osint-recon v0.5.0
Passive OSINT reconnaissance framework in Rust — for authorized security assessments only.
Highlights
Modules (10)
| Command | What it does | ATT&CK |
|---|---|---|
subdomain |
Passive subdomain enum (crt.sh + hackertarget fallback) | T1590 |
dns |
DNS records via DoH (A, AAAA, MX, NS, TXT) | T1590 |
asn |
IP → ASN / AS name / prefix (Team Cymru over DoH, keyless) | T1590.001 |
ct |
Certificate transparency history, CA stats, expiring certs (crt.sh) | T1596.003 |
ghdork |
GitHub exposure dorks — repos/users keyless, code-search with token | T1593.003 |
br cnpj |
🇧🇷 Brazilian company lookup (BrasilAPI + ReceitaWS fallback) | T1591 |
br cep |
🇧🇷 Brazilian postal code → address (+ coordinates) | T1591 |
br dorks |
🇧🇷 Brazilian dork pack — ready-to-open Google/Shodan URLs | T1593 |
tech |
Technology fingerprint (headers + HTML signatures) | T1592 |
email |
Email harvesting from public pages | T1589.002 |
metadata |
PDF metadata extraction (author, creator tool, dates) | T1593 |
full |
All domain modules combined, JSON + CSV export | — |
New in v0.5.0 — Brazilian context module (br)
br cnpj— company lookup via keyless BrasilAPI with ReceitaWS fallback (3 req/min respected with per-source throttling). Validates the classic numeric format with mod-11 check digits and the new alphanumeric CNPJ format valid since July 2026.br cep— address resolution via BrasilAPI v2 (coordinates when available) with ViaCEP fallback.br dorks— Brazilian OSINT dork pack (exposed SQL/backups on .br/.com.br, gov.br/mil.br docs, PowerBI, WhatsApp/Telegram indexation, Shodancountry:"BR"). No scraping — generates ready-to-open URLs for manual use.- LGPD by design (Lei 13.709/2018): public business/address data only — the module never handles personal data (CPF).
Quality
- 37/37 tests passing · clippy
-D warningsclean ·cargo fmtenforced - CI: fmt → clippy → test → build on every push/PR
- Polite by default: 1 req/s rate limiting, per-source throttles, timeouts, retries, graceful degradation
Changelog
- v0.5.0 — Brazilian context module: CNPJ, CEP, BR dork pack
- v0.4.0 — demo GIF,
--stdout/JSONL mode, stdin batch targets, release matrix CI - v0.3.0 — GitHub dorking module (keyless tier + optional token tier with 5 code-search dorks)
- v0.2.0 — ASN & netblock enumeration, certificate transparency history, CI workflow
- v0.1.0 — initial release: 5 modules, CLI, JSON/CSV export