
reconFTW è uno strumento progettato per eseguire ricognizione automatizzata su un dominio target lanciando il miglior set di strumenti per effettuare scansioni e scoprire vulnerabilità.
reconFTW è un potente strumento di ricognizione automatizzata progettato per ricercatori di sicurezza e penetration tester. Semplifica il processo di raccolta di informazioni su un target eseguendo enumerazione dei sottodomini, scansione delle vulnerabilità, OSINT e altro ancora. Grazie a un design modulare, a opzioni di configurazione estese e al supporto per la scansione distribuita tramite AX Framework, reconFTW è costruito per fornire risultati completi in modo efficiente.
reconFTW sfrutta un'ampia gamma di tecniche, tra cui la scoperta passiva e attiva di sottodomini, controlli delle vulnerabilità web (es. XSS, SSRF, SQLi), OSINT, fuzzing delle directory, scansione delle porte e acquisizione di screenshot. Si integra con strumenti e API all'avanguardia per massimizzare copertura e accuratezza, assicurandoti di restare al passo nei tuoi sforzi di ricognizione.
Caratteristiche principali:
Disclaimer: L'utilizzo di reconFTW per attaccare target senza previo consenso è illegale. È responsabilità dell'utente rispettare tutte le leggi applicabili. Gli sviluppatori non si assumono alcuna responsabilità per usi impropri o danni causati da questo strumento. Usalo in modo responsabile.
reconFTW è ricco di funzionalità per rendere la ricognizione approfondita ed efficiente. Di seguito una ripartizione dettagliata delle sue capacità, aggiornata per riflettere le ultime funzionalità nello script e nella configurazione.
IPV6_SCAN è abilitato.nuclei -dast sugli URL raccolti e sui candidati GF per una copertura DAST aggiuntiva.--quick-rescan / QUICK_RESCAN).hotlist.txt) in base ai nuovi risultati.SHOW_COMMANDS per registrare ogni comando eseguito nei log di destinazione per il debug.reconFTW utilizza un'architettura modulare. Il punto di ingresso principale (reconftw.sh) gestisce l'analisi degli argomenti e carica 8 moduli specializzati dalla directory modules/.
reconftw/ ├── reconftw.sh # Entry point — arg parsing, module loading, dispatch ├── reconftw.cfg # Default configuration ├── install.sh # Installer ├── Makefile # Data management, lint, fmt, test targets ├── modules/ │ ├── core.sh # Lifecycle, logging, notifications, cleanup (1024 lines) │ ├── modes.sh # Scan modes, argument parsing, help (902 lines) │ ├── subdomains.sh # Subdomain enumeration (1938 lines) │ ├── web.sh # Web analysis, fuzzing, JS checks (1712 lines) │ ├── vulns.sh # Vulnerability scanning (926 lines) │ ├── osint.sh # OSINT functions (500 lines) │ ├── axiom.sh # Ax/Axiom fleet helpers (143 lines) │ └── utils.sh # Utilities, sanitization, validation (508 lines) ├── tests/ │ ├── run_tests.sh # Test runner │ ├── unit/ # bats-core unit tests │ ├── integration/ # Integration tests │ └── fixtures/ # Test data ├── Docker/ │ └── Dockerfile # Official Docker image └── Terraform/ # AWS deployment
### Riferimento ai Moduli
| Modulo | Righe | Scopo |
|--------|------:|---------|
| `core.sh` | 1024 | Gestione del ciclo di vita, logging, notifiche, trap di pulizia |
| `modes.sh` | 902 | Definizioni delle modalità di scansione, parsing degli argomenti, output di aiuto |
| `subdomains.sh` | 1938 | Tutte le funzioni di enumerazione dei sottodomini |
| `web.sh` | 1712 | Analisi web, fuzzing, analisi JS, rilevamento CMS |
| `vulns.sh` | 926 | Scansione delle vulnerabilità (XSS, SQLi, SSRF, ecc.) |
| `osint.sh` | 500 | Funzioni OSINT (WHOIS, email, dorks, metadati) |
| `utils.sh` | 508 | Utility condivise, sanificazione degli input, validazione |
| `axiom.sh` | 143 | Gestione della flotta distribuita Ax/Axiom |
Il flag `--source-only` consente di includere `reconftw.sh` senza eseguire la logica principale, permettendo il test unitario delle singole funzioni.
---
## 💿 Installazione
reconFTW supporta molteplici metodi di installazione per adattarsi a diversi ambienti. Assicurati di avere spazio su disco sufficiente (almeno 10 GB consigliati) e una connessione internet stabile.
### Avvio rapido
1) Clona e installa```yaml
git clone https://github.com/six2dez/reconftw
cd reconftw
./install.sh --verbose
3) Esecuzione minima (footprint solo passivo)```bash
./reconftw.sh -d example.com -p
Suggerimento: esegui di nuovo
./install.sh --toolsin seguito per aggiornare la toolchain senza reinstallare i pacchetti di sistema.
Prerequisiti:
install_golang abilitato per impostazione predefinita in reconftw.cfg).sudo echo "${USERNAME} ALL=(ALL:ALL) NOPASSWD: ALL" | sudo tee -a /etc/sudoers.d/reconFTW
Passaggi: ```bash git clone https://github.com/six2dez/reconftw cd reconftw ./install.sh ./reconftw.sh -d target.com -r
Note:
install.sh installa le dipendenze, gli strumenti e configura i percorsi (GOROOT, GOPATH, PATH).install_golang=false in reconftw.cfg se Golang è già configurato../install.sh --tools per aggiornare i binari Go, i pacchetti pipx e i repository senza toccare i pacchetti di sistema.Per un elenco di target, monta il file dell'elenco nel container e fai riferimento al percorso all'interno del container: ```bash
docker run -it --rm
-v "${PWD}/domains.txt:/reconftw/domains.txt:ro"
-v "${PWD}/OutputFolder/:/reconftw/Recon/"
six2dez/reconftw:main -l /reconftw/domains.txt -r
3. **Visualizza i risultati**:
- I risultati vengono salvati nella directory `OutputFolder` sull'host (non all'interno del container).
4. **Personalizzazione**:
- Modifica l'immagine Docker o creane una tua; consulta la [Guida Docker](https://github.com/six2dez/reconftw/wiki/4.-Docker).
- Per saltare gli strumenti Ax nelle build personalizzate, usa `--build-arg INSTALL_AXIOM=false`.
- Monta la tua configurazione notify in `~/.config/notify/provider-config.yaml` all'interno del container se utilizzi le notifiche.
5. **Segreti in fase di esecuzione**:
Passa chiavi API e segreti tramite variabili d'ambiente — non incorporarli mai nell'immagine: ```bash
docker run -it --rm \
-e SHODAN_API_KEY="your-key" \
-e PDCP_API_KEY="your-projectdiscovery-key" \
-e COLLAB_SERVER="your-server" \
-e XSS_SERVER="your-server" \
-v "${PWD}/OutputFolder/:/reconftw/Recon/" \
six2dez/reconftw:main -d example.com -r
See SECURITY.md per la guida completa sulla gestione dei segreti.
