर्कों (NMAP_ARGS) में जोड़ता है--nmap-disable: Nmap अक्षम करें (NMAP_DISABLE=1 सेट करता है)पर्यावरण चर भी सीधे समर्थित हैं: NMAP_TIMEOUT, NMAP_TOP_PORTS, NMAP_ARGS, NMAP_DISABLE।
.gitignore reports/* को छोड़कर reports/sample_report.md को बाहर करता है।reports/ के अंतर्गत रहती हैं।एक प्रूफ-ऑफ-कॉन्सेप्ट के रूप में निर्मित, यह लक्ष्य की पहचान करने, व्यापक रीकॉनिसेंस (Nmap, DNS, वेब खोज) करने, LLM का उपयोग करके हमले की रणनीति की योजना बनाने, सशर्त रूप से सिम्युलेटेड एक्सप्लॉइट निष्पादित करने और एक रिपोर्ट उत्पन्न करने का अनुकरण करता है।
phantomrecon/
├── phantomrecon/ # Main package (exported orchestrator agent)
│ ├── __init__.py
│ ├── __main__.py # CLI entrypoint (interactive and non-interactive)
│ └── agent/ # Agent graph and tools
├── agents/ # Python modules containing agent/tool logic
│ ├── recon_logic.py # Nmap, DNS (dig), seeded web analysis; ADK search enabled
│ ├── routing_logic.py # Logic for the Exploit Router agent
│ ├── exploit_web_logic.py # Functions for web exploits (currently simulated)
│ ├── exploit_sql_logic.py # Functions for SQL exploits (currently simulated)
│ └── report_logic.py # Functions for report generation using session state
├── configs/
│ └── targets.json # (Optional) Target configuration
├── data/
│ └── dummy_scan_output.json # Example Nmap data if no target specified
├── demos/
│ └── walkthrough.md # Demo steps
├── prompts/ # Prompt templates for LLM agents
├── reports/
│ └── sample_report.md # Example output report
├── requirements.txt # Python dependencies (includes google-adk)
├── .gitignore # Files excluded from version control
└── LICENSE # MIT License
recon_workflow - समानांतर एजेंट):
nmap_tool)dns_tool)web_search_tool)aggregation_tool):
aggregated_recon_data को सत्र स्थिति में लिखता है।planning_agent - LlmAgent):
attack_planner_prompt.txt का उपयोग करता है।attack_plan को सत्र स्थिति में लिखता है।exploit_router - RouterAgent):
attack_plan पढ़ता है।web_exploit_tool, sql_exploit_tool) को सशर्त रूप से निष्पादित करता है।exploit_results सूची में परिणाम जोड़ते हैं।report_tool):
python3, pip, nmap, dig, whois, sqlmap, wapiti, wpscan, searchsploit।python3 -m venv venv
source venv/bin/activate # On Windows use `venv\Scripts\activate`
pip install -r requirements.txt
.env.example को .env में कॉपी करें (यदि उदाहरण मौजूद है) या .env संपादित करें।GOOGLE_API_KEY वेरिएबल के लिए अपनी Google API कुंजी जोड़ें (AI Studio या Vertex AI सेटअप से)।GOOGLE_GENAI_USE_VERTEXAI को True या False पर सेट करें और संबंधित वेरिएबल (GOOGLE_CLOUD_PROJECT, GOOGLE_CLOUD_LOCATION) कॉन्फ़िगर करें।python -m phantomreconpython -m phantomrecon --target <target> --autoadk run phantomreconयह उपकरण केवल अधिकृत सुरक्षा परीक्षण और शैक्षिक उद्देश्यों के लिए है। स्पष्ट अनुमति के बिना सिस्टम के विरुद्ध उपयोग न करें।
यह प्रोजेक्ट MIT लाइसेंस के अंतर्गत लाइसेंस प्राप्त है - विवरण के लिए LICENSE फ़ाइल देखें।
sudo apt install nmap या brew install nmap)sudo apt install dnsutils या brew install bind)sudo apt install whois या brew install whois)sudo apt install sqlmap या brew install sqlmap)sudo apt install wapiti या brew install wapiti)sudo apt install ruby-full फिर gem install wpscan या brew install wpscan)sudo apt install exploitdb या brew install exploitdb)requirements.txt में सूचीबद्ध पायथन लाइब्रेरीज़ (pip install -r requirements.txt के माध्यम से स्थापित करें)adk web इंटरफ़ेस का उपयोग करता है।dig, nslookup, dig +trace, AXFR प्रयास, whois)sqlmap के माध्यम से), Wapiti स्कैन (पार्स किए गए परिणाम), WPScan (पार्स किए गए परिणाम, सशर्त), बेसिक Reflected XSS, बेसिक कमांड इंजेक्शन - (वास्तविक जाँच)searchsploit के माध्यम से), पोस्ट-प्रमाणीकरण गणना (sqlmap डायरेक्ट कनेक्ट के माध्यम से) - (वास्तविक जाँच)searchsploit के माध्यम से), कॉन्फ़िगरेशन ऑडिट (ssh-audit के माध्यम से, पार्स किए गए परिणाम) - (वास्तविक जाँच)ToolContext का उपयोग करता है।