A Light-weight automated, modular, configurable recon pipeline built for bug bounty hunters and pentesters.
Supports multiple recon modes, API discovery logic, structured output, and automated command logging.
Choose the strategy you prefer:
Quick passive + resolving + probing
Perfect for initial triage.
Aggressive deep recon
Bruteforce, permutations, ports, crawling.
Minimal-noise recon
No brute-force, no heavy scans.
Focused on API hosts & routes
Custom filtering + JS crawling.
- subfinder (passive subdomain enumeration)
- shuffledns (dns brute-force/resolve)
- alterx (subdomain permutation generator)
- dnsx (DNS resolver)
- naabu (port scanner)
- httpx (HTTP probing)
- katana (crawler + JS parser)
For each target, the script generates:
recon_output/<target>/
│
├── subfinder_raw.txt
├── shuffledns_raw.txt
├── all_subdomains.txt
├── subdomains_alterx.txt
├── subdomains_to_resolve.txt
├── resolved_subdomains.txt
├── naabu_open_ports.txt
├── httpx_live_hosts.txt
├── httpx_urls_only.txt
├── api_hosts.txt
├── katana_urls.txt
└── commands_reference.md
All tool arguments, modes, and paths are fully customizable via:
config.yaml
Each tool can have:
- default args
- mode-specific args
- enable/disable flags
Modes are defined under:
modes:
fast:
full:
stealth:
api-only:
Run recon:
python3 recon_pipeline.py -c config.yaml -t example.com -m fullAvailable modes:
fast
full
stealth
api-onlyFull docs here → DOCUMENTATION.md
Includes:
- mode behavior
- tool flows
- output reference
- filter explanation
- troubleshooting