Recon-ng


Recon-ng is a tool that is focused on performing web-based reconnaissance.

  • has a syntax and use that parallels Metasploit Framework
  • uses workspaces to help organize information
  • functionality can be greatly expanded through the use of numerous add-on modules
  • can speed the collection of host and domain information
    • quickly revealing an organization’s external footprint to an attacker:
      • IP addresses
      • subdomains
      • software versions
      • and many other attributes
  • can be used by analysts to review and monitor an organization’s footprint to ensure it complies with policy and other security mandates