โโโโโโโ โโโโโโโโ โโโโโโโ โโโโโโโ โโโโ โโโโโโโโโโ โโโโโโโโโโโ โโโโโโโโโโ โโโ โโโโโโโ โโโโโโโโโโโโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโ โโโ โโโ โโโโโโโโโ โโโ โโโโโโโโโโโโโ โโโโโโ โโโโโโโโโโโ โโโ โโโโโโ โโโ
โโโโโโโโโโโโโโ โโโ โโโ โโโโโโโโโโโโโโโโโโโโ โโโโโโ โโโโโโ โโโโโโโ โโโ โโโ โโโโโโ โโโ
โโโ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโ โโโโโโโโโโโโโโโโโโโโ โโโ
โโโ โโโโโโโโโโโ โโโโโโโ โโโโโโโ โโโ โโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโ โโโโโโโโ โโโโโโโ โโโ โโโ
Automated Passive Reconnaissance โข Live CIRCL CVE Database Fusion โข Executive PDF & Interactive HTML Reports
- Executive Overview
- Key Features Matrix
- System Architecture
- Installation & Setup
- Usage & Execution
- Output Telemetry & Reports
- Executive PDF & Interactive HTML Dashboard
- Remediation Framework
- Legal Disclaimer & Ethics
- License
RECON2EXPLOIT is an enterprise-grade, cross-platform threat intelligence and security audit framework. Engineered for CISOs, SOC analysts, and security researchers, it aggregates passive intelligence from DNS records, WHOIS domain data, SSL/TLS certificates, multi-threaded port scans, HTTP security headers, and brand spoofing heuristics.
The framework correlates telemetry in real-time with official CIRCL CVE REST APIs to identify active vulnerability vectors, passing all data through a Multi-Factor Threat Risk Fusion Engine. Results are exported simultaneously as structured JSON telemetry, a Dark-Themed Executive PDF Report, and a Futuristic Interactive HTML Dashboard.
| Module | Core Functionality | Primary Metrics / Outputs |
|---|---|---|
| ๐ท๏ธ Real-Time CVE/CWE Intelligence | Live REST API integration (CIRCL CVE threat engine) querying active service banners and versions dynamically | Real-time CVE identifiers, CVSS v3 ratings, official vulnerability summaries, and remediation guides |
| โก Multi-Threaded Port Scanner | High-performance TCP socket scanner checking key service ports (80, 443, 22, 21, 25, 3389, 3306, etc.) |
Open service ports, protocols, socket banners, exposure alerts |
| ๐ SSL/TLS Security Auditor | Cryptographic certificate inspection, issuer validation, and expiration countdown | Expiration status, days remaining, CA Issuer, TLS version, Subject Alternative Names (SANs) |
| ๐ DNS & Mail Security | Queries A, AAAA, MX, NS, TXT, and _dmarc SPF/DMARC records |
Mail server configuration, IP resolution, email spoofing risk indicators |
| ๐ WHOIS Intelligence | Registrar identification, ICANN EPP status parsing, abuse contacts, creation dates | Domain age (years/days), domain lifecycle phase, registrar details |
| ๐ก๏ธ Web Security Audit | Web server header inspections (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy) |
Missing security headers, clickjacking vulnerability vector, banner disclosures |
| ๐ Web Link & Form Scraper | DOM structure parsing harvesting endpoints, input forms, and password fields | External links, exposed login interfaces over unencrypted HTTP |
| ๐ฏ Phishing Heuristics | Domain string analytics checking brand squatting, IP targets, shorteners, typosquatting | Phishing heuristic score, threat indicators, targeted brand detection |
| ๐งฎ Threat Risk Fusion Engine | Mathematical risk aggregation combining domain freshness, header gaps, and phishing indicators | Composite threat score (0-10), SOC Severity Verdict (CRITICAL, HIGH, MEDIUM, LOW) |
| ๐ป Cross-Platform Engine | 100% Pure Python implementation compliant with Windows, Linux (Kali/Ubuntu/Debian), and macOS | Universal path handling, platform-independent socket & HTTP concurrency |
| ๐ Executive PDF Generator | ReportLab dark-themed document generator with two-pass dynamic page numbering (Page X of Y) |
Dynamic scorecards, structured security tables, prioritized P1-P4 remediation checklist |
| ๐ Interactive HTML Dashboard | Single-file futuristic cyber security HTML report with live tabs, risk score gauges & print exports | Interactive dark dashboard matching executive SOC layout, filterable tables & export actions |
recon_2_exploit/
โโโ core/
โ โโโ main.py # Central orchestrator & ANSI banner execution engine
โ โโโ vuln_db.py # Real-time CIRCL CVE REST API query & CWE mapping engine
โ โโโ report_html.py # Interactive Cyber Dashboard HTML report generator
โ โโโ md_to_pdf.py # ReportLab executive PDF generator with NumberedCanvas
โ โโโ dns_enum.py # DNS record resolution & DMARC audit engine
โ โโโ port_scan.py # Multi-threaded TCP socket scanner with banner grabbing
โ โโโ ssl_audit.py # Cryptographic SSL/TLS certificate inspector
โ โโโ whois_enum.py # Domain WHOIS parser & age calculator
โ โโโ web_enum.py # HTTP header & web server security auditor
โ โโโ parser.py # BeautifulSoup DOM link & form interface parser
โ โโโ phishing_runner.py # Brand impersonation & URL heuristic analyzer
โ โโโ risk_fusion.py # Multi-factor threat risk fusion scoring engine
โโโ reports/ # Auto-generated per-domain target audit workspaces
โ โโโ <target_domain>/
โ โโโ output/ # Telemetry JSON datastores (dns, ports, ssl, whois, etc.)
