Secure_with_Rajatsecure_with_rajat
// flagshipOpen sourcev2.0.0

ShadowRecon

OSINT & Reconnaissance Platform · CLI

One target in — a full attack-surface map, risk score and AI summary out. ShadowRecon runs 29 specialized modules across domains, IPs, phone numbers, usernames, images and documents, through an eight-phase async pipeline behind a Rich/Typer terminal UI — and the same offensive mindset goes into every client build.

PythonasyncioaiohttpaiodnsdnspythonTyperRichSQLiteJinja2
rajat@studio — ~/shadowrecon
secure_channelencrypted
TYPE
OSINT / Recon Platform
MODULES
29 modules
PHASES
8-stage pipeline
VERSION
2.0.0
// pipeline --stages 8

The eight-phase pipeline

01 / network

Map

WHOIS, DNS records, reverse DNS, ASN/BGP, IP geolocation, port scan and optional OS fingerprinting.

02 / subdomain

Enumerate

Passive discovery from 5 providers plus active DNS brute-force, wildcard detection and dedup.

03 / web

Probe

HTTP/SSL audit, WAF/CDN detection, tech fingerprinting, directories, JS endpoints and takeover checks.

04 / cloud

Expose

Public S3 / GCS / Azure bucket discovery, public-listing detection and provider identification.

05 / intel

Enrich

Shodan host data, VirusTotal reputation, SecurityTrails subdomains and historical DNS.

06 / osint

Attribute

Email harvesting, SPF/DMARC, username search across 14 platforms and phone validation/carrier intel.

07 / media

Extract

Image EXIF / GPS / OCR plus PDF, DOCX, PPTX and XLSX document metadata extraction.

08 / analysis

Score

Risk scoring across all findings plus an AI-generated summary of the attack surface.

// features

What it does

29 specialized modules across domains, IPs, phone numbers, usernames, images and documents
Network recon — WHOIS, full DNS (A/AAAA/MX/NS/TXT/CNAME/SOA), reverse DNS, ASN/BGP, IP geolocation and port scanning
Subdomain enumeration — 5 passive providers (crt.sh, urlscan, SecurityTrails, AlienVault OTX, HackerTarget) plus active brute-force and wildcard detection
Web analysis — HTTP security audit, SSL/TLS certs, WAF/CDN detection, tech fingerprinting, directory discovery, JS endpoint extraction and subdomain-takeover
Cloud recon — public S3 / GCS / Azure bucket discovery and public-listing detection
Threat intelligence — Shodan, VirusTotal, SecurityTrails and historical DNS enrichment
Digital-identity OSINT — email harvesting, SPF/DMARC, username search across 14 platforms and phone carrier/region intel
Media & document OSINT — image EXIF / GPS / OCR and PDF / DOCX / PPTX / XLSX metadata
Risk scoring plus AI-generated summaries (Anthropic / OpenAI)
JSON, CSV, interactive HTML dashboard and optional PDF reporting, with persistent SQLite scan history
// stack
PythonasyncioaiohttpaiodnsdnspythonTyperRichSQLiteJinja2

Built async-first on aiohttp + aiodns + dnspython, with a Rich/Typer terminal UI, persistent SQLite scan history, risk scoring and AI summaries, and JSON / CSV / HTML / PDF reporting. Optional Shodan, VirusTotal and SecurityTrails integrations.

// open_source

Read the code

MIT-spirited, on GitHub — clone it, run it, read how it's built.