749 words
4 minutes
recon.sh

recon.sh — All-Around Automated Recon#

What It Is#

recon.sh is my all-around recon pipeline. One bash script. Eight phases. Max depth. You give it a target, it runs everything it can, and it auto-skips tools you do not have.

This is not a TryHackMe walkthrough. My Race Conditions post follows a public room. This one is a tool I actually run — against labs, bug bounty scope, and machines I am explicitly allowed to test.

CAUTION

Only run this against systems you own or are explicitly authorized to test (bug bounty scope, signed engagement, lab). Recon against random hosts is illegal. I will not take responsibility if you ignore that.

Output lands in a timestamped tree so you are not grepping a 4,000-line terminal dump at 2am:

recon_<target>_<timestamp>/
nmap/ web/ dns/ smb/ msf/
recon_summary.txt

Why I Wrote It#

I already knew the chain. Nmap first. Then whatever the ports tell you — gobuster if 80 is open, enum4linux if 445 is open, sslscan if 443 is open. The problem was not knowledge. The problem was doing it by hand every box, and having the whole night die because nikto crashed.

I wanted one entry point: -t. After that, open ports decide what runs next. A missing binary is a skip. A failed tool is a skip. The run continues.

IMPORTANT

Control. I do not want a single apt package or a single scanner to decide whether the rest of recon happens. That is the same reason the script uses set -uo pipefail and not set -e.


The Pipeline#

Eight phases. Domain targets get DNS and subdomains. An IP or CIDR skips name lookups — IS_DOMAIN is just “does the target contain a letter.”

PhaseWhat runsNotes
1. Host / DNS / WHOIS / TLSdig, dnsrecon, whois, sslscanDNS/WHOIS only if the target is a domain
2. NmapTCP -A, full TCP -p-, UDP, --script vulnThis is the brain. Everything later reads open ports from here
3. Subdomainssubfinder, assetfinder, amass, ffuf, httpxDomain only; skipped on IP/CIDR
4. Web fingerprintwhatweb, wafw00fOnly if HTTP/HTTPS ports showed up
5. Content discoverygobuster, dirb, ffuf, feroxbusterSame wordlist, four tools, different opinions
6. Web vulnsnikto, nuclei, wpscan if WordPresswpscan only if whatweb said WordPress
7. ServicesSMB, SNMP, FTP, LDAPDriven by has_port
8. Metasploitauxiliary scannersOpt-in with -m
NOTE

--fast is TCP top-1000 only — no -p-, no full UDP. --skip-udp, --skip-web, --skip-subs, --skip-vuln are escape hatches when you do not have all night.


Design Choices#

Three things that matter more than the ASCII banner.

1. Missing tools skip. Failed tools skip.#

set -uo pipefail # NOTE: no -e; a single tool failing must not kill the run
have() { command -v "$1" &>/dev/null; }
warn_missing() { echo -e "${YELLOW}[~] $1 not installed — that step will be skipped${RESET}"; }

If you do not have nuclei, you still get nmap. If nikto dies at minute 40, nuclei still runs. Recon is a collection of evidence, not a single fragile command.

2. Nmap is the brain#

Parse open TCP from the nmap files, then build web URLs and service checks from that list. Gobuster never runs “because I always run gobuster.” It runs because 80 or 443 was actually open.

OPEN_TCP=$(grep -hoE "^[0-9]+/tcp[[:space:]]+open" "$OUTDIR"/nmap/tcp_*.txt \
| awk '{print $1}' | cut -d/ -f1 | sort -un | paste -sd, -)
has_port() { echo ",$OPEN_TCP," | grep -q ",$1,"; }
# 80/8080/... → http:// | 443/8443/... → https://
# then SMB 139/445, FTP 21, LDAP 389 only if has_port says so
TIP

UDP still wants root (-sU). Without sudo you get a warning and the TCP path keeps going. That is the same skip philosophy, just for privileges.

3. --install does not abort the batch#

for p in "${APT_PKGS[@]}"; do
$SUDO apt-get install -y "$p" 2>/dev/null \
&& echo -e " ${GREEN}✔${RESET} $p" \
|| echo -e " ${YELLOW}~ $p not in apt (will try another method or skip)${RESET}"
done

One missing apt package must not kill the rest. Go tools (nuclei, subfinder, httpx, dnsx, assetfinder, amass) are optional — no Go, those steps skip. Same rule as runtime.


How I Actually Run It#

./recon.sh --install
./recon.sh -t 10.10.10.5
./recon.sh -t example.com
./recon.sh -t 10.10.10.5 --fast
./recon.sh -t 10.10.10.5 -m

That is the whole operator surface I care about. Wordlists default to SecLists / dirb if they exist. Extensions default to the usual junk (php,html,txt,bak,js,...). -m adds Metasploit auxiliary recon after the rest.


Close#

This script does not exploit. It does not “hack the box” for you. It dumps a findings tree — nmap, web, dns, smb — so you know where to look next.

IMPORTANT

Recon is evidence collection. The interesting part is not running four directory busting tools. The interesting part is nmap decides the rest, and one failure does not get to kill the night.

recon.sh
https://milanfarkas.com/posts/recon-sh/
Author
Milan Farkas
Published at
2026-08-16
License
CC BY-NC-SA 4.0