James Ruggles
A web-based reconnaissance toolkit for the information-gathering phase of a penetration test. One Go binary, a dark dashboard in the browser, live scan output, and every result saved for the report.
GoSQLiteWebSocketNmapOSINTReporting
  View on GitHub
Go
single binary
19
recon tools
~4K
lines of Go
3
recon phases

Why I built it

Recon is the part of a pentest where you run a dozen different tools, and the output ends up scattered across terminal tabs and text files. I wanted one place to run them, watch them, and keep what they found.

I wrote it for my penetration testing course in spring 2026, and it is the project where I learned Go. Everything ships in a single binary: the templates, the styles, and the scripts are embedded, so there is nothing to configure. Build it, run it, open the browser.

Browser dashboardprojects · quick-action cardsHTTP + WebSocket (live output)Raccoon Reconone Go binary · templates, CSS, JS embeddedPassive reconWHOISDNS recordsSubdomainsDorks · OSINTActive reconPort scanService + OSPing sweepSNMP · tracerouteWeb reconHeadersTech detectDirectoriesTLS · robotsSQLiteevery result persistedReportsMarkdown or PDF

Passive · Active · Web

What it does

It covers the three phases in order. Passive recon never touches the target: WHOIS, DNS records, subdomain enumeration, generated search dorks, and links out to the public OSINT sources. Active recon does: port scans, service and OS detection, ping sweeps, SNMP. Web recon looks at headers, technologies, directories, and TLS.

Most of that work is done by the tools pentesters already trust, like Nmap and Gobuster. Raccoon Recon detects which ones are installed, runs them, and streams the output to the browser as it happens. A few things are built in with no dependencies at all: TLS analysis, robots and sitemap parsing, and metadata extraction from photos and PDFs, including GPS coordinates from a JPEG.

Live

Scan output streams to the dashboard over a WebSocket

Saved

Every result lands in SQLite, organized by engagement

Reported

Findings export as a Markdown or PDF report

What I learned

Wrapping a command-line tool sounds simple until you have to stream its output live, handle the tool not being installed, and store results in a shape a report can use later. That was the real work.

It also made the point of recon stick. The toolkit is organized the way an engagement is, so using it is a reminder of what you are allowed to do before you have touched anything, and what changes once you have.

Next
Project