Skip to main content

vamp-passive-recon

Passive Recon & Attack Surface Mapping Engine — VampSecure Labs


Overview

vamp-passive-recon is a modular passive reconnaissance tool that discovers subdomains, maps the external attack surface, and audits HTTP security headers — entirely through open-source intelligence sources, without sending a single packet directly to the target during enumeration.

The engine queries eight OSINT sources concurrently, deduplicates and validates results, and runs an Attack Surface Management (ASM) analysis phase that examines Certificate Transparency logs, GitHub dorks, and exposed infrastructure metadata. An optional Shodan enrichment phase appends service fingerprints and known CVEs to live hosts.


Features

  • Eight concurrent OSINT sources: crt.sh, AlienVault OTX Passive DNS, HackerTarget, Wayback Machine, AnubisDB, urlscan.io, RapidDNS, BufferOver
  • ASM phase: Certificate Transparency analysis, GitHub dork enumeration (requires GITHUB_TOKEN), exposed infrastructure detection
  • HTTP security header audit per active host: CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Permissions-Policy, Server information leakage, Set-Cookie flag analysis
  • Optional Shodan enrichment for service fingerprinting and CVE correlation
  • Scope enforcement via --allowed-domains to restrict analysis to authorized targets
  • Subdomain export for use as input to other VSL tools (e.g., vamp-subdomain-takeover)
  • Three output formats: Rich console, JSON, HTML

Requirements

Python 3.11+
aiohttp >= 3.9.0
rich >= 13.7.0

Install dependencies:

pip install -r requirements.txt

Installation

git clone https://github.com/belky-me/vamp-passive-recon.git
cd vamp-passive-recon
pip install -r requirements.txt

Configuration

Variable Purpose Required
OTX_API_KEY AlienVault OTX Passive DNS enrichment Optional — increases OTX data volume
GITHUB_TOKEN GitHub dork queries in the ASM phase Optional — required for GitHub ASM
export OTX_API_KEY=your_otx_key
export GITHUB_TOKEN=your_github_token

Usage

python vamp_passive_recon.py -d DOMAIN [OPTIONS]

Required:
  -d, --domain DOMAIN            Target apex domain to enumerate

Scope:
      --allowed-domains DOM,...  Comma-separated list of domains to include in header analysis
                                 (default: target domain only)

Analysis control:
      --no-headers               Skip the HTTP security header audit phase
      --no-asm                   Skip the ASM (attack surface mapping) phase
      --max-hosts N              Maximum hosts to probe in header analysis (default: 15)
      --concurrency N            Concurrent OSINT source queries (default: 5)

Enrichment:
      --shodan-key API_KEY       Shodan API key for service fingerprinting

Output:
      --json FILE                Write findings to JSON
      --html FILE                Generate standalone HTML report
      --subs-out FILE            Write subdomain list only (one per line)
      --quiet                    Suppress console output (useful for piping)

Examples

Basic passive recon of a target domain:

python vamp_passive_recon.py -d example.com

Full recon with ASM phase and HTML report:

python vamp_passive_recon.py -d example.com --json recon.json --html report.html

Export subdomain list as input for the subdomain takeover scanner:

python vamp_passive_recon.py -d example.com --subs-out subdomains.txt --no-headers --no-asm
python vamp_subdomain_takeover.py -d example.com -f subdomains.txt

Recon with Shodan enrichment and restricted header analysis scope:

python vamp_passive_recon.py -d example.com \
  --allowed-domains example.com,api.example.com \
  --shodan-key YOUR_KEY \
  --html full_report.html

Output Formats

Format How to enable Description
Console Default Rich panels: subdomain table, ASM findings, header audit summary
JSON --json FILE All findings with source attribution, header scores, and ASM data
HTML --html FILE Standalone report with tabbed sections for each analysis phase
Subdomains --subs-out FILE Plain text subdomain list for pipeline chaining

Exit Codes

Code Meaning CI/CD usage
0 Recon complete — no high-severity header or ASM findings Pass gate
1 Moderate findings (missing security headers, minor exposure) Review recommended
2 High-severity ASM findings or critical header misconfigurations Fail gate

Analysis Phases

Phase Sources / Actions
1. Subdomain enumeration crt.sh, OTX, HackerTarget, Wayback, AnubisDB, urlscan.io, RapidDNS, BufferOver
2. ASM analysis Certificate Transparency deep scan, GitHub dorks, exposed service detection
3. Header audit HEAD request per active host — security header presence and configuration
4. Shodan enrichment Port scan results, service banners, CVE annotations (optional)

Part of VampSecure Labs Toolkit

vamp-passive-recon is part of the VampSecure Labs Security Research Toolkit — a collection of professional-grade, self-hosted security assessment tools.

Tool Purpose
vamp-forticheck Multi-vendor edge device CVE scanner
vamp-cve-oracle CVE intelligence and RBVM engine
vamp-passive-recon Passive recon and attack surface mapping
vamp-subdomain-takeover Subdomain takeover vulnerability scanner
vamp-cloud-enum Cloud storage bucket enumerator
vamp-orchestrator Multi-tool assessment orchestrator

© VampSecure Studios — VampSecure Labs Security Research Division
For authorized security assessments only. Unauthorized use is prohibited.

Metadata

Release files for vamp-passive-recon 1.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vamp-passive-recon 1.1.0
File Size Uploaded
vamp_passive_recon-1.1.0.tar.gz 39.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vamp-passive-recon 1.1.0
File Interpreter ABI Platform
vamp_passive_recon-1.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 79.2 kB

Release files / vamp_passive_recon-1.1.0.tar.gz

Download URL vamp_passive_recon-1.1.0.tar.gz
Size 39.6 kB
Tags Source
SHA-256 checksum
How to use checksums
33440e24e5a75be156b2dde304be708a636995d744cedfa55bf4758570294d0d
BLAKE2b-256 checksum
How to use checksums
733703d78908b33055b6fb93a5e8277193f8a879c48a7c8aea410315fbf43be5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / vamp_passive_recon-1.1.0-py3-none-any.whl

Download URL vamp_passive_recon-1.1.0-py3-none-any.whl
Size 39.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
01eea377338ed8a84545d54e7e9c37de472815969960ccda05ee0f6828ce3c06
BLAKE2b-256 checksum
How to use checksums
3e6dd97b8e08ec034e193a1fbea25e095f3d53c3f0456a66e7a59c966f10daeb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release history Release notifications | RSS feed

1.3.0

2 release files

1.2.0

2 release files

This release

1.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page