Skip to main content

vamp-passive-recon

Passive Recon & Attack Surface Mapping Engine — VampSecure Labs


Overview

vamp-passive-recon is a modular passive reconnaissance tool that discovers subdomains, maps the external attack surface, and audits HTTP security headers — entirely through open-source intelligence sources, without sending a single packet directly to the target during enumeration.

The engine queries eight OSINT sources concurrently, deduplicates and validates results, and runs an Attack Surface Management (ASM) analysis phase that examines Certificate Transparency logs, GitHub dorks, and exposed infrastructure metadata. An optional Shodan enrichment phase appends service fingerprints and known CVEs to live hosts.


Features

  • Eight concurrent OSINT sources: crt.sh, AlienVault OTX Passive DNS, HackerTarget, Wayback Machine, AnubisDB, urlscan.io, RapidDNS, BufferOver
  • ASM phase: Certificate Transparency analysis, GitHub dork enumeration (requires GITHUB_TOKEN), exposed infrastructure detection
  • HTTP security header audit per active host: CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Permissions-Policy, Server information leakage, Set-Cookie flag analysis
  • Optional Shodan enrichment for service fingerprinting and CVE correlation
  • Scope enforcement via --allowed-domains to restrict analysis to authorized targets
  • Subdomain export for use as input to other VSL tools (e.g., vamp-subdomain-takeover)
  • Three output formats: Rich console, JSON, HTML

Requirements

Python 3.11+
aiohttp >= 3.9.0
rich >= 13.7.0

Install dependencies:

pip install -r requirements.txt

Installation

pip install vamp-passive-recon
# o con Homebrew:
brew install vampsecure-labs/labs/vamp-passive-recon
git clone https://github.com/belky-me/vamp-passive-recon.git
cd vamp-passive-recon
pip install -r requirements.txt

Configuration

Variable Purpose Required
OTX_API_KEY AlienVault OTX Passive DNS enrichment Optional — increases OTX data volume
GITHUB_TOKEN GitHub dork queries in the ASM phase Optional — required for GitHub ASM
export OTX_API_KEY=your_otx_key
export GITHUB_TOKEN=your_github_token

Usage

python vamp_passive_recon.py -d DOMAIN [OPTIONS]

Required:
  -d, --domain DOMAIN            Target apex domain to enumerate

Scope:
      --allowed-domains DOM,...  Comma-separated list of domains to include in header analysis
                                 (default: target domain only)

Analysis control:
      --no-headers               Skip the HTTP security header audit phase
      --no-asm                   Skip the ASM (attack surface mapping) phase
      --max-hosts N              Maximum hosts to probe in header analysis (default: 15)
      --concurrency N            Concurrent OSINT source queries (default: 5)

Enrichment:
      --shodan-key API_KEY       Shodan API key for service fingerprinting

Output:
      --json FILE                Write findings to JSON
      --html FILE                Generate standalone HTML report
      --subs-out FILE            Write subdomain list only (one per line)
      --quiet                    Suppress console output (useful for piping)

Examples

Basic passive recon of a target domain:

python vamp_passive_recon.py -d example.com

Full recon with ASM phase and HTML report:

python vamp_passive_recon.py -d example.com --json recon.json --html report.html

Export subdomain list as input for the subdomain takeover scanner:

python vamp_passive_recon.py -d example.com --subs-out subdomains.txt --no-headers --no-asm
python vamp_subdomain_takeover.py -d example.com -f subdomains.txt

Recon with Shodan enrichment and restricted header analysis scope:

python vamp_passive_recon.py -d example.com \
  --allowed-domains example.com,api.example.com \
  --shodan-key YOUR_KEY \
  --html full_report.html

Output Formats

Format How to enable Description
Console Default Rich panels: subdomain table, ASM findings, header audit summary
JSON --json FILE All findings with source attribution, header scores, and ASM data
HTML --html FILE Standalone report with tabbed sections for each analysis phase
Subdomains --subs-out FILE Plain text subdomain list for pipeline chaining

Exit Codes

Code Meaning CI/CD usage
0 Recon complete — no high-severity header or ASM findings Pass gate
1 Moderate findings (missing security headers, minor exposure) Review recommended
2 High-severity ASM findings or critical header misconfigurations Fail gate

Analysis Phases

Phase Sources / Actions
1. Subdomain enumeration crt.sh, OTX, HackerTarget, Wayback, AnubisDB, urlscan.io, RapidDNS, BufferOver
2. ASM analysis Certificate Transparency deep scan, GitHub dorks, exposed service detection
3. Header audit HEAD request per active host — security header presence and configuration
4. Shodan enrichment Port scan results, service banners, CVE annotations (optional)

Part of VampSecure Labs Toolkit

vamp-passive-recon is part of the VampSecure Labs Security Research Toolkit — a collection of professional-grade, self-hosted security assessment tools.

Tool Purpose
vamp-forticheck Multi-vendor edge device CVE scanner
vamp-cve-oracle CVE intelligence and RBVM engine
vamp-passive-recon Passive recon and attack surface mapping
vamp-subdomain-takeover Subdomain takeover vulnerability scanner
vamp-cloud-enum Cloud storage bucket enumerator
vamp-orchestrator Multi-tool assessment orchestrator

© VampSecure Studios — VampSecure Labs Security Research Division
For authorized security assessments only. Unauthorized use is prohibited.


Versión

v1.2.0 — VampSecure Labs Security Research Division

Metadata

Release files for vamp-passive-recon 1.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vamp-passive-recon 1.3.0
File Size Uploaded
vamp_passive_recon-1.3.0.tar.gz 46.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vamp-passive-recon 1.3.0
File Interpreter ABI Platform
vamp_passive_recon-1.3.0-py3-none-any.whl Python 3 none any Details

Total release size: 92.8 kB

Release files / vamp_passive_recon-1.3.0.tar.gz

Download URL vamp_passive_recon-1.3.0.tar.gz
Size 46.4 kB
Tags Source
SHA-256 checksum
How to use checksums
2951f45b7715ce0d418255f8419db1c6312470f9127940fb37f5844293b194c2
BLAKE2b-256 checksum
How to use checksums
aaa3d48fba46846dc84a9fa4e1256de66a2c6f1a95358b406a3f6a78b47320bb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.6

Release files / vamp_passive_recon-1.3.0-py3-none-any.whl

Download URL vamp_passive_recon-1.3.0-py3-none-any.whl
Size 46.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
31236808a4b7f1683b17d2b3f4e1029044bee76d571e3c9502c734cd53f14a54
BLAKE2b-256 checksum
How to use checksums
ea366e5efe4f6325232416904acefe603a2e61c61927ec81840002fe65a38995
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release history Release notifications | RSS feed

This release

1.3.0 This release

2 release files

1.2.0

2 release files

1.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page