awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com

Recon automation framework

Ranking updated Sep 6, 2026

For a recon automation framework, the first results are yogeshojha/rengine (rEngine is a comprehensive reconnaissance automation framework and vulnerability management platform that integrates multi-tool workflows, asset discovery, and a web interface for security assessments), blacklanternsecurity/bbot (BBOT is a containerized reconnaissance and attack surface mapping framework that automates OSINT, subdomain enumeration, and asset discovery through a recursive, modular plugin architecture, though it lacks a built-in web interface) and owasp/amass (Amass is a robust reconnaissance framework focused on attack surface mapping and subdomain enumeration, matching the core intent while offering a specialized command-line tool rather than a full multi-tool orchestration platform with a web UI). autumn-27/scopesentry and techarohq/anubis round out the shortlist. Compare the match explanations and check the project documentation against your requirements.

Compare the top open-source recon automation frameworks for bug bounties and pentesting, ranked by GitHub stars and activity to find the best fit.

Recon automation framework

Find the best repos with AI.We'll search the best matching repositories with AI.
  • yogeshojha/rengineyogeshojha avatar

    yogeshojha/rengine

    8,472View on GitHub↗

    Rengine is an automated reconnaissance framework and vulnerability management platform designed for attack surface monitoring. It functions as a centralized hub for discovering subdomains and open ports, gathering open-source intelligence, and tracking security flaws across target networks. The system integrates large language models to analyze reconnaissance data and generate vulnerability descriptions and insights. It distinguishes itself through a plugin-based tool integration that wraps external security scanning binaries and a target mapping system that tracks changes to assets over time

    rEngine is a comprehensive reconnaissance automation framework and vulnerability management platform that integrates multi-tool workflows, asset discovery, and a web interface for security assessments.

    HTMLAttack Surface ManagementAttack Surface MappingInfrastructure Reconnaissance
    View on GitHub↗8,472
  • blacklanternsecurity/bbotblacklanternsecurity avatar

    blacklanternsecurity/bbot

    9,929View on GitHub↗

    This project is an open-source intelligence reconnaissance framework and recursive attack surface mapper. It functions as a containerized security scanner designed to map public-facing infrastructure, perform subdomain enumeration, and automate the gathering of open-source intelligence. The system employs a recursive discovery engine to iteratively explore target infrastructure, utilizing a plugin-based module architecture to extend scanning capabilities. It integrates third-party APIs for data enrichment and applies YARA rules across discovered assets to identify specific vulnerability patte

    BBOT is a containerized reconnaissance and attack surface mapping framework that automates OSINT, subdomain enumeration, and asset discovery through a recursive, modular plugin architecture, though it lacks a built-in web interface.

    PythonSubdomain DiscoverySubdomain EnumerationSubdomain Enumeration Tools
    View on GitHub↗9,929
  • owasp/amassOWASP avatar

    OWASP/Amass

    14,722View on GitHub↗

    Amass is a network attack surface mapper and reconnaissance framework designed to discover and map the external, internet-facing infrastructure of a target organization. It functions as an open source intelligence tool that identifies public network boundaries and locates hidden or forgotten subdomains to define an organization's total reachable footprint. The project utilizes passive-source data aggregation from external APIs and public databases alongside active DNS brute-forcing and recursive subdomain expansion. It employs a graph-based asset mapping system to visualize the relationships

    Amass is a robust reconnaissance framework focused on attack surface mapping and subdomain enumeration, matching the core intent while offering a specialized command-line tool rather than a full multi-tool orchestration platform with a web UI.

    GoAsset Discovery ToolsSubdomain EnumerationSubdomain Enumeration
    View on GitHub↗14,722
  • autumn-27/scopesentryAutumn-27 avatar

    Autumn-27/ScopeSentry

    1,519View on GitHub↗

    ScopeSentry is a distributed attack surface management platform designed to catalog digital assets and automate security assessments across large network environments. It functions as a network asset discovery tool and vulnerability scanner, providing a framework for maintaining visibility over organizational infrastructure. The platform distinguishes itself through a distributed architecture that orchestrates worker nodes to execute security tasks in parallel. It utilizes an event-driven discovery process to identify new assets and subdomains, maintaining a stateful record of configurations

    ScopeSentry is a distributed security platform that automates asset discovery, subdomain enumeration, and vulnerability scanning, matching the core requirements for a reconnaissance framework even though its specific interface capabilities are distributed rather than unified.

