Recon-ng is a full-featured reconnaissance framework designed for open source web-based reconnaissance, with a look and feel similar to Metasploit but focused exclusively on web-based reconnaissance. It is completely modular, making it easy for Python developers to contribute.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A repository containing material for Android greybox fuzzing with AFL++ Frida mode
Tool for randomizing Cobalt Strike Malleable C2 profiles to evade static, signature-based detection controls.
Advanced command and control tool for red teaming and adversary simulation with extensive features and evasion capabilities.
Generates shellcode that loads Windows payloads from memory and runs them with parameters.
Redboto is a collection of scripts for red team operations against the AWS API.
High-performant, coroutines-driven, and fully customisable Low & Slow load generator for real-world pentesting with undetectability through Tor.
Darkarmour is a Windows AV evasion tool that helps bypass antivirus software, allowing for the creation of undetectable malware.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.