Skip to content

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 

Repository files navigation

██╗    ██╗███████╗██████╗ ██████╗ ███████╗██╗  ██╗ ██████╗ ███╗   ██╗
██║    ██║██╔════╝██╔══██╗██╔══██╗██╔════╝██║ ██╔╝██╔═══██╗████╗  ██║
██║ █╗ ██║█████╗  ██████╔╝██████╔╝█████╗  █████╔╝ ██║   ██║██╔██╗ ██║
██║███╗██║██╔══╝  ██╔══██╗██╔══██╗██╔══╝  ██╔═██╗ ██║   ██║██║╚██╗██║
╚███╔███╔╝███████╗██████╔╝██║  ██║███████╗██║  ██╗╚██████╔╝██║ ╚████║
 ╚══╝╚══╝ ╚══════╝╚═════╝ ╚═╝  ╚═╝╚══════╝╚═╝  ╚═╝ ╚═════╝ ╚═╝  ╚═══

GitHub Python Platform Security Status

WebRekon is a command-line web reconnaissance tool built for CTF players and authorized security testing.

The main goal is simple: reduce the time spent manually collecting information about a target and give the player a clear picture of the web attack surface before they start deeper manual testing.

What WebRekon Does

WebRekon performs multiple reconnaissance checks against an authorized target and organizes the results into an easy-to-read format.

It can identify:

  • Open ports and running services
  • Service versions
  • Web technologies
  • Discovered routes and files
  • API endpoints
  • Login and authentication surfaces
  • robots.txt and sitemap information
  • Interesting source-code indicators
  • Hidden source clues
  • JavaScript references
  • Exposed Git repositories
  • Potential SSRF attack surfaces
  • Interesting session or authorization cookies
  • Missing security headers
  • Other useful reconnaissance findings

The tool does not try to automatically exploit vulnerabilities. Instead, it helps the player understand what was discovered and suggests areas that are worth investigating manually.

AI-Assisted Reconnaissance

WebRekon also includes an optional AI-assisted source intelligence feature.

The AI can review retrieved web pages and help identify pages that may contain useful hidden clues in their source code.

Instead of dumping hidden content directly, WebRekon can point the player toward the relevant page and explain why it may deserve manual inspection.

The AI can also provide context-aware suggestions based on reconnaissance findings, helping the player decide what to investigate next.

AI usage is optional and the core reconnaissance workflow can continue without it.

Designed for CTF Players

WebRekon was created with CTF workflows in mind.

A typical workflow looks like:

Target → Authorization → Port & Service Discovery → Technology Detection → Route Discovery → API Discovery → Source Intelligence → Interesting Findings → Recommended Next Steps

The idea is to give the player useful information first, rather than immediately jumping into exploitation.

Interface

WebRekon uses a terminal-based interface designed to keep reconnaissance results organized and readable.

The interface separates information into areas such as:

  • Target details
  • Technologies
  • Ports and services
  • Web surface
  • API endpoints
  • Routes
  • Source intelligence
  • Interesting findings
  • Recommended next steps

Project Status

WebRekon is an active project and is still being improved with additional reconnaissance capabilities and better CTF-focused workflows.

Official Repository

The main development repository is maintained under my primary GitHub account.

For the complete source code, documentation, updates, and latest version:

Official WebRekon Repository:
https://github.com/thehusnain/WebRekon

Author

Built by Sheriff as a cybersecurity and CTF-focused reconnaissance project.

The project is intended for:

  • CTF competitions
  • Authorized security labs
  • Educational security testing
  • Systems you own or have explicit permission to assess

Only use WebRekon against targets you are authorized to test.

About

command-line web reconnaissance tool built for CTF players

Topics

Resources

Stars

4 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors