
reconftw is a bash-driven reconnaissance framework that chains subdomain enumeration, OSINT, and vulnerability checks into one configurable pipeline for authorized penetration testers and bug bounty researchers.
| Tool | six2dez/reconftw — automated reconnaissance framework that orchestrates subdomain enumeration, OSINT, and vulnerability scanning |
| Category | Reconnaissance / attack surface mapping automation |
| Primary Use | Running end-to-end recon pipelines — passive and active subdomain discovery, OSINT, and web checks — during scoped engagements |
| Safe Use | Authorized penetration tests, bug bounty programs with defined scope, and internal labs; the README's own disclaimer states attacking targets without prior consent is illegal |
| Telemetry Note | Active modes generate heavy DNS resolution, bruteforce traffic, and nuclei probe requests that surface readily in WAF logs, DNS query analytics, and SIEM alerting on scanning behavior |
reconftw is a Shell-based reconnaissance framework from six2dez that has accumulated over 8,100 stars on GitHub, making it one of the most-watched automation projects in the offensive recon space. Current release is v4.1 under an MIT license, and the project is actively distributed through Docker on Docker Hub alongside Terraform and Ansible deployment paths in the repository. What distinguishes it from a simple script is the orchestrator pattern: rather than implementing discovery logic itself, it chains dozens of best-in-class community tools — subfinder, nuclei, httpx, dnsx, puredns, and many more — into a single configurable pipeline. The philosophy is that an operator should spend time analyzing findings, not wiring glue between utilities.
The README organizes capabilities into clear phases: OSINT, Subdomains, Hosts, Web Analysis, Vulnerability Checks, and Extras. The OSINT module is unusually deep for a recon framework. It runs WHOIS lookups via whois, hunts leaked emails and credentials with emailfinder and LeakSearch, maps Microsoft 365 and Azure tenants through msftrecon, and extracts metadata from indexed office documents using metagoofil. API leak detection is handled by porch-pirate, SwaggerSpy, and the author's own postleaksNG, while automated Google dorking runs through dorks_hunter and xnldorker. There is even a mail hygiene check that reviews SPF and DMARC posture to flag spoofing and deliverability problems — a control that is just as useful to defenders hardening their own domain as to attackers profiling it.
The GitHub analysis module deserves its own mention because it signals where the project is heading. Beyond enumerating repositories in a target organization with enumerepo, it offers a selectable choice of secret-scanning engines: trufflehog, gitleaks, titus, and noseyparker. An optional audit with gato extends coverage into GitHub Actions workflow artifacts and CI/CD exposure, which is a modern and frequently overlooked attack surface. Third-party service misconfigurations are mapped with misconfig-mapper, and cloud storage exposure is enumerated through cloud_enum — the README notes that this replaced the older CloudHunter, dropping Alibaba OSS coverage and migrating bucket output to subdomains/cloud_enum_buckets_trufflehog.txt, a change worth knowing if you maintain downstream parsing of old artifact names.
Subdomain enumeration is the framework's core, and the README documents a layered methodology that mirrors current industry practice. Passive discovery flows through subfinder, github-subdomains, and certificate transparency queries via crt. The more interesting techniques include NOERROR-based discovery with dnsx — leveraging DNS responses that resolve without valid records to infer hidden hostnames — permutation generation with Gotator augmented by regulator and subwiz, and relationship discovery through AnalyticsRelationships, which correlates Google Analytics IDs across unrelated-looking hosts. TLS handshake discovery via tlsx and CSP header scraping via csprecon round out techniques that most homegrown scripts miss entirely.
Active discovery is present but separated deliberately. puredns handles DNS bruteforcing with customizable wordlists, recursive enumeration is driven by dsieve, and reverse IP lookups run through hakip2host. Subdomain takeover checks combine nuclei takeover templates with dnstake, and classic DNS zone transfer misconfigurations are tested with dig. The framework also resolves and categorizes hosts — retrieving ipinfo geolocation, distinguishing CDN-fronted IPs with cdncheck, and performing WAF detection so downstream scanners can adjust expectations. This staging matters operationally: passive phases are nearly silent from the target's perspective, while active phases announce themselves loudly, so an operator can split runs by authorization scope.
The Vulnerability Checks section covers the expected web classes — XSS, SSRF, SQLi, LFI, SSTI — plus directory fuzzing, port scanning, and automated screenshotting for quick visual triage. The README does not oversell these as exploitation capabilities; they are detection-oriented checks that produce leads for manual validation. Integration with Faraday provides structured reporting and visualization, which is a pragmatic touch for consultants who need to hand clients something more digestible than a directory of text files. The project also advertises AI integration, and its data-management section covers output organization, including a Makefile workflow for handling results.
Two architectural features elevate reconftw above single-box scripts. The first is distributed scanning via the AX Framework (the successor to Axiom), which fans the workload across cloud instances so large-scope programs finish in hours instead of days. The second is a v2 beta written in Go, which the README surfaces as an opt-in track — a rewrite that should eventually address the fragility inherent in bash orchestration of dozens of external dependencies. For now, the Go and Python badges on the repo reflect the underlying tools it invokes rather than the framework's own language, and the GitHub Actions integration signals CI testing of the installer, which is reassuring given how dependency-heavy this design is.
Configuration is centralized in a detailed configuration file where nearly every phase can be toggled, tuned, or pointed at custom wordlists. Target options support single domains, lists, and CIDR-style scopes, while mode options let you select between recon-only, subdomain-focused, or full vulnerability-inclusive runs. This granularity is what makes the tool defensible in a professional context: you can constrain execution to exactly what the rules of engagement permit, and disable anything that would exceed authorized scope.
Installation is straightforward for a tool of this complexity, with an installer script handling the long dependency chain, and a Docker image available as the isolation-friendly alternative: git clone https://github.com/six2dez/reconftw followed by the documented installer, or docker pull six2dez/reconftw for containerized use. The README also documents Terraform plus Ansible deployment for teams standing up distributed scanning infrastructure repeatably.
The telemetry footprint is significant and defenders should understand it. Active phases produce high-rate DNS resolution, bruteforce queries against many nonexistent hostnames, WAF-visible probing from nuclei, and screenshotting traffic — all of which correlate cleanly in SIEM pipelines tuned for reconnaissance detection. From a defensive perspective, running reconftw against your own estate is one of the better ways to enumerate what your external attack surface actually leaks before someone with worse intentions does it for you. The README's disclaimer is explicit and worth repeating: using reconftw against targets without prior consent is illegal, and responsible use is the operator's obligation.
six2dez/reconftw.Educational analysis for authorized security professionals. Use only in controlled, authorized environments.
Related coverage
0 comentários:
Post a Comment
Note: Only a member of this blog may post a comment.