A program-aware, highly concurrent reconnaissance pipeline for authorized security testing and bug bounty programs.
This project automates the reconnaissance lifecycle for multiple bug bounty programs, prioritizing performance and isolation. It uses an asynchronous, multi-threaded architecture with two primary pipelines: a Web Pipeline and an ASN Pipeline. All collected data is persisted into an isolated SQLite database, eliminating duplicate scans and enabling historical tracking.
The main scanner (recon.py) discovers assets, fingerprints them, port scans, runs vulnerability checks, and performs deep regex scanning for secrets. The companion exporter (export.py) generates rich, interactive HTML reports and JSON exports.
- Multi-Pipeline Architecture: Independent threaded pipelines for Web and ASN tasks.
- Concurrent Execution: Parallel execution of Nuclei and Regex Scanning.
- Multi-Program Support: Maintains isolated state for each program.
- SQLite State Management: Non-blocking database writes via a dedicated DB thread.
- Web Recon: Subdomain discovery (Subfinder), active probing (HTTPX), and web crawling (Katana).
- ASN & Infrastructure: ASN enumeration (ASNMap), CIDR parsing (MapCIDR), and fast port scanning (Naabu).
- Vulnerability & Secret Scanning: Nuclei for templates, custom Regex Scanner for JS and HTML secret monitoring.
- Historical Tracking: Schema migrations and lifecycle tracking for discovered assets.
- Reporting: Advanced HTML dashboard and JSON export via
export.py.
The pipeline uses a threaded orchestrator that spawns separate workflows for Web and ASN tasks, ensuring they do not block each other. Database writes are handled by a thread-safe DbWriter.
flowchart TD
A[Scope & Targets] --> O[Orchestrator]
subgraph Web Pipeline
O --> W1[Subfinder]
W1 --> W2[New Subdomains]
W2 --> W3[HTTPX]
W3 --> W4[Katana Crawling]
W4 --> W5[Parallel Execution]
W5 --> W6[Nuclei]
W5 --> W7[Regex Scanner]
end
subgraph ASN Pipeline
O --> A1[ASNMap]
A1 --> A2[MapCIDR]
A2 --> A3[Naabu Port Scan]
A3 --> A4[HTTPX on Alive Ports]
end
W6 --> DB[(SQLite DB)]
W7 --> DB
A4 --> DB
DB --> EX[export.py]
EX --> H[Interactive HTML]
EX --> J[JSON Export]
- Python 3.11+
- Linux environment (or WSL/Windows)
- Go (for ProjectDiscovery tools)
- SQLite3
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txtgo install github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest
go install github.com/projectdiscovery/httpx/cmd/httpx@latest
go install github.com/projectdiscovery/naabu/v2/cmd/naabu@latest
go install github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
go install github.com/projectdiscovery/katana/cmd/katana@latest
go install github.com/projectdiscovery/asnmap/cmd/asnmap@latest
go install github.com/projectdiscovery/mapcidr/cmd/mapcidr@latest
go install github.com/projectdiscovery/notify/cmd/notify@latestroot/
├── recon.py # Main CLI entry point
├── export.py # HTML/JSON report generator
├── requirements.txt # Python dependencies
├── .env # Configuration file
├── targets/ # Folder for scope lists (*.txt)
├── logs/ # Application logs
├── work/ # Temporary working directories for tools
├── reports/ # Generated HTML/JSON outputs
├── recon/ # Core pipeline package
│ ├── config.py # Env validation and config loading
│ ├── database.py # SQLite schemas and queries
│ ├── pipeline/ # Pipeline orchestration (web, asn, orchestrator)
│ └── tools/ # Python wrappers for external CLI tools
└── recon.db # Central SQLite database
Create a .env file beside recon.py based on .env.example. Ensure all required binaries are in your PATH or configured correctly.
Important variables include:
ROOT_DIR: Base directory for logs, work, and databases.SUBFINDER_BIN,HTTPX_BIN,NAABU_BIN,NUCLEI_BIN,KATANA_BIN,ASNMAP_BIN,MAPCIDR_BIN,NOTIFY_BINKATANA_DEPTH: Depth for crawling (default: 3)REGEX_SCANNER_THREADS: Thread pool size for fast async regex scanning- Skip Flags:
SUBFINDER_SKIP,HTTPX_SKIP,KATANA_SKIP,NUCLEI_SKIP,ASN_PIPELINE_SKIP,REGEX_SCANNER_JS_SKIP,REGEX_SCANNER_HTML_SKIP
To scan all targets found in the targets/ folder:
python3 recon.pyThe core focus of this tool is continuous asset monitoring. It is designed to be run on a recurring schedule to catch new subdomains, ports, vulnerabilities, and leaked secrets.
To run the scanner automatically every day at midnight:
# Edit the crontab
crontab -e
# Add the following line (update paths as needed)
0 0 * * * cd /path/to/bugBounty-auto-recon && /path/to/bugBounty-auto-recon/.venv/bin/python recon.py >> logs/cron.log 2>&1For better log management and process control, a systemd service/timer is highly recommended:
- Create
/etc/systemd/system/recon.service:[Unit] Description=Bug Bounty Auto Recon Scanner [Service] Type=oneshot WorkingDirectory=/path/to/bugBounty-auto-recon ExecStart=/path/to/bugBounty-auto-recon/.venv/bin/python recon.py User=your_user
- Create
/etc/systemd/system/recon.timer:[Unit] Description=Run Recon Scanner Daily [Timer] OnCalendar=*-*-* 00:00:00 Persistent=true [Install] WantedBy=timers.target
- Enable and start the timer:
sudo systemctl enable --now recon.timer
If running on Windows:
- Open Task Scheduler and click Create Basic Task.
- Name it "Bug Bounty Recon" and set the trigger to Daily.
- Action: Start a program.
- Program/script:
C:\path\to\bugBounty-auto-recon\.venv\Scripts\python.exe - Add arguments:
recon.py - Start in:
C:\path\to\bugBounty-auto-recon
Export an interactive HTML report for a specific program:
python3 export.py --db recon.db --program "company_name"Export HTML and JSON for all tracked programs:
python3 export.py --db recon.db --all-programsPrimary tables managed by recon/database.py:
- Scope:
programs,scope_domains - Web:
subdomains,httpx_results,katana_results - Vulnerabilities & Secrets:
nuclei_findings,javascript_monitor_files,regex_scanner_findings,regex_scanner_history - Infrastructure:
asn_ranges,asn_ips,ports,asn_httpx_results - System:
runs,schema_version
- Resource Limits: Adjust timeout and threading configurations in
.envbased on your VPS/machine limits. - Authorization: Use only on authorized targets and bug bounty programs.
- Templates: Run
nuclei -update-templatesregularly to ensure coverage against the latest CVEs. - Data Pruning: Use
MAX_JOB_RETENTION_DAYSin.envto prevent thework/directory from exhausting disk space.
Use only for authorized security assessments and bug bounty programs.