    GoAsset Discovery ToolsSubdomain Enumeration ToolsAttack Surface Management
    View on GitHub↗1,519
  • techarohq/anubisTecharoHQ avatar

    TecharoHQ/anubis

    17,067View on GitHub↗

    Anubis is a command-line security reconnaissance framework designed for subdomain enumeration and attack surface mapping. It functions as a utility for security professionals to identify, catalog, and visualize the external digital footprint of an organization by discovering all subdomains associated with a target domain. The tool distinguishes itself through a modular resolver pipeline that integrates passive reconnaissance from third-party security APIs and public certificate transparency logs. It combines this data with active discovery methods, including recursive DNS brute-forcing and al

    Anubis is a command-line security reconnaissance framework focused on subdomain enumeration and attack surface mapping, though it lacks some broader features like built-in vulnerability scanning and a web interface.

    GoSubdomain Enumeration ToolsAttack Surface ManagementInfrastructure Reconnaissance
    View on GitHub↗17,067
  • guelfoweb/knockguelfoweb avatar

    guelfoweb/knock

    4,163View on GitHub↗

    Knock is an attack surface management tool and DNS reconnaissance framework used for discovering and mapping an organization's external infrastructure. It functions as a subdomain enumeration tool and HTTP security scanner to identify reachable hosts and organizational assets. The project distinguishes itself by using a passive-active hybrid enumeration strategy, combining external API lookups with active wordlist brute-force attacks and DNS zone transfers. It includes a multi-stage validation pipeline that detects DNS wildcard records and verifies host connectivity to filter out false positi

    Knock is a targeted reconnaissance framework focused on subdomain enumeration and attack surface mapping, though it lacks the broad multi-tool integration and full workflow automation of a comprehensive platform.

    PythonSubdomain EnumerationSubdomain EnumerationSubdomain Enumeration Tools
    View on GitHub↗4,163
  • owasp-amass/amassowasp-amass avatar

    owasp-amass/amass

    14,155View on GitHub↗

    Amass is an attack surface management tool designed to identify, map, and inventory an organization's internet-facing digital assets. It functions as a security asset discovery engine that systematically expands an organization's known infrastructure footprint through recursive domain name resolution and the collection of intelligence from diverse public data sources. The platform distinguishes itself by utilizing a graph-based modeling approach to organize discovered resources. By maintaining a persistent graph database, it tracks the relationships between infrastructure components and norma

    Amass is a powerful reconnaissance and asset discovery engine focused on subdomain enumeration and attack surface mapping, though it operates primarily as a command-line tool rather than an end-to-end framework with its own built-in web interface and vulnerability scanner.

    GoAsset Discovery ToolsSubdomain DiscoveryAttack Surface Management
    View on GitHub↗14,155
  • owasp/nettackerOWASP avatar

    OWASP/Nettacker

    5,258View on GitHub↗

    Nettacker is an automated penetration testing framework designed to orchestrate reconnaissance, port scanning, and vulnerability detection. It functions as a network reconnaissance tool and vulnerability scanner that identifies open ports, fingerprints services, and checks systems against databases of known security flaws. The framework distinguishes itself by combining a web application crawler for discovering hidden paths via fuzzing with a vulnerability management system that persists scan results in a database to track historical assessments. It also includes specialized capabilities for

    Nettacker is an automated penetration testing framework that orchestrates reconnaissance, vulnerability scanning, and asset discovery, directly fulfilling the requirements for security assessment automation.

    PythonSubdomain Enumeration ToolsAttack Surface MappingVulnerability Scanners
    View on GitHub↗5,258
  • smicallef/spiderfootsmicallef avatar

    smicallef/spiderfoot

    18,189View on GitHub↗

    SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the collection and correlation of data for security investigations. It functions as a comprehensive platform that automates the querying of hundreds of public data sources to map digital footprints, identify exposed assets, and uncover potential security threats across an organization's external perimeter. The platform distinguishes itself through a modular, plugin-based architecture that executes data gathering tasks in parallel, supported by a directed graph data model that tracks relati

    SpiderFoot is an open-source reconnaissance and intelligence automation framework that integrates numerous modules for asset discovery, OSINT, and threat data collection through both web and command-line interfaces.

