βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β reconFTW Capabilities β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β OSINT β Google dorks, GitHub secrets, metadata, β
β β email harvesting, API leaks, cloud enum, β
β β leaked credentials, S3 buckets β
ββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββ€
β Subdomains β 10+ passive sources, DNS bruteforce, β
β β permutations (AI-powered), recursive enum, β
β β CT logs, scraping, zone transfer, takeover β
ββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββ€
β Web Analysis β HTTP probing, screenshots, JS secrets, β
β β URL extraction, directory fuzzing, CMS, β
β β virtual hosts, parameters, GraphQL, gRPC β
ββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββ€
β Vulnerabilities β Nuclei templates, XSS, SQLi, SSRF, LFI, β
β β SSTI, CORS, CRLF, command injection, β
β β prototype pollution, 403 bypass, smuggling β
ββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββ€
β Host Analysis β Port scanning (nmap/naabu), CDN detection, β
β β WAF fingerprinting, geolocation, banners β
ββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββ€
β Automation β Checkpoint/resume system, incremental scans, β
β β notifications (Slack/Discord/Telegram), β
β β Axiom distributed scanning, AI reports β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