Health Check:
L'immagine Docker include un HEALTHCHECK integrato che esegue ./reconftw.sh --health-check ogni 60 secondi. Puoi anche eseguirlo manualmente: ```bash
docker exec ./reconftw.sh --health-check
reconFTW è in fase di riscrittura in Go. La riscrittura viene distribuita come pre-release opzionale: è
elencata nella pagina delle release, e GitHub
non punta mai releases/latest a una pre-release — quindi se non fai nulla, continui a ricevere
la release bash. Questa è una scelta deliberata.
Il binario Go è reconftw; il punto di ingresso bash è reconftw.sh. Non si sovrascrivono
a vicenda, quindi puoi tenerli entrambi e tornare indietro in qualsiasi momento.
La beta attuale è v5.0.0-beta.1. Non è servita da releases/latest, quindi devi
specificare esplicitamente il tag:```bash
curl -sSL "https://github.com/six2dez/reconftw/releases/download/v5.0.0-beta.1/reconftw_Linux_x86_64.tar.gz" | tar xz
sudo install -m 755 reconftw /usr/local/bin/reconftw
reconftw version
Scegli l’asset corrispondente alla tua piattaforma dalla
[pagina di rilascio](https://github.com/six2dez/reconftw/releases/tag/v5.0.0-beta.1) — sono pubblicati build `Darwin`
e `arm64`, una build musl statica e pacchetti `.deb`/`.rpm`.
- [**Cos’è la beta e cosa non è**](https://github.com/six2dez/reconftw/blob/main/docs/V2-BETA-ANNOUNCEMENT.md) — incluse tre
cose che non sono ancora esplicitamente finite.
- [**Segnala qualcosa**](https://github.com/six2dez/reconftw/issues/new?template=v2-beta-feedback.md)
— il modello di feedback per la beta v2. I bug nella release bash vanno ancora al normale modello Bug report.
## 🛠️ Risoluzione dei problemi
- Bash 4+ su macOS: Gli script si riavviano automaticamente con Homebrew Bash. Se vedi un messaggio su Bash < 4, esegui `brew install bash`, apri un nuovo terminale e ri-esegui `./install.sh`.
- timeout su macOS: macOS fornisce `gtimeout` tramite `brew install coreutils`. Gli script ora lo rilevano e lo usano automaticamente.
- Problemi di rete: Gli installer nascondono la maggior parte dell’output dei comandi. Se qualcosa fallisce, ri-esegui con `upgrade_tools=true` in `reconftw.cfg`, esegui `./install.sh --tools`, oppure installa manualmente lo strumento mancante (l’errore lo indicherà).
- Binari GOPATH: I binari vengono copiati in `/usr/local/bin`. Se preferisci non farlo, assicurati che `~/go/bin` sia nel tuo `PATH`.
- Modelli Nuclei: Se i modelli non sono stati clonati, rimuovi `~/nuclei-templates` e ri-esegui `./install.sh`.
## 🔑 Checklist API (Opzionale)
- `subfinder`: `~/.config/subfinder/provider-config.yaml`
- Token GitHub: `~/Tools/.github_tokens` (uno per riga)
- Token GitLab: `~/Tools/.gitlab_tokens` (uno per riga)
- WHOISXML: imposta `WHOISXML_API` in `reconftw.cfg` o come variabile d’ambiente
- Enumerazione ASN (`asnmap`): imposta `PDCP_API_KEY` in env/config (`ASN_ENUM` viene saltato se non impostato)
- Slack/Discord/Telegram: configura `notify` in `~/.config/notify/provider-config.yaml`
- Server SSRF: imposta `COLLAB_SERVER` in env/cfg se usato
- Server Blind XSS: imposta `XSS_SERVER` in env/cfg se usato
## 💾 Requisiti
- Disco: 10–20 GB liberi consigliati (toolchain + dati)
- Rete: connessione stabile durante installazione e aggiornamenti
- Sistema operativo: Linux/macOS con Bash ≥ 4
- Extra: `shellcheck` e `shfmt` (opzionali) per `make lint`/`make fmt`
## ⚙️ Configurazione
Il file `reconftw.cfg` controlla l’intera esecuzione di reconFTW. Consente una personalizzazione granulare di:
- **Percorsi degli strumenti**: Imposta percorsi per strumenti, resolver e wordlist (`tools`, `resolvers`, `fuzz_wordlist`).
- **Chiavi API**: Configura chiavi per Shodan, WHOISXML, ecc. tramite variabili d’ambiente o `secrets.cfg` (vedi [SECURITY.md](https://github.com/six2dez/reconftw/blob/main/SECURITY.md)).
- **Modalità di scansione**: Abilita/disabilita moduli (es. `OSINT`, `SUBDOMAINS_GENERAL`, `VULNS_GENERAL`).
- **Prestazioni**: Regola thread, limiti di velocità e timeout (es. `FFUF_THREADS`, `HTTPX_RATELIMIT`).
- **Limitazione adattiva della velocità**: Riduce automaticamente su errori 429/503 (`ADAPTIVE_RATE_LIMIT`, `MIN_RATE_LIMIT`, `MAX_RATE_LIMIT`).
- **Scansione incrementale**: Scansiona solo i nuovi risultati dall’ultima esecuzione (`INCREMENTAL_MODE`).
- **Notifiche**: Configura notifiche Slack, Discord o Telegram (`NOTIFY_CONFIG`).
- **Ax (ex Axiom)**: Configura scansione distribuita e percorsi dei resolver (`AXIOM_FLEET_NAME`, `AXIOM_FLEET_COUNT`, `AXIOM_RESOLVERS_PATH`).
- **Report AI**: Configura modello/profilo/formato e controlli di contesto (`AI_MODEL`, `AI_REPORT_PROFILE`, `AI_REPORT_TYPE`, `AI_MAX_CHARS_PER_FILE`).
- **Controlli web avanzati**: Attiva/disattiva introspezione GraphQL, scoperta parametri, test WebSocket, probing gRPC e scansione IPv6.
- **Automazione e dati**: Controlla euristiche di riscansione rapida, logging degli asset, dimensioni dei chunk, hotlist e tracciamento debug (`QUICK_RESCAN`, `ASSET_STORE`, `CHUNK_LIMIT`, `HOTLIST_TOP`, `SHOW_COMMANDS`).
- **Disco e logging**: Controllo disco pre-volo (`MIN_DISK_SPACE_GB`), rotazione log (`MAX_LOG_FILES`, `MAX_LOG_AGE_DAYS`), logging JSON strutturato (`STRUCTURED_LOGGING`).
- **Cache**: Configura la scadenza della cache per wordlist e resolver (`CACHE_MAX_AGE_DAYS`).
