Output Interpretation
Output Directory Structure
Recon/
└── example.com/
├── subdomains/ # Subdomain enumeration results
├── webs/ # Web probing and analysis
├── hosts/ # IP and port scanning
├── osint/ # OSINT findings
├── vulns/ # Vulnerability scan results
├── nuclei_output/ # Nuclei JSON results
├── fuzzing/ # Directory/file fuzzing
├── js/ # JavaScript analysis
├── screenshots/ # Web screenshots
├── .tmp/ # Temporary files
├── .log/ # Execution logs
├── .called_fn/ # Checkpoint markers
├── assets.jsonl # Automation-friendly asset list
└── hotlist.txt # Risk-scored findingsSubdomain Files (subdomains/)
subdomains/)subdomains.txt
subdomains_crt.txt
subdomains_dnsrecords.txt
subdomains_noerror.txt
subdomains_permut.txt
subdomains_recursive.txt
subdomains_scraping.txt
Web Files (webs/)
webs/)webs.txt
webs_all.txt
url_extract.txt
takeover.txt
url_gf/
url_extensions/
Host Files (hosts/)
hosts/)ips.txt
cdn.txt
portscan_passive.txt
portscan_active.txt
portscan_active.xml
portscan_active.gnmap
waf.txt
geo.txt
OSINT Files (osint/)
osint/)dorks.txt
emails.txt
passwords.txt
metadata_results.txt
github_company_secrets.json
apileaks.txt
domain_info.txt
spf_dmarc.txt
Vulnerability Files (vulns/)
vulns/)nuclei_output/
xss.txt
sqli.txt
ssrf.txt
cors.txt
redirect.txt
lfi.txt
testssl.txt
JavaScript Files (js/)
js/)js_files.txt
js_secrets.txt
js_endpoints.txt
Fuzzing Files (fuzzing/)
fuzzing/)fuzzing_full.txt
fuzzing_{subdomain}.txt
Screenshots (screenshots/)
screenshots/)Log Files (.log/)
.log/)reconftw.log
errors.log
Checkpoint Files (.called_fn/)
.called_fn/)Special Files
assets.jsonl
hotlist.txt
Interpreting Nuclei Results
Severity Levels
Severity
Description
Action
Reading Nuclei JSON
Key Fields:
Report Generation
AI-Generated Reports
Manual Report Creation
Data Export
Export to CSV
Export to Faraday
Export to JSON
Cleanup
Temporary Files
Reset Checkpoints
Full Clean
Next Steps
Last updated