
Recon toolkit, written in Go
Raccoon Recon
Recon toolkit, written in Go
Raccoon Recon
Why I built it
Recon is the part of a pentest where you run a dozen different tools, and the output ends up scattered across terminal tabs and text files. I wanted one place to run them, watch them, and keep what they found.
I wrote it for my penetration testing course in spring 2026, and it is the project where I learned Go. Everything ships in a single binary: the templates, the styles, and the scripts are embedded, so there is nothing to configure. Build it, run it, open the browser.
Passive · Active · Web
What it does
It covers the three phases in order. Passive recon never touches the target: WHOIS, DNS records, subdomain enumeration, generated search dorks, and links out to the public OSINT sources. Active recon does: port scans, service and OS detection, ping sweeps, SNMP. Web recon looks at headers, technologies, directories, and TLS.
Most of that work is done by the tools pentesters already trust, like Nmap and Gobuster. Raccoon Recon detects which ones are installed, runs them, and streams the output to the browser as it happens. A few things are built in with no dependencies at all: TLS analysis, robots and sitemap parsing, and metadata extraction from photos and PDFs, including GPS coordinates from a JPEG.
Live
Scan output streams to the dashboard over a WebSocket
Saved
Every result lands in SQLite, organized by engagement
Reported
Findings export as a Markdown or PDF report
What I learned
Wrapping a command-line tool sounds simple until you have to stream its output live, handle the tool not being installed, and store results in a shape a report can use later. That was the real work.
It also made the point of recon stick. The toolkit is organized the way an engagement is, so using it is a reminder of what you are allowed to do before you have touched anything, and what changes once you have.