- **Sicurezza dei resolver DNS**: I file resolver mancanti falliscono rapidamente, i download dei resolver usano tentativi/timeout configurabili (`RESOLVER_DOWNLOAD_*`), e il timeout di brute/risoluzione DNS è disabilitato di default (`DNS_*_TIMEOUT=0`) con avanzamento heartbeat.
- **Segreti**: Usa `secrets.cfg` per override locali o variabili d’ambiente per CI/Docker (vedi [SECURITY.md](https://github.com/six2dez/reconftw/blob/main/SECURITY.md)).
**Esempio di configurazione**:```bash
#############################################
# reconFTW config file #
#############################################
# General values
tools=$HOME/Tools # Path installed tools
if [[ -z "${SCRIPTPATH:-}" ]]; then
if [[ -n "${BASH_SOURCE[0]:-}" ]]; then
SCRIPTPATH="$( cd "$(dirname "${BASH_SOURCE[0]}")" >/dev/null 2>&1 ; pwd -P )" # Get current script's path
else
SCRIPTPATH="$( cd "$(dirname "$0")" >/dev/null 2>&1 ; pwd -P )" # Get current script's path
fi
fi
_detected_shell="${SHELL:-/bin/bash}"
profile_shell=".$(basename "${_detected_shell}")rc" # Get current shell profile
if git rev-parse --is-inside-work-tree >/dev/null 2>&1; then
reconftw_version="$(git rev-parse --abbrev-ref HEAD)-$(git describe --tags 2>/dev/null || git rev-parse --short HEAD)"
else
reconftw_version="standalone"
fi # Fetch current reconftw version
DATA_DIR="${SCRIPTPATH}/data"
WORDLISTS_DIR="${DATA_DIR}/wordlists"
PATTERNS_DIR="${DATA_DIR}/patterns"
generate_resolvers=false # Generate custom resolvers with dnsvalidator
update_resolvers=true # Fetch and rewrite resolvers from trickest/resolvers before DNS resolution
resolvers_url="https://raw.githubusercontent.com/trickest/resolvers/main/resolvers.txt"
resolvers_trusted_url="https://gist.githubusercontent.com/six2dez/ae9ed7e5c786461868abd3f2344401b6/raw/trusted_resolvers.txt"
RESOLVER_DOWNLOAD_CONNECT_TIMEOUT=10 # Seconds to wait for resolver download TCP connection
RESOLVER_DOWNLOAD_MAX_TIME=120 # Hard cap in seconds for resolver downloads
RESOLVER_DOWNLOAD_RETRY=2 # Retry count for resolver downloads
RESOLVER_DOWNLOAD_RETRY_DELAY=2 # Delay in seconds between resolver download retries
fuzzing_remote_list="https://raw.githubusercontent.com/six2dez/OneListForAll/main/onelistforallmicro.txt" # Used to send to Ax (if used) on fuzzing
proxy_url="http://127.0.0.1:8080/" # Proxy url
install_golang=true # Set it to false if you already have Golang configured and ready
upgrade_tools=true
upgrade_before_running=false # Upgrade tools before running
#dir_output=/custom/output/path
SHOW_COMMANDS=false # Set true to log every executed command to the per-target log (verbose; may include sensitive data)
MIN_DISK_SPACE_GB=0 # Minimum required disk space in GB before starting reconnaissance (0 to disable check)
# Incremental mode configuration
INCREMENTAL_MODE=false # Only scan new findings since last run (use --incremental flag to enable)
MONITOR_MODE=false # Continuous monitor mode (enabled by --monitor)
MONITOR_INTERVAL_MIN=60 # Minutes between monitoring cycles
MONITOR_MAX_CYCLES=0 # 0 = run forever until interrupted
ALERT_SUPPRESSION=true # Suppress repeated monitor alerts by fingerprint history
ALERT_SEEN_FILE=".incremental/alerts_seen.hashes" # Store of seen alert fingerprints
# Adaptive rate limiting configuration
ADAPTIVE_RATE_LIMIT=false # Automatically adjust rate limits when encountering 429/503 errors (use --adaptive-rate flag to enable)
MIN_RATE_LIMIT=10 # Minimum rate limit (requests per second)
MAX_RATE_LIMIT=500 # Maximum rate limit (requests per second)
RATE_LIMIT_BACKOFF_FACTOR=0.5 # Multiply rate by this when errors occur (0.5 = half speed)
RATE_LIMIT_INCREASE_FACTOR=1.2 # Multiply rate by this on success (1.2 = 20% faster)
# Cache configuration
CACHE_MAX_AGE_DAYS=30 # Maximum age in days for cached wordlists/resolvers (30 = 1 month)
CACHE_MAX_AGE_DAYS_RESOLVERS=7 # Resolver cache TTL
CACHE_MAX_AGE_DAYS_WORDLISTS=30 # Wordlist cache TTL
CACHE_MAX_AGE_DAYS_TOOLS=14 # Tool cache TTL
CACHE_REFRESH=false # Force-refresh cache (or use --refresh-cache)
# Log rotation
MAX_LOG_FILES=10 # Maximum number of log files to keep per target
MAX_LOG_AGE_DAYS=30 # Delete log files older than this many days
# Structured logging configuration (JSON format)
STRUCTURED_LOGGING=false # Enable JSON structured logging for advanced log analysis
# Golang Vars (Comment or change on your own)
export GOROOT="${GOROOT:-/usr/local/go}"
export GOPATH="${GOPATH:-$HOME/go}"
case ":${PATH}:" in
*":$GOPATH/bin:"*) ;;
*) PATH="$GOPATH/bin:$PATH" ;;
esac
case ":${PATH}:" in
*":$GOROOT/bin:"*) ;;
*) PATH="$GOROOT/bin:$PATH" ;;
esac
case ":${PATH}:" in
*":$HOME/.local/bin:"*) ;;
*) PATH="$HOME/.local/bin:$PATH" ;;
esac
export PATH
# Rust Vars (Comment or change on your own)
export PATH="$HOME/.cargo/bin:$PATH"
# Tools config files
#NOTIFY_CONFIG=~/.config/notify/provider-config.yaml # No need to define
GITHUB_TOKENS=${tools}/.github_tokens
GITLAB_TOKENS=${tools}/.gitlab_tokens
#CUSTOM_CONFIG=custom_config_path.txt # In case you use a custom config file, uncomment this line and set your files path
