Skip to content

Latest commit

 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

🔎 Bug Bounty Recon Automation Pipeline

A Light-weight automated, modular, configurable recon pipeline built for bug bounty hunters and pentesters.

Supports multiple recon modes, API discovery logic, structured output, and automated command logging.


🚀 Features

✔ Multiple Recon Modes

Choose the strategy you prefer:

1. Fast

Quick passive + resolving + probing
Perfect for initial triage.

2. Full

Aggressive deep recon
Bruteforce, permutations, ports, crawling.

3. Stealth

Minimal-noise recon
No brute-force, no heavy scans.

4. API-Only

Focused on API hosts & routes
Custom filtering + JS crawling.


🛠 Tools Integrated

  • subfinder (passive subdomain enumeration)
  • shuffledns (dns brute-force/resolve)
  • alterx (subdomain permutation generator)
  • dnsx (DNS resolver)
  • naabu (port scanner)
  • httpx (HTTP probing)
  • katana (crawler + JS parser)

📁 Output Structure

For each target, the script generates:

recon_output/<target>/
│
├── subfinder_raw.txt
├── shuffledns_raw.txt
├── all_subdomains.txt
├── subdomains_alterx.txt
├── subdomains_to_resolve.txt
├── resolved_subdomains.txt
├── naabu_open_ports.txt
├── httpx_live_hosts.txt
├── httpx_urls_only.txt
├── api_hosts.txt
├── katana_urls.txt
└── commands_reference.md

⚙ Configuration

All tool arguments, modes, and paths are fully customizable via:

config.yaml

Each tool can have:

  • default args
  • mode-specific args
  • enable/disable flags

Modes are defined under:

modes:
  fast:
  full:
  stealth:
  api-only:

▶ Usage

Run recon:

python3 recon_pipeline.py -c config.yaml -t example.com -m full

Available modes:

fast
full
stealth
api-only

📚 Documentation

Full docs here → DOCUMENTATION.md

Includes:

  • mode behavior
  • tool flows
  • output reference
  • filter explanation
  • troubleshooting

About

Configurable Python reconnaissance workflow for authorised security testing, with fast, full, stealth and API-focused modes.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages