ShadowRecon
One target in — a full attack-surface map, risk score and AI summary out. ShadowRecon runs 29 specialized modules across domains, IPs, phone numbers, usernames, images and documents, through an eight-phase async pipeline behind a Rich/Typer terminal UI — and the same offensive mindset goes into every client build.
The eight-phase pipeline
Map
WHOIS, DNS records, reverse DNS, ASN/BGP, IP geolocation, port scan and optional OS fingerprinting.
Enumerate
Passive discovery from 5 providers plus active DNS brute-force, wildcard detection and dedup.
Probe
HTTP/SSL audit, WAF/CDN detection, tech fingerprinting, directories, JS endpoints and takeover checks.
Expose
Public S3 / GCS / Azure bucket discovery, public-listing detection and provider identification.
Enrich
Shodan host data, VirusTotal reputation, SecurityTrails subdomains and historical DNS.
Attribute
Email harvesting, SPF/DMARC, username search across 14 platforms and phone validation/carrier intel.
Extract
Image EXIF / GPS / OCR plus PDF, DOCX, PPTX and XLSX document metadata extraction.
Score
Risk scoring across all findings plus an AI-generated summary of the attack surface.
What it does
Built async-first on aiohttp + aiodns + dnspython, with a Rich/Typer terminal UI, persistent SQLite scan history, risk scoring and AI summaries, and JSON / CSV / HTML / PDF reporting. Optional Shodan, VirusTotal and SecurityTrails integrations.
Read the code
MIT-spirited, on GitHub — clone it, run it, read how it's built.