# APIs/TOKENS - Set via environment variables (preferred) or uncomment and edit below.
# Environment variables take precedence if set.
SHODAN_API_KEY="${SHODAN_API_KEY:-}"
WHOISXML_API="${WHOISXML_API:-}"
PDCP_API_KEY="${PDCP_API_KEY:-}"
XSS_SERVER="${XSS_SERVER:-}"
COLLAB_SERVER="${COLLAB_SERVER:-}"
slack_channel="${slack_channel:-}"
slack_auth="${slack_auth:-}"
# For additional secrets, create a secrets.cfg file (gitignored) and it will be auto-sourced
# File descriptors
DEBUG_STD="&>/dev/null" # Skips STD output on installer
DEBUG_ERROR="2>/dev/null" # Skips ERR output on installer
# Osint
OSINT=true # Enable or disable the whole OSINT module
GOOGLE_DORKS=true
GITHUB_DORKS=true
GITHUB_REPOS=true
METADATA=true # Fetch metadata from indexed office documents
EMAILS=true # Fetch emails from differents sites
DOMAIN_INFO=true # whois info
IP_INFO=true # Reverse IP search, geolocation and whois
API_LEAKS=true # Check for API leaks
API_LEAKS_POSTLEAKS=true # Enhance API leaks with postleaksNg
THIRD_PARTIES=true # Check for 3rd parties misconfigs
SPOOF=true # Check spoofable domains
MAIL_HYGIENE=true # Check DMARC/SPF records
CLOUD_ENUM=true # Enumerate cloud storage across providers with cloud_enum
GITHUB_LEAKS=true # Search for leaked secrets across GitHub with ghleaks
GHLEAKS_THREADS=5 # Concurrent download threads for ghleaks
SECRETS_ENGINE="gitleaks" # gitleaks|titus|noseyparker|hybrid
SECRETS_SCAN_GIT_HISTORY=false # Include git history scans when supported
SECRETS_VALIDATE=false # Validate detected secrets when supported (titus)
GITHUB_ACTIONS_AUDIT=false # Audit GitHub Actions artifacts/workflows with gato
GATO_INCLUDE_ALL_ARTIFACT_SECRETS=false # Include noisy artifact secret matches in gato output
# Subdomains
SUBDOMAINS_GENERAL=true # Enable or disable the whole Subdomains module
SUBPASSIVE=true # Passive subdomains search
SUBCRT=true # crtsh search
CTR_LIMIT=999999 # Limit the number of results
SUBNOERROR=false # Check DNS NOERROR response and BF on them
SUBANALYTICS=true # Google Analytics search
SUBBRUTE=true # DNS bruteforcing
SUBSCRAPING=true # Subdomains extraction from passive URLs and live web metadata
SUBPERMUTE=true # DNS permutations
SUBIAPERMUTE=true # Permutations by AI analysis
SUBREGEXPERMUTE=true # Permutations by regex analysis
GOTATOR_FLAGS=" -depth 1 -numbers 3 -mindup -adv -md" # Flags for gotator
PERMUTATIONS_WORDLIST_MODE=auto # auto|full|short (auto: short if subs > threshold, full if DEEP)
PERMUTATIONS_SHORT_THRESHOLD=100 # Use short wordlist when subdomain count exceeds this
SUBTAKEOVER=true # Check subdomain takeovers, false by default cuz nuclei already check this
SUB_RECURSIVE_PASSIVE=false # Uses a lot of API keys queries
DEEP_RECURSIVE_PASSIVE=10 # Number of top subdomains for recursion
SUB_RECURSIVE_BRUTE=false # Needs big disk space and time to resolve
ZONETRANSFER=true # Check zone transfer
S3BUCKETS=true # Check S3 buckets misconfigs
REVERSE_IP=false # Check reverse IP subdomain search (set True if your target is CIDR/IP)
TLS_PORTS="21,22,25,80,110,135,143,261,271,324,443,448,465,563,614,631,636,664,684,695,832,853,854,990,993,989,992,994,995,1129,1131,1184,2083,2087,2089,2096,2221,2252,2376,2381,2478,2479,2482,2484,2679,2762,3077,3078,3183,3191,3220,3269,3306,3410,3424,3471,3496,3509,3529,3539,3535,3660,36611,3713,3747,3766,3864,3885,3995,3896,4031,4036,4062,4064,4081,4083,4116,4335,4336,4536,4590,4740,4843,4849,5443,5007,5061,5321,5349,5671,5783,5868,5986,5989,5990,6209,6251,6443,6513,6514,6619,6697,6771,7202,7443,7673,7674,7677,7775,8243,8443,8991,8989,9089,9295,9318,9443,9444,9614,9802,10161,10162,11751,12013,12109,14143,15002,16995,41230,16993,20003"
INSCOPE=false # Uses inscope tool to filter the scope, requires .scope file in reconftw folder
# Web detection
WEBPROBEFULL=true # Unified web probing over configured ports
WEBSCREENSHOT=true # Webs screenshooting
VIRTUALHOSTS=false # Check virtualhosts by fuzzing HOST header
UNCOMMON_PORTS_WEB="81,300,591,593,832,981,1010,1311,1099,2082,2095,2096,2480,3000,3001,3002,3003,3128,3333,4243,4567,4711,4712,4993,5000,5104,5108,5280,5281,5601,5800,6543,7000,7001,7396,7474,8000,8001,8008,8014,8042,8060,8069,8080,8081,8083,8088,8090,8091,8095,8118,8123,8172,8181,8222,8243,8280,8281,8333,8337,8443,8500,8834,8880,8888,8983,9000,9001,9043,9060,9080,9090,9091,9092,9200,9443,9502,9800,9981,10000,10250,11371,12443,15672,16080,17778,18091,18092,20720,32000,55440,55672"
WEBPROBE_PORTS="80,443,${UNCOMMON_PORTS_WEB}" # Ports used by webprobe_full
# Host
FAVIRECON=true # Favicon-based technology recon for discovered web targets
PORTSCANNER=true # Enable or disable the whole Port scanner module
GEO_INFO=true # Fetch Geolocalization info
PORTSCAN_PASSIVE=true # Port scanner with Shodan
PORTSCAN_ACTIVE=true # Port scanner with nmap
PORTSCAN_ACTIVE_OPTIONS="--top-ports 200 -sV -n -Pn --open --max-retries 2"
PORTSCAN_DEEP_OPTIONS="--top-ports 1000 -sV -n -Pn --open --max-retries 2 --script vulners"
PORTSCAN_STRATEGY=legacy # legacy|naabu_nmap
NAABU_ENABLE=true
NAABU_RATE=1000
NAABU_PORTS="--top-ports 1000"
SERVICE_FINGERPRINT=true # Fingerprint exposed services with nerva
SERVICE_FINGERPRINT_ENGINE="nerva" # nerva
SERVICE_FINGERPRINT_TIMEOUT_MS=2000 # nerva timeout per target (ms)
PORTSCAN_UDP=false
PORTSCAN_UDP_OPTIONS="--top-ports 20 -sU -sV -n -Pn --open"
CDN_IP=true # Check which IPs belongs to CDN