โ โโโ *.pdf # Standalone Executive PDF Report
โ โโโ *.html # Standalone Interactive Cyber Dashboard HTML Report
โโโ requirements.txt # Python dependency manifest
โโโ .gitignore # Configured git exclusion rules
โโโ README.md # Framework documentation
- Python 3.8+
pippackage manager
-
Clone the Repository:
git clone https://github.com/Bhuvaneshkumar1/Recon_2_Exploit.git cd Recon_2_Exploit -
Set Up Virtual Environment (Recommended):
python -m venv reconvenv # Windows PowerShell: .\reconvenv\Scripts\Activate.ps1 # Linux/macOS: source reconvenv/bin/activate
-
Install Dependencies:
pip install -r requirements.txt
Launch the interactive reconnaissance pipeline:
python -m core.main- Terminal ASCII Banner: Displays the colorized ANSI terminal header banner.
- Target Selection: Input the target domain (e.g.,
example.com). - Auto Scheme Resolution: Resolves HTTPS/HTTP protocol access automatically.
- Passive Recon & Audit: Executes DNS, WHOIS, Port Banner Scans, SSL Certificate Inspection, Web Header Matrix, and Phishing Analysis.
- Real-Time Live CVE API Query: Connects to the CIRCL CVE REST API to fetch live vulnerability IDs, CVSS scores, and summaries for detected service banners.
- Risk Fusion Computation: Merges telemetry into an overall SOC severity score.
- Report Generation: Automatically outputs
dashboard_report.htmland prompts for generatingfull_report.pdf.
All reconnaissance results are saved in reports/<domain>/:
- ๐
dashboard_report.html- Interactive Cyber Dashboard HTML Report - ๐
<report_name>_<timestamp>.pdf- Executive Dark PDF Security Audit Report - ๐
output/vulnerabilities.json- Matched live CVE/CWE entries & CVSS ratings - ๐
output/dns.json- Complete DNS & DMARC records - ๐
output/ports.json- Open ports & service socket banners - ๐
output/ssl_audit.json- Cryptographic certificate details & expiration status - ๐
output/whois.json- WHOIS domain registration metadata - ๐
output/web.json- Web server headers & security matrix - ๐
output/links.json- Discovered web endpoints & sensitive form targets - ๐
output/phishing.json- Heuristic threat analysis indicators - ๐
output/risk_analysis.json- Aggregated threat scores & SOC verdict
- Cyber Aesthetic: Styled with Orbitron & Rajdhani Google Fonts, glassmorphism card containers, glowing risk score gauges, and dark cyan/emerald/red color palettes.
- Overall Risk Gauge: Circular risk score gauge (
0.0to10.0) withCRITICAL,HIGH,MEDIUM, orLOWrisk severity badges. - Interactive Tabs: Allows seamless switching between:
- Open Ports & Banners: Active service ports, protocols, and socket banners.
- CVE & CWE Database: Real-time matched vulnerability IDs, CVSS scores, and remediation guides.
- Web Security Headers Matrix: Audit table for
HSTS,CSP,X-Frame-Options,X-Content-Type-Options, andReferrer-Policy. - DNS & Email Audit: Record queries (
A,AAAA,MX,NS,TXT,_dmarc). - SSL/TLS Audit: Certificate issuer chain, validity countdown, status, and SANs.
- Browser Export: Includes a
๐จ๏ธ EXPORT DASHBOARDaction for printing or exporting directly from any browser.
RECON2EXPLOIT automatically prescribes remediations based on discovered vulnerabilities:
- P1 Critical: Enforce HTTP Security Headers (
HSTS,CSP,X-Frame-Options), renew expiring SSL certificates immediately. - P2 High: Configure strict
DMARCpolicies (p=reject), restrict open administrative service ports (SSH, RDP, MySQL, Database). - P3 Medium: Add missing anti-clickjacking
X-Frame-Optionsheaders, patch services matched in live CVE queries. - P4 Low / Info: Suppress detailed server version banner disclosures (
Server,X-Powered-By).
IMPORTANT: RECON2EXPLOIT is designed solely for legal security assessments, authorized penetration testing, and academic research. Unauthorized scanning of third-party domains without prior explicit consent is illegal. The developers assume no liability for misuse or damage caused by this software. Always operate within legal and ethical boundaries.
Distributed under the MIT License. See LICENSE for more information.
Made with โค๏ธ for Security Researchers & Penetration Testers