Recon-ng Tutorial: Workspaces, Modules and a Short Walkthrough for Authorised Recon

Recon-ng is an open-source OSINT (Open Source Intelligence) framework built for ethical hackers and penetration testers. It provides a command-line environment with modular capabilities that help gather intelligence on domains, emails, IPs, and organizations using publicly available data sources. Recon-ng simplifies the reconnaissance phase by automating data collection, integrating with third-party APIs, and storing results in a structured database. It is widely used by red teamers, bug bounty hunters, and cybersecurity professionals to identify potential vulnerabilities before launching real-world attacks.

Jul 08, 2025 - 14:37
Updated: 7 days ago
108.5k
Recon-ng Tutorial: Workspaces, Modules and a Short Walkthrough for Authorised Recon

Quick answer: Recon-ng is an open-source Python framework with a console and installable modules for collecting public information such as subdomains, hosts and contacts into a database. Create a workspace, install and load a module, set the SOURCE domain, run it and view the results. Use it only on domains you own or are authorised to assess.

Key takeaways

  • Recon-ng keeps recon data in workspaces and database tables.
  • Modules are installed from a marketplace, and many need API keys.
  • Treat results as leads to verify, not a finished asset list.
  • Use it only on authorised targets, and on your own domain for defence.

What Recon-ng is

Recon-ng is an open-source reconnaissance framework written in Python, with a console that feels like Metasploit's. Instead of exploits it holds modules that collect public information such as subdomains, hosts, contacts and leaked credentials, and stores results in a database. It is part of Kali Linux and its source is on GitHub. See also the Kali tools page.

Use it only against domains and organisations you own or have written permission to assess. Even passive collection can matter legally when you use the data for contact or access.

Core ideas

  • Workspaces keep each engagement's data separate.
  • Marketplace modules are installed on demand, since many are not included by default.
  • Tables such as domains, hosts, contacts and credentials hold the data modules read and write.
  • API keys unlock modules that use third-party services. Keys are stored locally, so protect them.

A short walkthrough

This example uses the commands of Recon-ng version 5. Run it against a domain you own. Names and options can differ between versions, so use help to confirm.

$ recon-ng
[recon-ng][default] > workspaces create demo
[recon-ng][demo] > marketplace search hackertarget
[recon-ng][demo] > marketplace install recon/domains-hosts/hackertarget
[recon-ng][demo] > modules load recon/domains-hosts/hackertarget
[recon-ng][demo][hackertarget] > options set SOURCE yourdomain.example
[recon-ng][demo][hackertarget] > run
[recon-ng][demo][hackertarget] > show hosts

What this does: it creates a workspace, installs a module that queries a public host-search service, sets the target domain, runs the module and lists the hosts found in the database. The output is a table of hostnames and, where available, addresses. Which results appear depends on the target and on the service at the time, so treat any listing as a lead to verify, not a finished asset list.

Where it fits in a workflow

  1. Scope. Write down the domains and organisations in scope.
  2. Collect. Run domain, host and contact modules.
  3. Resolve and verify. Check which hosts exist and who owns them.
  4. Export. Use the reporting modules to produce CSV or HTML for the team.
  5. Hand off. Feed confirmed hosts to scanning tools such as Nmap, within scope.

Strengths and limits

StrengthsLimits
Free, scriptable and keeps results in a databaseMany modules need third-party API keys, some paid
Good for repeatable recon across engagementsResults depend on external services that change or disappear
Resource scripts allow automationData may be stale or wrong and must be checked

Defender's view

What Recon-ng finds is what any outsider can find. Run it on your own domain, then remove forgotten subdomains, retire exposed test hosts, check DNS records and remove staff contact details that should not be public. Reconnaissance is a defensive exercise as much as an offensive one.

Next steps

Read our deeper guides on Recon-ng commands and API setup and advanced reconnaissance, plus the roundup of best OSINT tools. To learn recon within a full methodology, see the CEH v13 course.

Related reading

Frequently Asked Questions

Recon-ng is an open-source reconnaissance framework in Python with a Metasploit-like console. Its modules gather public information such as subdomains, hosts and contacts and store results in a database, and it ships with Kali Linux.

The tool is legal, but you should use it only on domains and organisations you own or have written permission to assess. Using collected data to contact or access others without authorisation can break the law under the IT Act.

Use the marketplace commands inside Recon-ng, such as marketplace search to find a module and marketplace install to add it. Then load it with modules load, set options and run it. Confirm syntax with help for your version.

Many do, because they query third-party services such as search and threat intelligence platforms. Keys are stored locally, so protect them. Some services are free with limits and some are paid.

Recon-ng is a console framework that stores data in tables and runs modules, Maltego is a graphical link-analysis tool and theHarvester is a simpler command-line collector. They overlap, and many teams use more than one.

Run it against your own domain to see what outsiders can find, then remove forgotten subdomains, retire exposed test systems, review DNS records and take down staff contact details that should not be public.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.