Module marketplace
Modules are grouped by methodology step: recon, discovery, exploitation and reporting, plus a custom branch for your own.
The Recon-ng OSINT framework is a free, open-source tool for web-based reconnaissance, with a console that looks like Metasploit and modules you install from a marketplace. This review is based on the official repository, its wiki and the Kali Linux package page, checked on 10 October 2026.
Recon-ng OSINT framework is a Python command-line tool for structured reconnaissance: you create a workspace per target, install modules from its marketplace and chain them so that domains become hosts, hosts become IP addresses and contacts. It suits penetration testers and security teams who script repeatable recon. It is free under GPL-3.0; some modules need third-party API keys.
A full-featured reconnaissance framework that collects open-source, web-based information about an organization and stores it in a database for analysis.
The repository describes Recon-ng as a "full-featured reconnaissance framework" meant to reduce the time spent collecting information from open sources (GitHub). Its interface resembles Metasploit's, but the scope is deliberately narrow: the README sends users to Metasploit for exploitation and to the Social-Engineer Toolkit for social engineering. Recon-ng is only for collection.
It is a staple of security training and testing distributions. Kali Linux packages version 5.1.2 and includes it in its default metapackage (Kali Tools), and the repository shows about 5,900 GitHub stars.
You start with an empty framework, install the modules you need, seed a workspace with what you know and run modules that turn one data type into another.
A database-centered design, scripting and a separate web interface make it suited to repeatable, documented recon.
Modules are grouped by methodology step: recon, discovery, exploitation and reporting, plus a custom branch for your own.
Built-in commands run raw SQL queries, draw the schema and insert or delete records.
Record a session's commands and replay them later, or log all activity to a file for your notes.
A web interface for exploring stored data; the wiki marks the old reporting modules as deprecated in its favor.
Exposes framework functions to external shell scripts and pipelines.
Install from source with pip, or use Docker; the Recon-web task API needs Redis, so Docker Compose is recommended.
Recon-ng is free under GPL-3.0; its version has been 5.1.2 for some time, so check module health before you depend on it.
| Item | Detail (checked 10 October 2026) |
|---|---|
| Price | Free; the README asks for donations to fund development |
| License | GPL-3.0 for the framework and the official module repository |
| Language and runtime | Python; the wiki states Python 3.6 or later |
| Current version | 5.1.2 in the repository's VERSION file and in Kali |
| Releases | No tagged GitHub releases; the Getting Started wiki page was last edited in June 2020 |
| Sponsors listed | Black Hills Information Security and Practical Security Services |
| Data costs | Some modules call commercial APIs; their keys and fees are set by each provider |
A stable version number is not a problem by itself, but recon modules depend on third-party websites and APIs that change. Before an engagement, run the modules you plan to use against a test domain and replace any that fail.
It suits technical testers who want structured, scriptable recon; it does not suit non-technical users or investigations focused on people.
Modules can break as sources change, results need verification, and anything beyond passive lookups requires the system owner's permission.
theHarvester is quicker for a first pass, SpiderFoot automates more, Shodan and Censys add scan data and Maltego adds graphs.
| Tool | How it differs | Price model |
|---|---|---|
| theHarvester | Single command for emails, subdomains and hosts from 59 sources; actively released in 2026 | Free, open source |
| SpiderFoot | Over 200 modules with a web interface and automated scans | Free, open source (MIT) |
| Shodan and Censys | Internet-scan search engines for hosts, ports and certificates | Free tiers, paid plans |
| Maltego | Visual link analysis with commercial data integrations | Free and paid plans |
Our guide to OSINT tools groups these and others by investigation task.
If you need to know what an attacker can learn about your organization, an analyst-led, authorized assessment gives you verified findings and priorities.
Recon-ng collects data; it does not decide what matters. Our red team OSINT reconnaissance and social engineering assessment services combine tooling like this with manual research, verify which assets and people are really exposed and rank the fixes. Work is scoped in writing, reviewed by a senior analyst before reporting and quoted at a fixed price; focused engagements usually run from 10 business days.
You can also browse the full range of OSINT services we offer.
Send the domains in scope and who signed off. We return a verified map of your exposure with the fixes in order.
Recon-ng is a Python console framework that collects open-source information about an organization through installable modules and stores results in a per-target database. It is still widely taught and ships in Kali's default metapackage at version 5.1.2 (Kali). Its value today is mostly the method it teaches: workspaces, seeding and chaining data types. Pair it with actively released tools such as theHarvester and check that the modules you need still work.
You are not doing anything wrong: the framework ships with no modules by default. Use the marketplace command to search for modules, check whether they need dependencies or API keys, and install them one by one or all at once. Modules with unmet dependencies may install but stay disabled, and modules loaded before their API key is added will warn you and may fail when run.
Get written approval from whoever owns security for the domain, even if it is your employer, and note which systems are hosted by third parties. Passive recon modules that query public datasets are low risk. Discovery and exploitation modules interact with systems directly, so run them only within an agreed scope. Treat collected employee names and emails as personal data and delete them when the audit ends.
You do not have to pick one; many teams use both. SpiderFoot offers a web interface and over 200 modules with automated scans, which is easier for occasional users. Recon-ng gives finer control through workspaces, a queryable database and resource scripts, which suits testers who script their workflow. Both are free. For maintenance, test the modules you rely on regularly, because recon modules break when outside sources change.
Raw output is not enough for a board. Recon-ng records what modules returned, including stale hosts and contacts who left long ago. Before reporting, verify each asset belongs to the client, remove outdated records, explain what an attacker could do with each finding and rank fixes by impact. Recon-web can export the data, but the analysis and the plain-language summary still have to be written by a person.
Sources checked 10 October 2026. This review is based on official documentation, repositories and package pages; OSINT-S has not run the tool for this review and has no affiliation with the project.