Sign inSign up

vulmon/recon-essentials

By vulmon

•Updated 5 minutes ago

Vulmon Recon Essentials web console: free, self-hosted external attack surface monitoring.

Image
0

125

vulmon/recon-essentials repository overview

⁠Vulmon Recon Essentials

Free, self-hosted reconnaissance and monitoring for your external attack surface. Recon Essentials is the discovery and inventory part of Vulmon Recon⁠, packaged to run on your own machine with Docker. You add the domains and IP ranges you own. It then keeps discovering what is exposed (subdomains, IPs, open ports, websites, technologies, certificates) and shows changes as they happen.

Everything it finds stays in a PostgreSQL database on your machine. It never uploads your assets.

This image is the web console. It runs together with the engine image, vulmon/recon-essentials-engine⁠, and a PostgreSQL database. Do not start it on its own. Use the installer below.

⁠Install

curl -fsSL https://raw.githubusercontent.com/kontratek/recon-essentials/main/install.sh | bash

The script creates a recon-essentials folder in the current directory, generates the database password, asks for the address people will open in the browser, pulls the images and starts everything. Then open http://<your-address>:8080/setup and create the first administrator.

Requirements: Docker Engine 24+ with Docker Compose v2 (a Linux server, or Docker Desktop on macOS or Windows), 2 CPU cores, 4 GB RAM and 10 GB disk to start with.

⁠Versions

Every release is one tested pair of images: this web image and the engine image carry the same version number. In the installation, .env names the release in one line, RECON_VERSION, and both images take that number. Always use the same version for both images, for example 1.0.0.

Images are available for linux/amd64 and linux/arm64.

⁠Limits

UnregisteredRegistered (free)
Discovered assets (domains + IPs)UnlimitedUnlimited
In-scope assets (domains + IPs)1550
Seeds45150

Registering is optional. It takes an email address and an activation code, in the app under Settings → License.

⁠The hosted product

Vulmon Recon⁠, the hosted product, adds a managed service and vulnerability intelligence: vulnerability findings with CVE matching, cloud connectors, integrations, the public API and single sign-on.

⁠Documentation and support

Recon Essentials is not open source. Its use is governed by the Terms of Service⁠ and the Privacy Policy⁠.

Tag summary

Content type

Image

Digest

sha256:d8c6e119f…

Size

255 Bytes

Last updated

5 minutes ago

docker pull vulmon/recon-essentials:sha256-e3cdf41c822b2b2fce416b98e1b01b1f5a5dd2600c62b4a8543f18bb34d175ea.sig