    PythonAsset Discovery ToolsAttack Surface Management
    View on GitHub↗18,189
  • laramies/theharvesterlaramies avatar

    laramies/theHarvester

    15,687View on GitHub↗

    theHarvester is a command-line utility designed for gathering open-source intelligence and mapping an organization's external attack surface. It functions as a security information gathering framework that automates the collection of publicly available data to assist in reconnaissance and threat analysis. The tool utilizes a plugin-based architecture to execute isolated queries against various search engines and public databases. It employs asynchronous task execution to run multiple discovery operations in parallel, while a centralized pipeline aggregates and deduplicates findings from these

    This tool is a reconnaissance and information gathering framework with a plugin-based architecture for subdomain enumeration and public data collection, fitting the search well despite lacking a built-in web interface.

    PythonOSINT and ReconSubdomain EnumerationSubdomain Enumeration Tools
    View on GitHub↗15,687
  • aboul3la/sublist3raboul3la avatar

    aboul3la/Sublist3r

    10,957View on GitHub↗

    Sublist3r is a subdomain enumeration tool and passive reconnaissance framework designed to discover subdomains by querying search engines and public intelligence sources. It functions as a security tool for identifying the digital footprint of a target domain. The project provides both passive enumeration through multi-source API aggregation and active discovery via a DNS brute force tool. It includes a TCP port scanner to identify active services and open ports on discovered subdomains, facilitating attack surface mapping. The tool can be used as a standalone utility or as a Python security

    Sublist3r is a targeted reconnaissance tool focused on subdomain enumeration and passive discovery rather than a broad workflow automation framework, but it provides key information-gathering and port scanning capabilities for security assessments.

    PythonSubdomain EnumerationSubdomain EnumerationSubdomain Enumeration Tools
    View on GitHub↗10,957
  • usestrix/strixusestrix avatar

    usestrix/strix

    20,138View on GitHub↗

    Strix is an automated security research and vulnerability scanning platform that leverages language models to orchestrate complex security analysis tasks. It functions as a comprehensive framework for penetration testing and continuous security integration, allowing users to embed automated vulnerability research directly into development pipelines or execute it within isolated, containerized environments. The platform distinguishes itself through a multi-agent orchestration engine that coordinates specialized autonomous agents to perform parallel security assessments. By integrating LLM-agno

    Strix is an automated security research and vulnerability scanning platform featuring multi-agent orchestration, asset discovery, and penetration testing capabilities that fit the reconnaissance automation framework category.

    PythonAttack Surface ManagementInfrastructure ReconnaissanceVulnerability Scanners
    View on GitHub↗20,138
  • 1n3/sn1per1N3 avatar

    1N3/Sn1per

    10,049View on GitHub↗

    Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets. The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan

    Sn1per is an automated penetration testing and reconnaissance framework that integrates multiple security tools into unified pipelines for asset discovery and vulnerability scanning, though it lacks a full native web interface out of the box.

    ShellSubdomain DiscoverySubdomain Enumeration ToolsAttack Surface Management
    View on GitHub↗10,049
  • tuhinshubhra/red_hawkTuhinshubhra avatar

    Tuhinshubhra/RED_HAWK

    3,695View on GitHub↗

    RED_HAWK is a penetration testing framework and reconnaissance suite designed for information gathering and vulnerability assessment. It provides a toolkit for infrastructure reconnaissance, technology stack detection, automated web spidering, and security scanning. The project distinguishes itself through a multi-stage reconnaissance pipeline that maps attack surfaces. This includes DNS-based infrastructure mapping to resolve network layouts and pattern-based detection to identify specific content management systems and server stacks. The system covers a broad range of capabilities includin

    RED_HAWK is an open-source reconnaissance and vulnerability assessment framework that automates information gathering and web scanning tasks, matching the core intent while lacking a dedicated web interface and extensive plugin architecture.

    PHPSubdomain DiscoveriesAttack Surface MappingInfrastructure Reconnaissance
    View on GitHub↗3,695
  • jasonxtn/argusjasonxtn avatar

    jasonxtn/Argus

    3,254View on GitHub↗

    Argus is a modular network reconnaissance framework designed for gathering network intelligence, mapping infrastructure, and assessing security postures through automated discovery tasks. It operates as a containerized security toolset that allows for the consistent execution of specialized information-gathering modules across different operating systems. The system functions as an infrastructure audit tool and a web application security scanner, performing tasks such as DNS lookups, port scanning, and the inspection of HTTP headers to detect vulnerabilities. It also serves as a threat intell

    Argus is a modular network reconnaissance framework that automates information gathering and infrastructure mapping, though it lacks a documented web interface alongside its CLI.

    PythonInfrastructure Reconnaissance
    View on GitHub↗3,254
  • six2dez/reconftwsix2dez avatar

    six2dez/reconftw

    7,226View on GitHub↗

    reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio

    Reconftw is a modular reconnaissance workflow orchestrator that coordinates multi-tool pipelines for asset discovery and vulnerability scanning, though it lacks a built-in web interface.

    ShellSubdomain Enumeration ToolsAttack Surface ManagementAttack Surface Mapping
    View on GitHub↗7,226
  • projectdiscovery/nucleiprojectdiscovery avatar

    projectdiscovery/nuclei

    29,189View on GitHub↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Nuclei is a template-driven security scanning framework that automates infrastructure reconnaissance and vulnerability detection through an extensible engine, though it focuses more on executing modular checks than orchestrating a broader multi-tool reconnaissance workflow.

    GoAsset Discovery ToolsSubdomain Enumeration ToolsAttack Surface Management
    View on GitHub↗29,189
  • reconurge/flowsintreconurge avatar

    reconurge/flowsint

    6,979View on GitHub↗

    Flowsint is an open-source intelligence framework and reconnaissance orchestrator used for cybersecurity investigations. It functions as a containerized tool runner and data mapper, automating the collection of intelligence from open-source providers and APIs to profile targets and map threat intelligence. The platform distinguishes itself through a graph-based investigation interface, where processed raw intelligence is converted into nodes and edges to visualize relationships between entities. It allows for the creation of sequenced pipelines that chain data enrichment tools, enabling the o

    Flowsint is an open-source reconnaissance orchestrator and OSINT framework that automates information gathering and chains tool pipelines, making it well-suited for security assessments though it lacks built-in vulnerability scanning.

    TypeScriptOSINT Automation FrameworksReconnaissance Workflow OrchestratorsExternal Intelligence Integrators
    View on GitHub↗6,979
  • projectdiscovery/subfinderprojectdiscovery avatar

    projectdiscovery/subfinder

    13,105View on GitHub↗

    Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It functions as a discovery engine that identifies and maps internet-exposed infrastructure, cloud-hosted assets, and network ranges to maintain a comprehensive inventory of an organization's digital footprint. The project distinguishes itself through a modular, template-driven scanning engine that executes security checks against discovered assets. It leverages cloud-native asset discovery to query provider APIs and infrastructure metadata, while supporting distributed agent orc

    Subfinder is a security reconnaissance framework focused on subdomain enumeration and attack surface discovery, fitting the domain well even though it is narrower than a full multi-tool orchestration platform.

    GoAsset Discovery ToolsSubdomain EnumerationSubdomain Enumeration Tools
    View on GitHub↗13,105
  • rapid7/metasploit-frameworkrapid7 avatar

    rapid7/metasploit-framework

    38,415View on GitHub↗

    The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of security exploits. It serves as a research toolkit and automated assessment environment, enabling security professionals to identify and validate vulnerabilities within networked systems and infrastructure through repeatable, standardized procedures. The platform distinguishes itself through a modular architecture that supports reflective payload injection, allowing for the execution of code directly in memory without writing to disk. It utilizes an asynchronous event loop to

    Rapid7 Metasploit Framework is a well-known penetration testing platform featuring modular architecture, vulnerability scanning, and multi-tool integration, though its primary focus is exploit development rather than dedicated reconnaissance workflow automation.

    RubyVulnerability Assessment Tools
    View on GitHub↗38,415
  • greydgl/pentestgptGreyDGL avatar

    GreyDGL/PentestGPT

    11,697View on GitHub↗

    PentestGPT is an autonomous security testing framework that leverages large language models to plan, execute, and coordinate end-to-end penetration testing engagements. By functioning as an autonomous agent, the system automates the entire testing lifecycle, from initial reconnaissance and vulnerability analysis to the generation of custom exploits and the execution of post-exploitation tasks. The platform distinguishes itself through a multi-agent orchestration system that coordinates specialized AI agents to collaborate on complex, multi-stage attack chains. It integrates multimodal context

    PentestGPT is an autonomous security testing framework driven by large language models that handles reconnaissance alongside vulnerability scanning and exploitation, though it approaches automation through AI agents rather than traditional workflow scripting.

