π¦ Install directly from PyPI
pip install cyber-recon-toolkit
cyber-reconCyber Recon Toolkit is a modular Python-based cybersecurity framework that provides reconnaissance, network analysis, automated security assessment, forensic utilities, and professional report generation through a unified command-line interface.
This toolkit combines multiple reconnaissance, scanning, forensic, and reporting utilities into a single integrated Python platform. It is designed for practical cybersecurity workflows, clean CLI interaction, modular expansion, and evidence-oriented reporting.
- WHOIS Lookup
- DNS Enumeration
- Ping Sweep
- TCP Port Scanner
- Log Analyzer
- Hash Generator
- Phishing URL Checker
- Combined Report Generator
- Automated Security Assessment
- Risk Classification (LOW / MEDIUM / HIGH)
- Executive Summary Generation
- Consolidated Security Reporting
- JSON Assessment Reports
- PDF Assessment Reports
- JSON report export
- CSV report export
- PDF report export
- Timestamped forensic reports
- PDF watermarking
- Consolidated evidence collection
- Cross-module report aggregation
Cyber-Recon-Toolkit/
βββ cyber_recon_toolkit/
β βββ modules/
β β βββ dns_enum.py
β β βββ hash_generator.py
β β βββ log_analyzer.py
β β βββ phishing_checker.py
β β βββ ping_sweep.py
β β βββ port_scanner.py
β β βββ report_generator.py
β β βββ security_assessment.py
β β βββ whois_lookup.py
β βββ __init__.py
β βββ __main__.py
β βββ toolkit.py
βββ README.md
βββ pyproject.toml
βββ requirements.txt
βββ run.sh
βββ screenshots/
βββ reports/
βββ logs/
- Python 3.10 or higher
- Linux-based environment recommended
- Tested on Kali Linux
The toolkit is published on PyPI and can be installed with a single command:
pip install cyber-recon-toolkit
cyber-reconClone the repository for development:
git clone https://github.com/kvr585/Cyber-Recon-Toolkit.git
cd Cyber-Recon-Toolkit
./run.shThe launcher automatically:
- Creates a virtual environment (
.venv) - Activates the environment
- Installs required dependencies
- Starts the toolkit
After installation, launch the toolkit:
cyber-reconOr if running from source:
./run.shStart the toolkit using:
./run.shUsing the launcher ensures the virtual environment and dependencies are configured correctly before execution.
RECON
1. WHOIS Lookup
2. DNS Enumeration
3. Ping Sweep
SCANNING
4. Port Scanner
5. Log Analyzer
UTILITIES
6. Hash Generator
7. Phishing URL Checker
8. Generate Combined Report
ASSESSMENT
10. Automated Security Assessment
SYSTEM
9. Exit (Available from any menu)
- Domain WHOIS lookup
- Registrar information
- Creation and expiration dates
- Domain status
- DNS nameservers
- JSON report generation
- A record lookup
- AAAA record lookup
- MX record lookup
- NS record lookup
- TXT record lookup
- CNAME discovery
- DNS summary output
- JSON report export
- /24 subnet discovery
- Multithreaded ICMP scanning
- Live host detection
- Scan timing
- JSON reporting
- Multithreaded TCP port scanning
- Custom port range support
- Service detection
- Basic banner grabbing
- Progress tracking
- Resolved target IP display
- JSON reporting
- Log file parsing
- Suspicious activity detection
- Error highlighting
- Security event inspection
- JSON export
- MD5 hashing
- SHA1 hashing
- SHA256 hashing
- SHA512 hashing
- Text hashing
- File hashing
- Hash verification
- File integrity checks
- JSON reporting
- URL structure analysis
- Suspicious keyword detection
- IP-based URL detection
- URL length analysis
- HTTPS validation
- Domain extraction checks
The Automated Security Assessment module performs multiple security checks against a target and generates a consolidated report.
Assessment workflow:
- WHOIS Analysis
- DNS Enumeration
- Port Scanning
- Phishing URL Analysis
- Risk Classification
- Executive Summary Generation
- JSON Report Export
- PDF Report Export
The module automatically combines findings from multiple components into a single assessment report for easier review and documentation.
- Aggregates module outputs into combined JSON
- Generates combined CSV reports
- Produces formatted PDF reports
- Adds forensic timestamps
- Includes PDF watermarking
- Allows direct report opening from toolkit
Generated reports are automatically saved inside the reports/ directory.
Supported formats include:
- JSON
- CSV
Generated reports may include:
- Scan results
- DNS findings
- WHOIS information
- Security events
- Forensic summaries
- Timestamps
- Watermarked PDF exports
This project is intended strictly for educational, academic, and authorized security testing purposes only.
Do not use this toolkit against systems, networks, or services without proper authorization.
The developer is not responsible for misuse or unauthorized activities performed using this toolkit.
Veera Bhadhra Rao
Cyber Security Student | Python Developer | Cybersecurity Enthusiast | Open Source Contributor