CDN_BYPASS=true # Try origin IP discovery on CDN-fronted hosts with hakoriginfinder
# Web analysis
WAF_DETECTION=true # Detect WAFs
NUCLEICHECK=true # Enable or disable nuclei
NUCLEI_TEMPLATES_PATH="$HOME/nuclei-templates" # Set nuclei templates path
NUCLEI_SEVERITY="info,low,medium,high,critical" # Set templates criticity
NUCLEI_EXTRA_ARGS="" # Additional nuclei extra flags, don't set the severity here but the exclusions like " -etags openssh"
#NUCLEI_EXTRA_ARGS="-etags openssh,ssl -eid node-express-dev-env,keycloak-xss,CVE-2023-24044,CVE-2021-20323,header-sql,header-reflection" # Additional nuclei extra flags, don't set the severity here but the exclusions like " -etags openssh"
NUCLEI_DAST=true # Run additional nuclei -dast module over webs/urls/gf candidates (forced on when VULNS_GENERAL=true, e.g. -a)
URL_CHECK=true # Enable or disable URL collection
URL_CHECK_PASSIVE=true # Search for urls, passive methods from Archive, OTX, CommonCrawl, etc
URL_CHECK_ACTIVE=true # Search for urls by crawling the websites
WAYMORE_TIMEOUT=30m # Timeout for waymore passive URL collection
WAYMORE_LIMIT=5000 # Optional URL collection limit for waymore
URL_GF=true # Url patterns classification
URL_EXT=true # Returns a list of files divided by extension
JSCHECKS=true # JS analysis
FUZZ=true # Web fuzzing
FUZZ_RECURSION_DEPTH=2 # ffuf recursion depth used in DEEP mode
IIS_SHORTNAME=true
CMS_SCANNER=true # CMS scanner
WORDLIST=true # Wordlist generation
ROBOTSWORDLIST=true # Check historic disallow entries on waybackMachine (DEEP mode only)
PASSWORD_DICT=true # Generate password dictionary
PASSWORD_DICT_ENGINE=cewler # cewler|pydictor
PASSWORD_MIN_LENGTH=5 # Min password length
PASSWORD_MAX_LENGTH=14 # Max password length
KATANA_HEADLESS_PROFILE=off # off|smart|full
CLOUD_ENUM_S3_PROFILE=optimized # optimized: quickscan (-qs + safe -m/-b paths) | exhaustive: -m/-b ${tools}/cloud_enum/enum_tools/fuzz.txt (missing fuzz => optimized)
CLOUD_ENUM_S3_THREADS=20 # Threads used by cloud_enum in s3buckets/cloud enumeration
# Vulns
VULNS_GENERAL=false # Enable or disable the vulnerability module (very intrusive and slow)
XSS=true # Check for xss with dalfox
TEST_SSL=true # SSL misconfigs
SSRF_CHECKS=true # SSRF checks
CRLF_CHECKS=true # CRLF checks
LFI=true # LFI by fuzzing
LFI_MAX_URLS=150 # Max single-parameter LFI candidates to test per target (0 = unlimited)
SSTI=true # SSTI by fuzzing
SSTI_ENGINE="TInjA" # SSTI engine
SQLI=true # Check SQLI
SQLMAP=true # Check SQLI with sqlmap
GHAURI=false # Check SQLI with ghauri
BROKENLINKS=true # Check for brokenlinks
BROKENLINKS_ENGINE="second-order" # Broken links engine
SPRAY=true # Performs password spraying
SPRAY_ENGINE="brutespray" # brutespray|brutus
SPRAY_BRUTUS_ONLY_DEEP=true # Run brutus only in DEEP mode unless disabled
BRUTUS_USERNAMES="" # Optional comma-separated usernames for brutus
BRUTUS_PASSWORDS="" # Optional comma-separated passwords for brutus
BRUTUS_KEY_FILE="" # Optional SSH private key path for brutus
COMM_INJ=true # Check for command injections with commix
SMUGGLING=true # Check for HTTP request smuggling flaws
WEBCACHE=true # Check for Web Cache issues
WEBCACHE_TOXICACHE=true # Complement web cache checks with toxicache
BYPASSER4XX=true # Check for 4XX bypasses
FUZZPARAMS=true # Fuzz parameters values
# Extra features
NOTIFICATION=false # Notification for every function
SOFT_NOTIFICATION=false # Only for start/end
DEEP=false # DEEP mode, really slow and don't care about the number of results
DEEP_LIMIT=500 # First limit to not run unless you run DEEP
DEEP_LIMIT2=1500 # Second limit to not run unless you run DEEP
DIFF=false # Diff function, run every module over an already scanned target, printing only new findings (but save everything)
REMOVETMP=false # Delete temporary files after execution (to free up space)
REMOVELOG=false # Delete logs after execution
PROXY=false # Send to proxy the websites found
SENDZIPNOTIFY=false # Send to zip the results (over notify)
PRESERVE=true # set to true to avoid deleting the .called_fn files on really large scans
FFUF_FLAGS=" -mc all -fc 404 -sf -noninteractive -of json" # Ffuf flags
# HTTP options
HEADER="User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:72.0) Gecko/20100101 Firefox/72.0" # Default header
# Threads (auto-scaled based on CPU cores, override to set fixed values)
AVAILABLE_CORES=$(nproc 2>/dev/null || sysctl -n hw.ncpu 2>/dev/null || echo 4)
FFUF_THREADS=$((AVAILABLE_CORES * 10))
HTTPX_THREADS=$((AVAILABLE_CORES * 12))
HTTPX_UNCOMMONPORTS_THREADS=$((AVAILABLE_CORES * 25))
KATANA_THREADS=$((AVAILABLE_CORES * 5))
BRUTESPRAY_CONCURRENCE=$((AVAILABLE_CORES * 2))
DNSTAKE_THREADS=$((AVAILABLE_CORES * 25))
DALFOX_THREADS=$((AVAILABLE_CORES * 50))
DNS_RESOLVER=auto # auto|puredns|dnsx (auto: detects NAT/CGNAT → dnsx for home, puredns for VPS)
PUREDNS_PUBLIC_LIMIT=0 # Set between 2000 - 10000 if your router blows up, 0 means unlimited
PUREDNS_TRUSTED_LIMIT=400
PUREDNS_WILDCARDTEST_LIMIT=30
PUREDNS_WILDCARDBATCH_LIMIT=1500000
DNSX_THREADS=25 # Threads for dnsx when behind NAT (safe for home routers)
DNSX_RATE_LIMIT=100 # QPS for dnsx
DNSVALIDATOR_THREADS=200
INTERLACE_THREADS=10
LFI_INTERLACE_THREADS=4 # Dedicated interlace concurrency for LFI
TLSX_THREADS=1000
XNLINKFINDER_DEPTH=3
# Rate limits
HTTPX_RATELIMIT=150
NUCLEI_RATELIMIT=150
FFUF_RATELIMIT=0
LFI_FFUF_THREADS=20 # Dedicated ffuf threads for LFI
