r3con — OSINT Recon Tool
Multi-phase recon pipeline: passive subdomain enumeration, HTTP probing, rule-based tech fingerprinting, banner grabbing, Shodan enrichment, dual JSON+TXT reports with risk flags.
I don't trust a system until I've tried to break it myself. So I build the tools to do that, then see what's left standing.
What's running on my machine and in my head right now. Updated as things change.
Three of twelve. Recon automation, network detection, and cloud misconfiguration scanning — each one solved a problem I actually hit.
Multi-phase recon pipeline: passive subdomain enumeration, HTTP probing, rule-based tech fingerprinting, banner grabbing, Shodan enrichment, dual JSON+TXT reports with risk flags.
Real-time network intrusion detection built on Scapy. Detects ARP spoofing, port scans, SYN floods, and DNS anomalies. Flags MITM attempts and reconstructs TCP streams.
Automated detection of IAM privilege escalation paths, public S3 buckets, open security groups, missing CloudTrail logging, and VPC misconfigurations.
Not what I know — how I apply it. Four modes, one habit: enumerate first, document everything.
Subdomain enumeration, web app testing, network pentesting, malware analysis and EDR evasion. I ask one question: what would an attacker do with this?
Windows event log hunting, endpoint detection with Velociraptor + Sysmon, malware analysis, incident response. I follow the artifacts to rebuild the timeline.
Python security tools from scratch, Bash and PowerShell automation, n8n pipelines, API integrations. If I do it manually twice, I script it.
Linux and Active Directory internals, AWS/Azure/GCP security, lab deployment. Every system has a trust model — I find where it's assumed but not enforced.
Breaking down concepts, documenting labs, and sharing what I learn while it's still fresh.
A full walkthrough of deploying Velociraptor as a DFIR server on Kali Linux with a Windows 10 client — what worked, what didn't, and what I learned about endpoint visibility.
Coming SoonI built an intentionally vulnerable Flask app and attacked every vulnerability myself. What SQLi, XSS, and IDOR actually look like in a real codebase — and how to fix them.
Coming SoonIAM privilege escalation, public S3 buckets, open security groups — I built a scanner to find these. What's most commonly exposed, and why attackers love cloud environments.
Open to internships, freelance security work, bug bounty teams, CTF collabs, and anyone building something interesting in the security space.