Recon-ng OSINT Framework Review: Modules, Workspaces and Limits

The Recon-ng OSINT framework is a free, open-source tool for web-based reconnaissance, with a console that looks like Metasploit and modules you install from a marketplace. This review is based on the official repository, its wiki and the Kali Linux package page, checked on 10 October 2026.

  • Free, GPL-3.0 license
  • Python console framework
  • Modules from a marketplace
  • For authorized assessments only

Not tested by OSINT-S. Based on vendor documentation, the repository and package pages. No affiliation with the project.

Short answer

Recon-ng OSINT framework is a Python command-line tool for structured reconnaissance: you create a workspace per target, install modules from its marketplace and chain them so that domains become hosts, hosts become IP addresses and contacts. It suits penetration testers and security teams who script repeatable recon. It is free under GPL-3.0; some modules need third-party API keys.

What Is the Recon-ng OSINT Framework?

A full-featured reconnaissance framework that collects open-source, web-based information about an organization and stores it in a database for analysis.

The repository describes Recon-ng as a "full-featured reconnaissance framework" meant to reduce the time spent collecting information from open sources (GitHub). Its interface resembles Metasploit's, but the scope is deliberately narrow: the README sends users to Metasploit for exploitation and to the Social-Engineer Toolkit for social engineering. Recon-ng is only for collection.

It is a staple of security training and testing distributions. Kali Linux packages version 5.1.2 and includes it in its default metapackage (Kali Tools), and the repository shows about 5,900 GitHub stars.

How Recon-ng Works: Marketplace, Modules and Workspaces

You start with an empty framework, install the modules you need, seed a workspace with what you know and run modules that turn one data type into another.

  1. Create a workspaceEach workspace has its own database, configuration, reports and loot, so one engagement never mixes with another (wiki).
  2. Install modulesThe framework ships with no modules. The marketplace command searches, describes, installs and removes them from the official module repository, and flags modules that need dependencies or API keys.
  3. Add API keysKeys are kept in a separate SQLite database in the user's home folder, so they persist across workspaces (Getting Started).
  4. Seed and chainModule names encode input and output tables, such as domains to hosts. Every record in the database can become the input for the next module.
  5. Review and exportQuery the database directly or use Recon-web, the browser interface for analyzing, visualizing and exporting results.

Key Recon-ng Features

A database-centered design, scripting and a separate web interface make it suited to repeatable, documented recon.

Modules

Module marketplace

Modules are grouped by methodology step: recon, discovery, exploitation and reporting, plus a custom branch for your own.

Data

Database per workspace

Built-in commands run raw SQL queries, draw the schema and insert or delete records.

Automation

Resource files

Record a session's commands and replay them later, or log all activity to a file for your notes.

Interface

Recon-web

A web interface for exploring stored data; the wiki marks the old reporting modules as deprecated in its favor.

Scripting

recon-cli

Exposes framework functions to external shell scripts and pipelines.

Deploy

Source or Docker

Install from source with pip, or use Docker; the Recon-web task API needs Redis, so Docker Compose is recommended.

Price, License and Maintenance Status

Recon-ng is free under GPL-3.0; its version has been 5.1.2 for some time, so check module health before you depend on it.

ItemDetail (checked 10 October 2026)
PriceFree; the README asks for donations to fund development
LicenseGPL-3.0 for the framework and the official module repository
Language and runtimePython; the wiki states Python 3.6 or later
Current version5.1.2 in the repository's VERSION file and in Kali
ReleasesNo tagged GitHub releases; the Getting Started wiki page was last edited in June 2020
Sponsors listedBlack Hills Information Security and Practical Security Services
Data costsSome modules call commercial APIs; their keys and fees are set by each provider

A stable version number is not a problem by itself, but recon modules depend on third-party websites and APIs that change. Before an engagement, run the modules you plan to use against a test domain and replace any that fail.

Who Recon-ng Suits and Who It Does Not

It suits technical testers who want structured, scriptable recon; it does not suit non-technical users or investigations focused on people.

  • Good fit: penetration testers and red teams working inside a written scope; security teams auditing their own domains; instructors teaching a structured reconnaissance method; developers who want to write their own modules.
  • Poor fit: due diligence, background checks or person-focused research; users who need a graphical tool; teams that need results interpreted and reported for executives or lawyers.

