Attack-surface intelligence
Bring together subdomains, DNS, HTTP, ports/services, certificates, crawling, robots/sitemaps and content discovery into one investigation model.
ReconFlow is a methodology-driven security assessment orchestrator built to turn raw attack-surface data into prioritized, evidence-backed investigation paths.
Response behavior differs across captured identities. Validation gate required.
ReconFlow is designed to connect discovery, application understanding, behavioral signals and validation instead of treating them as isolated scans.
Bring together subdomains, DNS, HTTP, ports/services, certificates, crawling, robots/sitemaps and content discovery into one investigation model.
Inventory endpoints and parameters, inspect API contracts, JavaScript signals, CORS, HTTP methods and security posture.
Model application states, workflows, invariants and authorization relationships from authorized browser captures.
Normalize dynamic values and compare authorization, cache and response differences to surface investigation leads.
Track findings through evidence, hypotheses, validation gates and review queues rather than promoting guesses to confirmed vulnerabilities.
The reasoning layer prioritizes what to investigate next using application context, methodology coverage and assurance gaps.
A single loop for authorized security research.
Map the known and unknown surface.
Build an application and behavior model.
Use context and evidence to choose the next test.
Keep high-impact findings behind explicit evidence gates.
ReconFlow's automated behavioral execution is intentionally bounded. The system is designed to assist security researchers without turning candidate signals into uncontrolled exploit traffic.
FINAL STABILITY AUDIT PASS
ReconFlow is being built for researchers who want less command chaining and more intelligent investigation.
Connect with the builder on LinkedIn or copy the project link.