Skip to main content

vamp-passive-recon

Passive Recon & Attack Surface Mapping Engine — VampSecure Labs


Overview

vamp-passive-recon is a modular passive reconnaissance tool that discovers subdomains, maps the external attack surface, and audits HTTP security headers — entirely through open-source intelligence sources, without sending a single packet directly to the target during enumeration.

The engine queries eight OSINT sources concurrently, deduplicates and validates results, and runs an Attack Surface Management (ASM) analysis phase that examines Certificate Transparency logs, GitHub dorks, and exposed infrastructure metadata. An optional Shodan enrichment phase appends service fingerprints and known CVEs to live hosts.


Features

  • Eight concurrent OSINT sources: crt.sh, AlienVault OTX Passive DNS, HackerTarget, Wayback Machine, AnubisDB, urlscan.io, RapidDNS, BufferOver
  • ASM phase: Certificate Transparency analysis, GitHub dork enumeration (requires GITHUB_TOKEN), exposed infrastructure detection
  • HTTP security header audit per active host: CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Permissions-Policy, Server information leakage, Set-Cookie flag analysis
  • Optional Shodan enrichment for service fingerprinting and CVE correlation
  • Scope enforcement via --allowed-domains to restrict analysis to authorized targets
  • Subdomain export for use as input to other VSL tools (e.g., vamp-subdomain-takeover)
  • Three output formats: Rich console, JSON, HTML

Requirements

Python 3.11+
aiohttp >= 3.9.0
rich >= 13.7.0

Install dependencies:

pip install -r requirements.txt

Installation

git clone https://github.com/belky-me/vamp-passive-recon.git
cd vamp-passive-recon
pip install -r requirements.txt

Configuration

Variable Purpose Required
OTX_API_KEY AlienVault OTX Passive DNS enrichment Optional — increases OTX data volume
GITHUB_TOKEN GitHub dork queries in the ASM phase Optional — required for GitHub ASM
export OTX_API_KEY=your_otx_key
export GITHUB_TOKEN=your_github_token

Usage

python vamp_passive_recon.py -d DOMAIN [OPTIONS]

Required:
  -d, --domain DOMAIN            Target apex domain to enumerate

Scope:
      --allowed-domains DOM,...  Comma-separated list of domains to include in header analysis
                                 (default: target domain only)

Analysis control:
      --no-headers               Skip the HTTP security header audit phase
      --no-asm                   Skip the ASM (attack surface mapping) phase
      --max-hosts N              Maximum hosts to probe in header analysis (default: 15)
      --concurrency N            Concurrent OSINT source queries (default: 5)

Enrichment:
      --shodan-key API_KEY       Shodan API key for service fingerprinting

Output:
      --json FILE                Write findings to JSON
      --html FILE                Generate standalone HTML report
      --subs-out FILE            Write subdomain list only (one per line)
      --quiet                    Suppress console output (useful for piping)

Examples

Basic passive recon of a target domain:

python vamp_passive_recon.py -d example.com

Full recon with ASM phase and HTML report:

python vamp_passive_recon.py -d example.com --json recon.json --html report.html

Export subdomain list as input for the subdomain takeover scanner:

python vamp_passive_recon.py -d example.com --subs-out subdomains.txt --no-headers --no-asm
python vamp_subdomain_takeover.py -d example.com -f subdomains.txt

Recon with Shodan enrichment and restricted header analysis scope:

python vamp_passive_recon.py -d example.com \
  --allowed-domains example.com,api.example.com \
  --shodan-key YOUR_KEY \
  --html full_report.html

Output Formats

Format How to enable Description
Console Default Rich panels: subdomain table, ASM findings, header audit summary
JSON --json FILE All findings with source attribution, header scores, and ASM data
HTML --html FILE Standalone report with tabbed sections for each analysis phase
Subdomains --subs-out FILE Plain text subdomain list for pipeline chaining

Exit Codes

Code Meaning CI/CD usage
0 Recon complete — no high-severity header or ASM findings Pass gate
1 Moderate findings (missing security headers, minor exposure) Review recommended
2 High-severity ASM findings or critical header misconfigurations Fail gate

Analysis Phases

Phase Sources / Actions
1. Subdomain enumeration crt.sh, OTX, HackerTarget, Wayback, AnubisDB, urlscan.io, RapidDNS, BufferOver
2. ASM analysis Certificate Transparency deep scan, GitHub dorks, exposed service detection
3. Header audit HEAD request per active host — security header presence and configuration
4. Shodan enrichment Port scan results, service banners, CVE annotations (optional)

Part of VampSecure Labs Toolkit

vamp-passive-recon is part of the VampSecure Labs Security Research Toolkit — a collection of professional-grade, self-hosted security assessment tools.

Tool Purpose
vamp-forticheck Multi-vendor edge device CVE scanner
vamp-cve-oracle CVE intelligence and RBVM engine
vamp-passive-recon Passive recon and attack surface mapping
vamp-subdomain-takeover Subdomain takeover vulnerability scanner
vamp-cloud-enum Cloud storage bucket enumerator
vamp-orchestrator Multi-tool assessment orchestrator

© VampSecure Studios — VampSecure Labs Security Research Division
For authorized security assessments only. Unauthorized use is prohibited.

Metadata

Release files for vamp-passive-recon 1.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vamp-passive-recon 1.2.0
File Size Uploaded
vamp_passive_recon-1.2.0.tar.gz 42.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vamp-passive-recon 1.2.0
File Interpreter ABI Platform
vamp_passive_recon-1.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 85.0 kB

Release files / vamp_passive_recon-1.2.0.tar.gz

Download URL vamp_passive_recon-1.2.0.tar.gz
Size 42.5 kB
Tags Source
SHA-256 checksum
How to use checksums
bffabcb9c56e6f30d4465d77cfe51fa5b7b4404f43337743e1ef31605df3e8f7
BLAKE2b-256 checksum
How to use checksums
94a22dc86db26fe7863aa87fddc7f8951cf4c1dbce527500777ca1ab60a22777
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.6

Release files / vamp_passive_recon-1.2.0-py3-none-any.whl

Download URL vamp_passive_recon-1.2.0-py3-none-any.whl
Size 42.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
9dd4f92a241dacd13b49f408d43925a0425c63ccc6b83f6e950b7f7fcb22f969
BLAKE2b-256 checksum
How to use checksums
c0e0c160497dc680c458421e8e8ad251dc4f12324e936ab4931c317f95876b3c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.6

Release history Release notifications | RSS feed

1.3.0

2 release files

This release

1.2.0 This release

2 release files

1.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page