LFI_FFUF_RATELIMIT=50 # Dedicated ffuf rate limit for LFI
# Timeouts
SUBFINDER_ENUM_TIMEOUT=180 # Minutes
CMSSCAN_TIMEOUT=3600 # Seconds
FFUF_MAXTIME=900 # Seconds
LFI_INTERLACE_TIMEOUT=180 # Seconds per LFI interlace worker
LFI_FFUF_TIMEOUT=10 # Seconds per LFI HTTP request
LFI_FFUF_MAXTIME=90 # Seconds per single LFI ffuf job
LFI_FOLLOW_REDIRECTS=false # Follow redirects during LFI fuzzing
HTTPX_TIMEOUT=10 # Seconds
HTTPX_UNCOMMONPORTS_TIMEOUT=10 # Seconds
PERMUTATIONS_LIMIT=21474836480 # Bytes, default is 20 GB
DNS_BRUTE_TIMEOUT=0 # timeout/gtimeout duration for DNS bruteforce (0 disables hard-timeout, e.g. 4h)
DNS_RESOLVE_TIMEOUT=0 # timeout/gtimeout duration for DNS resolve (0 disables hard-timeout, e.g. 6h)
DNS_HEARTBEAT_INTERVAL_SECONDS=20 # Progress heartbeat interval for long DNS jobs
# lists
fuzz_wordlist=${WORDLISTS_DIR}/fuzz_wordlist.txt
lfi_wordlist=${WORDLISTS_DIR}/lfi_wordlist.txt
ssti_wordlist=${WORDLISTS_DIR}/ssti_wordlist.txt
subs_wordlist=${WORDLISTS_DIR}/subdomains.txt
subs_wordlist_big=${tools}/subdomains_n0kovo_big.txt
headers_inject=${WORDLISTS_DIR}/headers_inject.txt
resolvers=${tools}/resolvers.txt
resolvers_trusted=${tools}/resolvers_trusted.txt
# Ax Fleet (formerly Axiom — uses attacksurge/ax)
# Resolver paths on Ax instances (change if your fleet uses a different home dir)
AXIOM_RESOLVERS_PATH="/home/op/lists/resolvers.txt"
AXIOM_RESOLVERS_TRUSTED_PATH="/home/op/lists/resolvers_trusted.txt"
# Will not start a new fleet if one exist w/ same name and size (or larger)
# AXIOM=false Uncomment only to overwrite command line flags
AXIOM_FLEET_LAUNCH=true # Enable or disable spin up a new fleet, if false it will use the current fleet with the AXIOM_FLEET_NAME prefix
AXIOM_FLEET_NAME="reconFTW" # Fleet's prefix name
AXIOM_FLEET_COUNT=10 # Fleet's number
AXIOM_FLEET_REGIONS="eu-central" # Fleet's region
AXIOM_FLEET_SHUTDOWN=true # # Enable or disable delete the fleet after the execution
AXIOM_AUTO_FIX_HOSTKEY=true # Auto-repair known_hosts entries on SSH host-key mismatch before fallback to local mode
# This is a script on your reconftw host that might prep things your way...
#AXIOM_POST_START="~/Tools/axiom_config.sh" # Useful to send your config files to the fleet
AXIOM_EXTRA_ARGS="" # Leave empty if you don't want to add extra arguments
#AXIOM_EXTRA_ARGS=" --rm-logs" # Example
# Faraday-Server
FARADAY=false # Enable or disable Faraday integration
FARADAY_WORKSPACE="reconftw" # Faraday workspace
# AI
AI_EXECUTABLE="python3" # Python executable fallback if reconftw_ai venv python is not available
AI_MODEL="llama3:8b" # Model to use
AI_REPORT_TYPE="md" # Report type to use (md, txt)
AI_REPORT_PROFILE="bughunter" # Report profile to use (executive, brief, or bughunter)
AI_PROMPTS_FILE="" # Optional custom prompts file (empty uses reconftw_ai default)
AI_MAX_CHARS_PER_FILE=50000 # Max chars loaded per file before truncation
AI_MAX_FILES_PER_CATEGORY=200 # Max files loaded per category for AI context
AI_REDACT=true # Redact sensitive indicators before AI analysis
AI_ALLOW_MODEL_PULL=false # Allow reconftw_ai to auto-pull missing model
AI_STRICT=false # Fail AI analysis if one or more categories have no data
# API & Advanced Web Checks
GRAPHQL_CHECK=true # Detect GraphQL endpoints and introspection
GQLSPECTION=false # Run GQLSpection deep introspection on detected GraphQL endpoints (heavier)
PARAM_DISCOVERY=true # Parameter discovery with arjun
GRPC_SCAN=false # Attempt basic gRPC reflection on common ports
LLM_PROBE=false # Probe discovered web/API endpoints for LLM services with julius
LLM_PROBE_AUGUSTUS=false # Include augustus generator config in julius output
# IPv6
IPV6_SCAN=true # Attempt IPv6 discovery/portscan where addresses exist
# Wordlists / threads for new modules
ARJUN_THREADS=10
# Data & Automation
ASSET_STORE=true # Append assets/findings to assets.jsonl
EXPORT_FORMAT="" # Optional exporter at end of scan: json|html|csv|all
REPORT_ONLY=false # Rebuild report artifacts from existing results (or use --report-only)
QUICK_RESCAN=false # Skip heavy steps if no new subdomains/webs
CHUNK_LIMIT=2000 # Split very large lists into chunks (urls, webs)
HOTLIST_TOP=50 # Number of top risky assets to highlight
# Performance
RESOLVER_IQ=false # Prefer fast/healthy resolvers (experimental)
PERF_PROFILE="balanced" # low|balanced|max
# Estimated durations for skipped heavy modules (seconds)
TIME_EST_NUCLEI=600
TIME_EST_FUZZ=900
TIME_EST_URLCHECKS=300
TIME_EST_JSCHECKS=300
TIME_EST_API=300
TIME_EST_GQL=180
TIME_EST_PARAM=240
TIME_EST_GRPC=120
TIME_EST_IIS=60
# TERM COLORS
bred='\033[1;31m'
bblue='\033[1;34m'
bgreen='\033[1;32m'
byellow='\033[1;33m'
red='\033[0;31m'
blue='\033[0;34m'
green='\033[0;32m'
cyan='\033[0;36m'
yellow='\033[0;33m'
reset='\033[0m'
Protezioni per i resolver DNS:
RESOLVER_DOWNLOAD_CONNECT_TIMEOUT, RESOLVER_DOWNLOAD_MAX_TIME, RESOLVER_DOWNLOAD_RETRY e RESOLVER_DOWNLOAD_RETRY_DELAY.DNS_BRUTE_TIMEOUT=0 e DNS_RESOLVE_TIMEOUT=0 disabilitano il timeout rigido per impostazione predefinita (consigliato per set di target molto grandi). L'avanzamento tramite heartbeat viene comunque stampato ogni DNS_HEARTBEAT_INTERVAL_SECONDS.```bash
DNS_BRUTE_TIMEOUT=4h
DNS_RESOLVE_TIMEOUT=6h
DNS_HEARTBEAT_INTERVAL_SECONDS=20**Dettagli completi**: consulta la [Guida di configurazione](https://github.com/six2dez/reconftw/wiki/3.-Configuration-file).