Limitations and Authorized Use in OSINT Reconnaissance

Modules can break as sources change, results need verification, and anything beyond passive lookups requires the system owner's permission.

  • Module reliability. Modules are maintained separately from the framework and rely on outside services, so expect some to fail or return partial data.
  • Discovery modules touch the target. The marketplace includes discovery and exploitation branches. Use them only on systems you own or are authorized to test; unauthorized access can fall under laws such as the US Computer Fraud and Abuse Act. Our OSINT penetration testing work always runs under written rules of engagement.
  • Contacts are personal data. Modules that collect names, emails and profiles create personal data under the GDPR and similar laws. Minimize, secure and delete it when the work ends.
  • Sensitive sectors. Recon against utilities, energy or transport operators should run only through the operator's approved process; see our critical infrastructure page for that context.

Recon-ng Alternatives for OSINT Teams

theHarvester is quicker for a first pass, SpiderFoot automates more, Shodan and Censys add scan data and Maltego adds graphs.

ToolHow it differsPrice model
theHarvesterSingle command for emails, subdomains and hosts from 59 sources; actively released in 2026Free, open source
SpiderFootOver 200 modules with a web interface and automated scansFree, open source (MIT)
Shodan and CensysInternet-scan search engines for hosts, ports and certificatesFree tiers, paid plans
MaltegoVisual link analysis with commercial data integrationsFree and paid plans

Our guide to OSINT tools groups these and others by investigation task.

Need the Answer, Not the Tool?

If you need to know what an attacker can learn about your organization, an analyst-led, authorized assessment gives you verified findings and priorities.

Recon-ng collects data; it does not decide what matters. Our red team OSINT reconnaissance and social engineering assessment services combine tooling like this with manual research, verify which assets and people are really exposed and rank the fixes. Work is scoped in writing, reviewed by a senior analyst before reporting and quoted at a fixed price; focused engagements usually run from 10 business days.

You can also browse the full range of OSINT services we offer.

Plan an Authorized Reconnaissance Engagement

Send the domains in scope and who signed off. We return a verified map of your exposure with the fixes in order.

Recon-ng OSINT FAQ

I'm learning reconnaissance for a security job and keep seeing the Recon-ng OSINT framework in course material — what does it actually do, and is it still worth learning in 2026?

Recon-ng is a Python console framework that collects open-source information about an organization through installable modules and stores results in a per-target database. It is still widely taught and ships in Kali's default metapackage at version 5.1.2 (Kali). Its value today is mostly the method it teaches: workspaces, seeding and chaining data types. Pair it with actively released tools such as theHarvester and check that the modules you need still work.

I installed Recon-ng on Kali, but when I type a module name nothing loads — am I doing something wrong, or does the framework not come with modules?

You are not doing anything wrong: the framework ships with no modules by default. Use the marketplace command to search for modules, check whether they need dependencies or API keys, and install them one by one or all at once. Modules with unmet dependencies may install but stay disabled, and modules loaded before their API key is added will warn you and may fail when run.

Our company wants me to use Recon-ng to check what our own domain exposes — do I need anyone's permission if it's our own organization, and which modules should I be careful with?

Get written approval from whoever owns security for the domain, even if it is your employer, and note which systems are hosted by third parties. Passive recon modules that query public datasets are low risk. Discovery and exploitation modules interact with systems directly, so run them only within an agreed scope. Treat collected employee names and emails as personal data and delete them when the audit ends.

We're deciding between Recon-ng and SpiderFoot for automated recon in our small security team — which is easier to maintain, and do we have to pick only one?

You do not have to pick one; many teams use both. SpiderFoot offers a web interface and over 200 modules with automated scans, which is easier for occasional users. Recon-ng gives finer control through workspaces, a queryable database and resource scripts, which suits testers who script their workflow. Both are free. For maintenance, test the modules you rely on regularly, because recon modules break when outside sources change.

A client asked whether our Recon-ng findings can go straight into a board report about cyber exposure — is raw framework output good enough, or what extra work does it need?

Raw output is not enough for a board. Recon-ng records what modules returned, including stale hosts and contacts who left long ago. Before reporting, verify each asset belongs to the client, remove outdated records, explain what an attacker could do with each finding and rank fixes by impact. Recon-web can export the data, but the analysis and the plain-language summary still have to be written by a person.