    PythonInfrastructure ReconnaissanceVulnerability Scanners
    View on GitHub↗11,697
  • lanmaster53/recon-nglanmaster53 avatar

    lanmaster53/recon-ng

    5,698View on GitHub↗

    recon-ng is an open source intelligence reconnaissance framework designed to automate the collection and aggregation of public information. It is a modular intelligence tool that utilizes a system of pluggable modules to harvest target data, resolve DNS queries, and parse web content. The framework is built as an API-driven tool with a programmatic interface to integrate with other security workflows. It is provided as a containerized application, using Docker to ensure a consistent environment for running reconnaissance tasks and managing a persistent data store. Its capabilities cover exte

    Recon-ng is an open-source reconnaissance framework designed to automate open-source intelligence collection and asset discovery through a modular architecture, though it lacks an out-of-the-box web interface and vulnerability scanning suite.

    PythonAttack Surface Mapping
    View on GitHub↗5,698
  • prowler-cloud/prowlerprowler-cloud avatar

    prowler-cloud/prowler

    13,049View on GitHub↗

    Prowler is an automated cloud infrastructure security scanner and posture management tool. It evaluates cloud environments and infrastructure-as-code templates against security benchmarks to identify misconfigurations, vulnerabilities, and compliance gaps that could compromise system integrity. The platform distinguishes itself through graph-based attack path analysis, which identifies chains of misconfigurations that create exploitable routes for unauthorized access. It utilizes a plugin-based execution model to perform state-based assessments of live environments and static analysis of conf

    Prowler is an automated cloud infrastructure security scanner and posture management tool that handles asset discovery, vulnerability scanning, and compliance audits, though it is specifically focused on cloud environments rather than general-purpose network reconnaissance workflows.

    PythonCloud Auditing ToolsCloud Security ToolsInfrastructure Security Scanners
    View on GitHub↗13,049
  • moham3driahi/th3inspectorMoham3dRiahi avatar

    Moham3dRiahi/Th3inspector

    2,571View on GitHub↗

    Th3inspector is a command-line open-source intelligence reconnaissance tool used for gathering public information on websites, phone numbers, and network records. It functions as a central interface for collecting technical metadata and performing various lookups to build profiles of target entities. The project provides specialized verification utilities for validating email addresses, phone numbers, and credit card bank identification numbers. It also includes tools for retrieving domain registration age, ownership records, and identified subdomains from global databases. Additional capabi

    Th3inspector is an information-gathering command-line tool that aggregates various lookups and target profiling utilities, fitting the reconnaissance framework category well despite lacking a web interface.

    PerlOSINT ToolsWebsite Analysis and ReconnaissanceGeographic IP Lookups
    View on GitHub↗2,571
Compare the top 10 at a glance
RepositoryStarsLanguageLicenseLast push
yogeshojha/rengine8.5KHTMLgpl-3.0Nov 16, 2025
blacklanternsecurity/bbot9.9KPythonAGPL-3.0Jun 17, 2026
owasp/amass
14.7K
Go
NOASSERTION
Apr 17, 2026
autumn-27/scopesentry1.5KGo—Jun 12, 2026
techarohq/anubis17.1KGomitFeb 19, 2026
guelfoweb/knock4.2KPythonGPL-3.0Feb 19, 2026
owasp-amass/amass14.2KGootherFeb 22, 2026
owasp/nettacker5.3KPythonApache-2.0Jun 19, 2026
smicallef/spiderfoot18.2KPythonMITApr 13, 2026
laramies/theharvester15.7KPython—Feb 20, 2026

Related searches

  • a recon automation framework
  • Reconnaissance and OSINT
  • a tool for performing dns reconnaissance
  • an osint toolkit for reconnaissance and enumeration
  • an open source penetration testing framework
  • a C2 framework for red teams
  • a penetration testing framework for security auditing
  • a tool for subdomain enumeration and reconnaissance