Vulmon Recon Essentials web console: free, self-hosted external attack surface monitoring.
125
Free, self-hosted reconnaissance and monitoring for your external attack surface. Recon Essentials is the discovery and inventory part of Vulmon Recon, packaged to run on your own machine with Docker. You add the domains and IP ranges you own. It then keeps discovering what is exposed (subdomains, IPs, open ports, websites, technologies, certificates) and shows changes as they happen.
Everything it finds stays in a PostgreSQL database on your machine. It never uploads your assets.
This image is the web console. It runs together with the engine image, vulmon/recon-essentials-engine, and a PostgreSQL database. Do not start it on its own. Use the installer below.
curl -fsSL https://raw.githubusercontent.com/kontratek/recon-essentials/main/install.sh | bash
The script creates a recon-essentials folder in the current directory, generates the database password, asks for the address people will open in the browser, pulls the images and starts everything. Then open http://<your-address>:8080/setup and create the first administrator.
Requirements: Docker Engine 24+ with Docker Compose v2 (a Linux server, or Docker Desktop on macOS or Windows), 2 CPU cores, 4 GB RAM and 10 GB disk to start with.
Every release is one tested pair of images: this web image and the engine image carry the same version number. In the installation, .env names the release in one line, RECON_VERSION, and both images take that number. Always use the same version for both images, for example 1.0.0.
Images are available for linux/amd64 and linux/arm64.
| Unregistered | Registered (free) | |
|---|---|---|
| Discovered assets (domains + IPs) | Unlimited | Unlimited |
| In-scope assets (domains + IPs) | 15 | 50 |
| Seeds | 45 | 150 |
Registering is optional. It takes an email address and an activation code, in the app under Settings → License.
Vulmon Recon, the hosted product, adds a managed service and vulnerability intelligence: vulnerability findings with CVE matching, cloud connectors, integrations, the public API and single sign-on.
Recon Essentials is not open source. Its use is governed by the Terms of Service and the Privacy Policy.
Content type
Image
Digest
sha256:d8c6e119f…
Size
255 Bytes
Last updated
5 minutes ago
docker pull vulmon/recon-essentials:sha256-e3cdf41c822b2b2fce416b98e1b01b1f5a5dd2600c62b4a8543f18bb34d175ea.sig