---
## 🚀 Utilizzo
reconFTW supporta diverse modalità e opzioni per una ricognizione flessibile. Usa il flag `-h` per visualizzare il menu di aiuto.
### Opzioni del target
| Flag | Descrizione |
| ---- | ------------------------------------------------------------ |
| `-d` | Dominio target singolo (es., `example.com`) |
| `-l` | File con elenco di domini target (uno per riga) |
| `-m` | Target multi-dominio (es., nome azienda per domini correlati) |
| `-x` | Escludi sottodomini (elenco fuori scope) |
| `-i` | Includi sottodomini (elenco in scope) |
### Opzioni di modalità
| Flag | Descrizione |
| ---- | --------------------------------------------------------------------- |
| `-r` | **Recon**: ricognizione completa senza attacchi attivi |
| `-s` | **Subdomains**: enumerazione sottodomini, probing web e takeover |
| `-p` | **Passive**: solo ricognizione passiva |
| `-a` | **All**: ricognizione completa più controlli attivi di vulnerabilità |
| `-w` | **Web**: controlli di vulnerabilità su target web specifici |
| `-n` | **OSINT**: scansione OSINT senza enumerazione sottodomini o attacchi |
| `-z` | **Zen**: ricognizione leggera con controlli di base e alcune vulnerabilità |
| `-c` | **Custom**: esegue una funzione specifica (richiede argomenti aggiuntivi) |
| `-h` | Mostra il menu di aiuto |
### Opzioni generali
| Flag | Descrizione |
| ----------------- | -------------------------------------------------------- |
| `--deep` | Abilita scansione profonda (più lenta, consigliato VPS) |
| `-f` | Percorso file di configurazione personalizzato |
| `-o` | Directory di output per i risultati |
| `-v` | Abilita scansione distribuita Ax |
| `--vps-count` | Sovrascrive il conteggio istanze della flotta Ax per questa esecuzione |
| `-q` | Imposta il limite di richieste (richieste al secondo) |
| `-y` | Abilita l'analisi dei risultati con AI |
| `--check-tools` | Esce se mancano gli strumenti richiesti |
| `--quick-rescan` | Salta i moduli pesanti quando non si trovano nuovi sottodomini/web |
| `--health-check` | Esegue il controllo di salute del sistema ed esce |
| `--incremental` | Scansiona solo i nuovi risultati dall'ultima esecuzione |
| `--adaptive-rate` | Regola automaticamente i limiti di richiesta su errori (429/503) |
| `--dry-run` | Mostra cosa verrebbe eseguito senza lanciare i comandi |
| `--parallel` | Esegue funzioni indipendenti in parallelo (più veloce, più RAM) |
| `--no-parallel` | Forza l'esecuzione sequenziale anche se il parallelo è abilitato |
| `--monitor` | Modalità di monitoraggio continuo (target singolo; `-w` supporta `-l`) |
| `--monitor-interval` | Minuti tra i cicli di monitoraggio |
| `--monitor-cycles` | Si ferma dopo N cicli (0 = infinito) |
| `--report-only` | Ricostruisce gli artefatti del report senza scansionare |
| `--refresh-cache` | Forza l'aggiornamento di resolver/wordlist in cache |
| `--export` | Esporta artefatti: `json`, `html`, `csv` o `all` |
### Esempi di utilizzo
1. **Ricognizione completa su un singolo target**: ```bash
./reconftw.sh -d target.com -r
11. **Forza l'aggiornamento della cache**: ```bash
./reconftw.sh -d target.com -r --refresh-cache
13. **Monitoraggio continuo (ogni 30 minuti, 48 cicli)**: ```bash
./reconftw.sh -d target.com -r --monitor --monitor-interval 30 --monitor-cycles 48
**Guida completa**: Consulta la [Guida all'uso](https://github.com/six2dez/reconftw/wiki/2.-Usage-Guide).
---
## ☁️ Supporto Ax Framework (precedentemente Axiom)
reconFTW si integra con [Ax](https://github.com/attacksurge/ax) per la scansione distribuita, riducendo i tempi di esecuzione distribuendo le attività su più istanze cloud.
- **Configurazione**: Seleziona `reconftw` come provisioner durante la configurazione di Ax (`axiom-configure`).
- **Gestione Fleet**: Crea e distruggi automaticamente le fleet (`AXIOM_FLEET_LAUNCH`, `AXIOM_FLEET_SHUTDOWN`) oppure utilizza una fleet esistente.
- **Configurazione**: Imposta dimensione della fleet, regione e nome in `reconftw.cfg` (`AXIOM_FLEET_COUNT`, `AXIOM_FLEET_REGIONS`, `AXIOM_FLEET_NAME`).
**Esempio**:```bash
./reconftw.sh -d target.com -r -v
Dettagli: Consulta la documentazione ufficiale di Ax e il repository attacksurge/ax.
reconFTW si integra con Faraday per la reportistica web e la gestione delle vulnerabilità.
faraday-cli e configura il workspace in reconftw.cfg (FARADAY_WORKSPACE).FARADAY=true in reconftw.cfg.reconFTW utilizza l'AI per generare report dettagliati dai risultati delle scansioni con lo strumento reconftw_ai.
llama3:8b tramite AI_MODEL).AI_REPORT_TYPE).AI_REPORT_PROFILE).reconftw salva un report leggibile dalla macchina in ai_result/reconftw_analysis.json.AI_MAX_CHARS_PER_FILE e AI_MAX_FILES_PER_CATEGORY.AI_REDACT e AI_STRICT.Esempio:```yaml AI_EXECUTABLE="python3" AI_MODEL="llama3:8b" AI_REPORT_TYPE="md" AI_REPORT_PROFILE="bughunter" AI_MAX_CHARS_PER_FILE=50000 AI_MAX_FILES_PER_CATEGORY=200 AI_REDACT=true AI_ALLOW_MODEL_PULL=false AI_STRICT=false
---
## 🗂️ Gestione dei Dati
Gestisci i dati di scansione e le chiavi API in modo sicuro utilizzando un repository privato.
Quando `ASSET_STORE=true`, reconFTW aggrega i risultati chiave in `assets.jsonl` durante ogni esecuzione, semplificando la sincronizzazione solo dei delta utili al tuo repository privato.
### Makefile
Utilizza il `Makefile` fornito per una gestione semplice del repository (richiede [GitHub CLI](https://cli.github.com/)).
1. **Bootstrap**: ```bash
export PRIV_REPO="$HOME/reconftw-data"
make bootstrap
reconFTW utilizza bats-core per i test automatizzati.
brew install bats-core
apt install bats
git clone https://github.com/bats-core/bats-core.git /tmp/bats sudo /tmp/bats/install.sh /usr/local
### Esecuzione dei Test```bash
# Unit tests only
make test
# Unit + integration tests
make test-all
# Via the runner script
./tests/run_tests.sh # unit only
./tests/run_tests.sh --all # unit + integration
tests/ ├── run_tests.sh # Test runner script ├── unit/ # Unit tests (fast, no network) │ ├── test_sanitize.bats │ ├── test_utils.bats │ └── test_validation.bats ├── integration/ # Integration tests (require installed tools) │ └── test_smoke.bats ├── security/ # Security tests (injection, etc.) │ └── test_injection.bats ├── mocks/ # Mock tools for offline testing └── fixtures/ # Shared test data files
### Esecuzione dei Test di Sicurezza```bash
# Test command injection prevention
make test-security
# Or directly
bats tests/security/
I test utilizzano il pattern --source-only per caricare le funzioni senza eseguire lo script principale:```bash
#!/usr/bin/env bats
setup() { source ./reconftw.sh --source-only }
@test "sanitize_domain strips invalid chars" { result="$(sanitize_domain 'exam;ple.com')" [ "$result" = "example.com" ] }
### Pipeline CI
Il workflow di GitHub Actions (`.github/workflows/tests.yml`) viene eseguito a ogni push e pull request:
1. **ShellCheck** — esegue il lint di `reconftw.sh`, `modules/*.sh` e `install.sh`
2. **Unit Tests** — esegue tutti i file `tests/unit/*.bats`
3. **Integration Tests** — installa reconFTW e valida la disponibilità degli strumenti
---
## Mindmap/Workflow

---
## Video di esempio

---
## 🤝 Come Contribuire
Consulta [CONTRIBUTING.md](https://github.com/six2dez/reconftw/blob/main/CONTRIBUTING.md) per la guida completa alla contribuzione, inclusi setup di sviluppo, stile del codice, test e processo delle pull request.
Link rapidi:
- [Segnala un Bug](https://github.com/six2dez/reconftw/issues/new/choose)
- [Invia una Pull Request](https://github.com/six2dez/reconftw/tree/dev) (destinata al branch `dev`)
- [Codice di Condotta](https://github.com/six2dez/reconftw/blob/main/CODE_OF_CONDUCT.md)
---
## 🔒 Sicurezza
Per la policy di sicurezza, la gestione dei segreti e la segnalazione di vulnerabilità, consulta [SECURITY.md](https://github.com/six2dez/reconftw/blob/main/SECURITY.md).
---
## ❓ Hai Bisogno di Aiuto?
- **Wiki**: Esplora la [Wiki di reconFTW](https://github.com/six2dez/reconftw/wiki).
- **FAQ**: Controlla le [FAQ](https://github.com/six2dez/reconftw/wiki/7.-FAQs).
- **Community**: Unisciti al [server Discord](https://discord.gg/R5DdXVEdTy) o al [gruppo Telegram](https://t.me/joinchat/TO_R8NYFhhbmI5co).
---
## 💖 Supporta Questo Progetto
Supporta lo sviluppo di reconFTW tramite:
- **Buy Me a Coffee**: [buymeacoffee.com/six2dez](https://www.buymeacoffee.com/six2dez)
[<img src="https://assets.kitploit.com/production/public/readmes/670/1177bf77de4c288d45b816dd405a8b5027116f0b1893449986cf200c765707ad.webp">](https://www.buymeacoffee.com/six2dez)
- **Referral DigitalOcean**: [Link di Referral](https://www.digitalocean.com/?refcode=f362a6e193a1&utm_campaign=Referral_Invite&utm_medium=Referral_Program&utm_source=badge)
<a href="https://www.digitalocean.com/?refcode=f362a6e193a1&utm_campaign=Referral_Invite&utm_medium=Referral_Program&utm_source=badge"><img src="https://web-platforms.sfo2.cdn.digitaloceanspaces.com/WWW/Badge%201.svg" alt="DigitalOcean Referral Badge" /></a>
- **Sponsorizzazione GitHub**: [github.com/sponsors/six2dez](https://github.com/sponsors/six2dez)
---
## 🙏 Ringraziamenti
Un ringraziamento speciale ai seguenti servizi per il supporto a reconFTW:
- [C99](https://api.c99.nl/)
- [CIRCL](https://www.circl.lu/)
- [NetworksDB](https://networksdb.io/)
- [ipinfo](https://ipinfo.io/)
- [hackertarget](https://hackertarget.com/)
- [Censys](https://censys.io/)
- [Fofa](https://fofa.info/)
- [intelx](https://intelx.io/)
- [Whoxy](https://www.whoxy.com/)
---
## 📝 Changelog
Consulta [CHANGELOG.md](https://github.com/six2dez/reconftw/blob/main/CHANGELOG.md) per un elenco dettagliato delle modifiche in ogni release.
---
## 🛠️ Sviluppo
### Struttura del Progetto```
reconftw/
├── reconftw.sh # Main entry point (~500 lines)
├── reconftw.cfg # Configuration file
├── modules/ # Phase modules
│ ├── utils.sh # Utilities, sanitization, caching, circuit breaker
│ ├── core.sh # Framework core, logging, lifecycle, health check
│ ├── modes.sh # Scan modes, argument parsing
│ ├── subdomains.sh # Subdomain enumeration
│ ├── web.sh # Web analysis, nuclei scans
│ ├── vulns.sh # Vulnerability scanning
│ ├── osint.sh # OSINT functions
│ └── axiom.sh # Ax/Axiom fleet helpers
├── lib/ # Pure utility libraries
│ └── validation.sh # Input validation functions
├── tests/ # Test suite (100+ tests)
│ ├── unit/ # Unit tests (bats)
│ ├── integration/ # Integration/smoke tests
│ └── security/ # Injection prevention tests
├── docs/ # Documentation
│ └── ARCHITECTURE.md # Detailed architecture guide
└── secrets.cfg.example # Template for API keys
make test # Unit tests make test-security # Security tests make test-all # All tests make lint # Shellcheck make lint-fix # Auto-fix with shfmt
### Flusso di Sviluppo```bash
# 1. Source without executing (for testing)
source ./reconftw.sh --source-only
# 2. Test individual functions
sanitize_domain "test;domain.com"
# 3. Run health check
./reconftw.sh --health-check
# 4. Dry run to preview
./reconftw.sh -d example.com -r --dry-run
Consulta CONTRIBUTING.md per le linee guida di sviluppo e docs/ARCHITECTURE.md per i dettagli tecnici.
reconFTW è concesso in licenza sotto la MIT License.
cloudhunter_* sono stati rimossi; usa invece subdomains/cloud_enum_buckets_trufflehog.txt.ws:// e wss://.assets.jsonl per l'automazione a valle quando ASSET_STORE è abilitato.report/report.json e report/index.html al termine della scansione.--health-check (usato anche da Docker HEALTHCHECK).--incremental).--adaptive-rate).STRUCTURED_LOGGING).--dry-run).--parallel, disattivabile con --no-parallel).secrets.cfg e segreti di runtime Docker (vedi SECURITY.md).