# six2dez/reconftw

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

Repository: https://github.com/six2dez/reconftw
Canonical: https://ross.abutalabs.com/products/reconftw
Homepage: https://docs.reconftw.com/
Language: Shell
License: MIT
License Family: permissive
Topics: bugbounty, hacking, recon, pentest, subdomain, nuclei, vulnerabilities, scanner, osint, penetration-testing, pentesting, reconnaissance, dns, pentest-tool, security, security-tools, bug-bounty, bugbounty-tool, subdomain-enumeration
Last push: 2026-08-26T12:01:21+00:00

## Health v2 (maintenance only)
Score: 86/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 62, longevity 100
- inputs: {"age_days": 2072, "days_push": 7, "days_rel": 179, "gap_med": 63.5, "n_releases_24m": 7}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 8025, forks 1224 (observed 2026-08-28T04:10:11.874931+00:00)

## What it is
reconFTW is an open-source (MIT) automated reconnaissance framework written in Shell that orchestrates 80+ security tools to perform full recon on target domains, from OSINT and subdomain enumeration to web analysis and vulnerability scanning. It is aimed at bug bounty hunters, penetration testers, and security researchers, with modular configuration and optional distributed scanning via Axiom.

## Use cases
- automate reconnaissance on a target domain
- enumerate subdomains for a bug bounty target
- scan a domain for vulnerabilities with nuclei
- run OSINT on a company before a pentest
- perform full recon pipeline with a single command
- scale recon scans across cloud instances
- import scan results into a vulnerability management platform

## When to choose
- you want a one-command, end-to-end recon pipeline for a domain
- you do bug bounty or pentesting and need subdomain enumeration, web analysis, and vuln scanning chained together
- you want to orchestrate many existing security tools without wiring them yourself
- you need distributed scanning across multiple machines via Axiom

## When to avoid
- you need a GUI or web dashboard for managing scans
- you only need a single specific check rather than a full recon suite
- you are on Windows without WSL2, since Linux/macOS are the supported platforms
- you lack authorization to scan the target - it is for legal, authorized testing only

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, penetration-testing, osint, vulnerability-scanning, web-scraping, developer-tools
- domain: security, penetration-testing, osint, developer-tools
- platform: cli
- tags: reconnaissance, bug-bounty, subdomain-enumeration, nuclei, automated-scanning, pentesting, shell-script, distributed-scanning, axiom, faraday, automation, linux, macos, docker, shell

## Member repositories
- six2dez/reconftw (main) score 86

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:10:11.874931+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:31:49.498398+00:00, confidence not recorded.
  - readme: https://github.com/six2dez/reconftw (fetched 2026-08-28T04:10:11.874931+00:00, sha 14eabc13553b)
  - homepage: https://docs.reconftw.com/ (fetched 2026-08-29T08:29:20.941369+00:00, sha 0c7cb522e503)
  - site_page: https://docs.reconftw.com/welcome/faq (fetched 2026-08-29T08:29:20.950231+00:00, sha defcb22a8490)
  - site_page: https://docs.reconftw.com/getting-started/getting-started (fetched 2026-08-29T08:29:20.952037+00:00, sha db4e87201616)
  - site_page: https://docs.reconftw.com/integrations/axiom (fetched 2026-08-29T08:29:20.953767+00:00, sha b0243db51a9a)
  - site_page: https://docs.reconftw.com/integrations/faraday (fetched 2026-08-29T08:29:20.955408+00:00, sha 5d977a536b8e)
- Data as of 2026-08-30T08:39:29.467469+00:00.
