Recon-ng
Full-featured, modular web-reconnaissance framework with a Metasploit-style CLI, SQLite workspaces, and a marketplace, licensed under GPL-3.0-or-later.
Technical Architecture & Overview
Recon-ng is a full-featured web-reconnaissance framework that uses a modular architecture and SQLite-backed workspaces to collect and store OSINT data. Its interactive command-line interface resembles the Metasploit Framework and is intended exclusively for web-based reconnaissance. Modules are installed from an official marketplace and include integrations with search engines, breach databases, and third-party APIs.
Targeted Technical Use Cases
Structure a multi-step OSINT investigation into a reproducible, workspace-based workflow with stored findings and cross-referenced entities.
Evaluation & Trade-offs
Core Strengths
- +Modular marketplace makes it easy to add only the data sources needed for each investigation.
- +SQLite database and workspaces keep engagement data organized and reusable.
- +Metasploit-style CLI lowers the learning curve for penetration testers.
Trade-Offs & Limitations
- -Some marketplace modules are outdated or no longer maintained.
- -Many modules require separate API keys and provider accounts.
- -Not a vulnerability scanner; limited to reconnaissance tasks.
Defensive Security Application
Document an organization's public exposure, compare findings over time, and identify assets that need remediation or monitoring.
Frequently Asked Questions
What is Recon-ng?→
Recon-ng is a full-featured web-reconnaissance framework that uses a modular architecture and SQLite-backed workspaces to collect and store OSINT data. Its interactive command-line interface resembles the Metasploit Framework and is intended exclusively for web-based reconnaissance. Modules are installed from an official marketplace and include integrations with search engines, breach databases, and third-party APIs.
What is Recon-ng used for?→
Structure a multi-step OSINT investigation into a reproducible, workspace-based workflow with stored findings and cross-referenced entities.
What are the strengths of Recon-ng?→
- +Modular marketplace makes it easy to add only the data sources needed for each investigation.
- +SQLite database and workspaces keep engagement data organized and reusable.
- +Metasploit-style CLI lowers the learning curve for penetration testers.
What are the limitations of Recon-ng?→
- +Some marketplace modules are outdated or no longer maintained.
- +Many modules require separate API keys and provider accounts.
- +Not a vulnerability scanner; limited to reconnaissance tasks.
How is Recon-ng used defensively?→
Document an organization's public exposure, compare findings over time, and identify assets that need remediation or monitoring.