Skip to main content

Recon-ng

Full-featured, modular web-reconnaissance framework with a Metasploit-style CLI, SQLite workspaces, and a marketplace, licensed under GPL-3.0-or-later.

Technical Architecture & Overview

Recon-ng is a full-featured web-reconnaissance framework that uses a modular architecture and SQLite-backed workspaces to collect and store OSINT data. Its interactive command-line interface resembles the Metasploit Framework and is intended exclusively for web-based reconnaissance. Modules are installed from an official marketplace and include integrations with search engines, breach databases, and third-party APIs.

Targeted Technical Use Cases

Structure a multi-step OSINT investigation into a reproducible, workspace-based workflow with stored findings and cross-referenced entities.

Evaluation & Trade-offs

Core Strengths

  • +Modular marketplace makes it easy to add only the data sources needed for each investigation.
  • +SQLite database and workspaces keep engagement data organized and reusable.
  • +Metasploit-style CLI lowers the learning curve for penetration testers.

Trade-Offs & Limitations

  • -Some marketplace modules are outdated or no longer maintained.
  • -Many modules require separate API keys and provider accounts.
  • -Not a vulnerability scanner; limited to reconnaissance tasks.

Defensive Security Application

Document an organization's public exposure, compare findings over time, and identify assets that need remediation or monitoring.

Frequently Asked Questions

What is Recon-ng?

Recon-ng is a full-featured web-reconnaissance framework that uses a modular architecture and SQLite-backed workspaces to collect and store OSINT data. Its interactive command-line interface resembles the Metasploit Framework and is intended exclusively for web-based reconnaissance. Modules are installed from an official marketplace and include integrations with search engines, breach databases, and third-party APIs.

What is Recon-ng used for?

Structure a multi-step OSINT investigation into a reproducible, workspace-based workflow with stored findings and cross-referenced entities.

What are the strengths of Recon-ng?
  • +Modular marketplace makes it easy to add only the data sources needed for each investigation.
  • +SQLite database and workspaces keep engagement data organized and reusable.
  • +Metasploit-style CLI lowers the learning curve for penetration testers.
What are the limitations of Recon-ng?
  • +Some marketplace modules are outdated or no longer maintained.
  • +Many modules require separate API keys and provider accounts.
  • +Not a vulnerability scanner; limited to reconnaissance tasks.
How is Recon-ng used defensively?

Document an organization's public exposure, compare findings over time, and identify assets that need remediation or monitoring.