Reconmap is an open source web application for organizing and mapping reconnaissance data during penetration tests. It allows infosec professionals to keep track of subnets, open ports, running services, and other findings.
Reconmap is an open source web application for organizing and mapping reconnaissance data during penetration tests. It allows infosec professionals to keep track of subnets, open ports, running services, and other findings.
What is Reconmap?
Reconmap is an open source web reconnaissance and vulnerability scanning application built for penetration testers and bug bounty hunters. It provides an intuitive user interface to organize and map information gathered during the initial reconnaissance phase.
Some of the key features of Reconmap include:
Subdomain discovery and mapping
Port scanning and service enumeration
Directory and file brute forcing
Vulnerability scanning integration
Notes, labels and tagging to keep findings organized
Customizable reporting
By leveraging Reconmap, security analysts can increase efficiency in documenting and leveraging reconnaissance data to expand their testing surface and identify promising areas to investigate for vulnerabilities. All findings are stored in a PostgreSQL database and displayed visually for rapid analysis.
As an open source tool, Reconmap benefits from contributions from the infosec community to continue adding new capabilities. It provides both time savings and visibility compared to manual tracking of reconnaissance activities.
Reconmap Features
Features
Web-based interface for managing and visualizing recon data
Hexway Hive is an all-in-one business management and collaboration platform designed to meet the needs of modern companies. It brings together essential tools like project and task management, customer relationship management (CRM), data analytics, and team communication in a single, easy-to-use solution.Some key features of Hexway Hive include:Project management -...
Dradis is an open-source web application designed for information security teams to collaborate on assessments. It provides a centralized repository to manage findings from vulnerability scans, pentests, and other security testing activities.Some key features of Dradis include:Import findings from tools like Nmap, Nessus, Nikto, Burp Suite etc.Organize findings into custom...
Faraday IDE is a free and open-source multiplatform Integrated Development Environment focused on penetration testing, security research, Internet of Things security testing, and software/hardware prototyping. It was created by Infobyte LLC, an Argentine cybersecurity company.Some of the key features of Faraday IDE include:Tools for network mapping and service enumeration like...
Karmahostage is an open-source comment hosting service released under the MIT license. It allows website owners to easily integrate a comment system into their sites to enable user discussions.Some key features of Karmahostage include:Lightweight and fast - it uses very little server resources so it can handle high traffic websitesCustomizable...
AttackForge.com is an online platform designed to make penetration testing more accessible and collaborative. It provides a library of preconfigured attacks covering common vulnerabilities that users can customize and chain together to model real-world attack scenarios.Some key features of AttackForge include:Library of hundreds of prebuilt attacks covering SQLi, XSS, RFI,...
Poortego is an open-source, self-hosted password manager that allows users to securely store passwords and other sensitive information. It is designed to protect sensitive data by using strong encryption so that only the user has the key to decrypt their information.Some key features of Poortego include:Secure password storage - Passwords...