This repo contains two reconnaissance scripts:
host/recon-collect.shβ General host/URL recon (domains, DNS, IPs, SSL/TLS, headers, metadata, subdomains, dirs, etc.).api/api-recon.shβ API-specific recon (endpoints, parameters, fuzzing, API docs detection).
# Host recon tools
sudo ./install-recon-tools-rhel.sh
# API recon tools
sudo ./install-api-recon-tools-rhel.sh./host/recon-collect.sh -u <url-or-host> [-o output.md] [-p quick|deep]-uβ URL/host (e.g.https://example.com)-oβ Markdown report (default:./recon-report.md)-pβquick(default, top ports) ordeep(full scan)
Finds: WHOIS, DNS, IPs, ASN, traceroute, ports (nmap/masscan), TLS (openssl/testssl/sslyze), headers, metadata, favicon hash, Wayback snapshots, subdomains, dirs, quick probes, email security.
./api/api-recon.sh -u <api-host-or-url> [-o output.md] [-m quick|deep]-uβ API host or base URL (e.g.https://api.example.com)-oβ Markdown report (default:./api-recon-report.md)-mβquickordeep
Finds: Swagger/OpenAPI/GraphQL docs, endpoints (kiterunner), hidden params (Arjun), fuzzed paths & payloads (ffuf), GraphQL checks, basic header/sensitive info leaks.
- Markdown report (
-o) with organized findings. - Raw tool outputs in
/tmp/recon-XXXXor/tmp/api-recon-XXXXfor manual review.