recon.sh — All-Around Automated Recon
What It Is
recon.sh is my all-around recon pipeline. One bash script. Eight phases. Max depth. You give it a target, it runs everything it can, and it auto-skips tools you do not have.
This is not a TryHackMe walkthrough. My Race Conditions post follows a public room. This one is a tool I actually run — against labs, bug bounty scope, and machines I am explicitly allowed to test.
CAUTIONOnly run this against systems you own or are explicitly authorized to test (bug bounty scope, signed engagement, lab). Recon against random hosts is illegal. I will not take responsibility if you ignore that.
Output lands in a timestamped tree so you are not grepping a 4,000-line terminal dump at 2am:
recon_<target>_<timestamp>/ nmap/ web/ dns/ smb/ msf/ recon_summary.txtWhy I Wrote It
I already knew the chain. Nmap first. Then whatever the ports tell you — gobuster if 80 is open, enum4linux if 445 is open, sslscan if 443 is open. The problem was not knowledge. The problem was doing it by hand every box, and having the whole night die because nikto crashed.
I wanted one entry point: -t. After that, open ports decide what runs next. A missing binary is a skip. A failed tool is a skip. The run continues.
IMPORTANTControl. I do not want a single
aptpackage or a single scanner to decide whether the rest of recon happens. That is the same reason the script usesset -uo pipefailand notset -e.
The Pipeline
Eight phases. Domain targets get DNS and subdomains. An IP or CIDR skips name lookups — IS_DOMAIN is just “does the target contain a letter.”
| Phase | What runs | Notes |
|---|---|---|
| 1. Host / DNS / WHOIS / TLS | dig, dnsrecon, whois, sslscan | DNS/WHOIS only if the target is a domain |
| 2. Nmap | TCP -A, full TCP -p-, UDP, --script vuln | This is the brain. Everything later reads open ports from here |
| 3. Subdomains | subfinder, assetfinder, amass, ffuf, httpx | Domain only; skipped on IP/CIDR |
| 4. Web fingerprint | whatweb, wafw00f | Only if HTTP/HTTPS ports showed up |
| 5. Content discovery | gobuster, dirb, ffuf, feroxbuster | Same wordlist, four tools, different opinions |
| 6. Web vulns | nikto, nuclei, wpscan if WordPress | wpscan only if whatweb said WordPress |
| 7. Services | SMB, SNMP, FTP, LDAP | Driven by has_port |
| 8. Metasploit | auxiliary scanners | Opt-in with -m |
NOTE
--fastis TCP top-1000 only — no-p-, no full UDP.--skip-udp,--skip-web,--skip-subs,--skip-vulnare escape hatches when you do not have all night.
Design Choices
Three things that matter more than the ASCII banner.
1. Missing tools skip. Failed tools skip.
set -uo pipefail # NOTE: no -e; a single tool failing must not kill the run
have() { command -v "$1" &>/dev/null; }warn_missing() { echo -e "${YELLOW}[~] $1 not installed — that step will be skipped${RESET}"; }If you do not have nuclei, you still get nmap. If nikto dies at minute 40, nuclei still runs. Recon is a collection of evidence, not a single fragile command.
2. Nmap is the brain
Parse open TCP from the nmap files, then build web URLs and service checks from that list. Gobuster never runs “because I always run gobuster.” It runs because 80 or 443 was actually open.
OPEN_TCP=$(grep -hoE "^[0-9]+/tcp[[:space:]]+open" "$OUTDIR"/nmap/tcp_*.txt \ | awk '{print $1}' | cut -d/ -f1 | sort -un | paste -sd, -)
has_port() { echo ",$OPEN_TCP," | grep -q ",$1,"; }
# 80/8080/... → http:// | 443/8443/... → https://# then SMB 139/445, FTP 21, LDAP 389 only if has_port says soTIPUDP still wants root (
-sU). Without sudo you get a warning and the TCP path keeps going. That is the same skip philosophy, just for privileges.
3. --install does not abort the batch
for p in "${APT_PKGS[@]}"; do $SUDO apt-get install -y "$p" 2>/dev/null \ && echo -e " ${GREEN}✔${RESET} $p" \ || echo -e " ${YELLOW}~ $p not in apt (will try another method or skip)${RESET}"doneOne missing apt package must not kill the rest. Go tools (nuclei, subfinder, httpx, dnsx, assetfinder, amass) are optional — no Go, those steps skip. Same rule as runtime.
How I Actually Run It
./recon.sh --install./recon.sh -t 10.10.10.5./recon.sh -t example.com./recon.sh -t 10.10.10.5 --fast./recon.sh -t 10.10.10.5 -mThat is the whole operator surface I care about. Wordlists default to SecLists / dirb if they exist. Extensions default to the usual junk (php,html,txt,bak,js,...). -m adds Metasploit auxiliary recon after the rest.
Close
This script does not exploit. It does not “hack the box” for you. It dumps a findings tree — nmap, web, dns, smb — so you know where to look next.
IMPORTANTRecon is evidence collection. The interesting part is not running four directory busting tools. The interesting part is nmap decides the rest, and one failure does not get to kill the night.