Skip to content

Recon-ng

Full-featured reconnaissance framework with modules for DNS, WHOIS, subdomains, and social media intelligence.

Self-hostedNot yet verified
Report issue
GPL-3.0★ 3100Source project only — not browser-runnable

External Tool

This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.

Browse network tools →

What's next with Recon-ng?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is Recon-ng?

Recon-ng is an open-source intelligence (OSINT) gathering framework designed to streamline the process of collecting information from public sources on the internet. Its primary purpose is to automate and accelerate web-based reconnaissance tasks, such as identifying subdomains, harvesting email addresses, and analyzing social media profiles. This tool is widely used by cybersecurity professionals, penetration testers, and digital forensics experts who need to gather actionable intelligence quickly. Recon-ng addresses the challenge of manually sifting through vast amounts of online data by providing a structured, modular environment that reduces repetitive tasks and enhances efficiency. The framework is built with a user interface reminiscent of the Metasploit Framework, making it accessible to users familiar with penetration testing tools. However, Recon-ng is specifically tailored for open-source reconnaissance, focusing on web-based data collection rather than exploitation or social engineering. It integrates various modules and plugins to handle tasks like WHOIS lookups, search engine scraping, and network mapping. By centralizing these functions, Recon-ng enables users to compile comprehensive threat intelligence or investigate digital footprints without switching between multiple tools.

How it works

Recon-ng is a reconnaissance framework that automates the collection of information from public sources, such as websites, social media, and search engines. It is designed to reduce the time required for manual data gathering by organizing tasks into modular components. The tool is ideal for security professionals conducting threat intelligence operations, vulnerability research, or competitive analysis. It provides a structured environment to execute reconnaissance workflows, ensuring consistency and scalability in data collection. Recon-ng supports modules for subdomain enumeration, email harvesting, and social media profile analysis. For example, it can use search engine queries to identify hidden subdomains or scrape LinkedIn for professional contact details. It also includes plugins for WHOIS lookups and network mapping, enabling users to build a comprehensive view of a target's digital footprint.

How to use it

  1. 1Install Recon-ng via Docker or clone the repository from GitHub. 2. Load modules using the 'use' command, such as 'use recon/domains-enum' for subdomain discovery. 3. Configure module parameters, like target domains or search terms. 4. Execute modules with the 'run' command and export results to CSV or JSON files. Practical tips include using Docker for simplified setup and prioritizing modules with active dependencies. Always verify data accuracy by cross-referencing results with multiple sources.

What it can do

  • web reconnaissance framework

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/lanmaster53/recon-ng
  • license: GPL-3.0 — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Dual-use tool — use only with explicit authorization on systems you own or have permission to test.
  • Relies on publicly available data, which may lack depth or timeliness
  • Requires manual verification of collected information for accuracy
  • Limited support for real-time data updates from dynamic sources
  • Lacks built-in tools for data visualization or analysis

Understanding the result

Full-featured reconnaissance framework with modules for DNS, WHOIS, subdomains, and social media intelligence.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (GPL-3.0).
Built with
(lanmaster53/recon-ng)
License
GPL-3.0
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with lanmaster53/recon-ng. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
GPL-3.0
View source on GitHub

Open-source project

License: GPL-3.0Source: this project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is Recon-ng used for?

Recon-ng is used for automating open-source intelligence gathering tasks such as subdomain discovery, email harvesting, and social media profile analysis. It helps security professionals collect structured data from public sources to support threat intelligence operations, penetration testing, and competitive analysis.

How does Recon-ng work technically?

Recon-ng operates through a modular architecture where users load and execute plugins that perform specific reconnaissance tasks. Each module interacts with external APIs, search engines, or databases to retrieve data. Results are stored in a database or exported to files, allowing users to analyze findings systematically. The framework's design enables extensibility, with new modules added via plugin development.

How do I find subdomains using Recon-ng?

To find subdomains, first install the 'recon/domains-enum' module. Use the 'use' command to load the module, then configure parameters like the target domain. Run the module with 'run' to execute the subdomain enumeration. Export results to a CSV file for further analysis. For example: 'use recon/domains-enum; set domain=example.com; run; export csv'

How does Recon-ng compare to Metasploit?

Recon-ng is specifically designed for open-source reconnaissance, while Metasploit focuses on exploitation and penetration testing. Recon-ng provides tools for data collection from public sources, whereas Metasploit includes payloads and exploit modules for interacting with targets. Both tools are complementary, with Recon-ng often used in the reconnaissance phase before Metasploit's exploitation modules are applied.

How do I troubleshoot module dependency errors?

If a module fails due to missing dependencies, check the module's documentation for required libraries or APIs. For example, some modules require Python packages like 'requests' or 'beautifulsoup4'. Install missing dependencies using pip or the system's package manager. Verify that all required plugins are enabled in the Recon-ng configuration file.

Spotted something wrong with Recon-ng, or want to maintain it? See how to help.