A comprehensive OSINT toolkit for cybersecurity professionals, penetration testers, bug bounty hunters, and digital forensics investigators.
- π¦ Package hardening β secrets (
config.py, Shodan JSON) stay out of git and PyPI wheels - β¨οΈ Interactive pause β About / Connect / Theme wait for Enter before redrawing the menu
- π Shodan keys outside the tree β
~/.config-vritrasecz/only (legacy in-treeconfig.pyread-only) - π Docs sync β README, layout, and install paths match the
bloodrecon/package
v2.0.1 / v2.0.0 / v1.2.0 release notes
v2.0.1 β single professional palette, menu alignment fixes, --list, interactive aliases. See CHANGELOG.md.
v2.0.0 β themeable redesign, package entry points, registry architecture, and module hardening.
v1.2.0 β Shodan --shodan-api CLI setup and ~/.config-vritrasecz/bloodrecon-shodan.json storage.
- π― Overview
- β¨ Key Features
- π οΈ Installation
- π Usage
- π§ Modules
- π API Key Configuration
- πΈ Screenshots
- π Folder Structure
- π§ͺ Testing
- βοΈ Legal Disclaimer
- π¨βπ» Author
- π€ Contributing
- π License
BloodRecon is an OSINT (Open Source Intelligence) framework with 34 specialized modules for reconnaissance and intelligence gathering. It ships as a Python package with an interactive menu and a full CLI.
π 34 specialized OSINT modules
π Network & infrastructure β IP, DNS, WHOIS, SSL, ports, ASN, ISP
π Web application recon β headers, robots, directories, JS endpoints, tech stack
π₯ People & social intel β GitHub, username checks, phone analysis
π Document & metadata β EXIF, document properties
π Search & discovery β Google dorking, Wayback, Common Crawl, leaks
π Communication intel β email validation, temp-mail detection
π‘οΈ Threat intelligence β Shodan host lookup
π¨ Interactive CLI β examples, colored output, --list / --about / --connect
pip install bloodrecon
bloodrecon --interactive
python -m bloodrecon --interactive
bloodrecon --dns google.comgit clone https://github.com/MrHacker-X/BloodRecon.git
cd BloodRecon
# editable install (dev)
pip install -e ".[dev]"
# or runtime only
pip install -r requirements.txt
pip install .
bloodrecon --interactive # console script
python -m bloodrecon --interactive
python bloodrecon.py --interactive # legacy launcherpkg update && pkg upgrade
pkg install git python
git clone https://github.com/MrHacker-X/BloodRecon.git
cd BloodRecon
pip install .
bloodrecon --interactivecolorama==0.4.6
dnspython==2.7.0
mmh3==5.1.0
phonenumbers==9.0.10
Pillow==11.3.0
requests==2.32.4
urllib3==2.5.0
whois==1.20240129.2
The
shodanclient library is not required β BloodRecon talks to the Shodan REST API viarequests.
bloodrecon # default: interactive menu
bloodrecon --interactive # sameMenu shortcuts: module number Β· [a] About Β· [c] Connect Β· [t] Palette Β· ? / help list Β· 0 / q quit.
# Core examples
bloodrecon --ip 8.8.8.8
bloodrecon --whois example.com
bloodrecon --dns google.com
bloodrecon --headers https://example.com
bloodrecon --social username123
bloodrecon --email test@example.com
bloodrecon --phone +1234567890
bloodrecon --shodan 8.8.8.8
# Advanced
bloodrecon --dork "site:example.com filetype:pdf"
bloodrecon --subdomains example.com
bloodrecon --ssl example.com:443
bloodrecon --dir-brute https://example.com
bloodrecon --js-endpoints https://example.com
bloodrecon --ip-scan 192.168.1.0/24
bloodrecon --wayback example.com
bloodrecon --github octocat
# Meta
bloodrecon --list # all modules / flags / examples
bloodrecon --about
bloodrecon --connect
bloodrecon --themes # active palette
bloodrecon --no-color
bloodrecon --version
bloodrecon --helppython bloodrecon.py β¦ and python -m bloodrecon β¦ accept the same flags.
34 modules from bloodrecon/modules/registry.py:
| Module | Description | Example |
|---|---|---|
| IP Lookup | Geolocation, ISP, ASN | --ip 8.8.8.8 |
| WHOIS Lookup | Domain registration / ownership | --whois example.com |
| DNS Lookup | A, AAAA, MX, TXT, NS | --dns google.com |
| Reverse DNS | PTR lookup | --reverse 8.8.8.8 |
| Port Scanner | Open ports / services | --ports scanme.nmap.org |
| SSL Scanner | Certificate & TLS assessment | --ssl example.com:443 |
| IP Range Scanner | Active hosts in a range | --ip-scan 192.168.1.0/24 |
| ASN Resolver | ASN β IP ranges | --asn AS15169 |
| ISP Tracker | IP β ISP | --isp 8.8.8.8 |
| Module | Description | Example |
|---|---|---|
| HTTP Headers | Security headers | --headers https://example.com |
| Robots Scanner | robots.txt |
--robots https://example.com |
| Directory Bruteforce | Path discovery | --dir-brute https://example.com |
| Sitemap Parser | XML sitemaps | --sitemap https://example.com |
| JS Endpoint Scanner | API endpoints in JS | --js-endpoints https://example.com |
| Favicon Hash | mmh3 favicon fingerprint | --favicon https://example.com |
| Tech Fingerprint | Stack identification | --tech https://example.com |
| URL Analyzer | URL structure / risk signals | --url https://example.com |
| User-Agent Detector | UA string analysis | --useragent "Mozilla/5.0..." |
| Module | Description | Example |
|---|---|---|
| Social Checker | Username across platforms | --social johndoe |
| GitHub Intel | User / repo intel | --github octocat |
| Phone Intel | Carrier / region | --phone +14155552671 |
| Email Validator | Format + domain checks | --email user@example.com |
| Temp Email Checker | Disposable mail detection | --temp-email test@10minutemail.com |
| Module | Description | Example |
|---|---|---|
| EXIF Extractor | Image metadata | --exif /path/to/photo.jpg |
| Doc Metadata | PDF / Office metadata | --metadata /path/to/document.pdf |
| Module | Description | Example |
|---|---|---|
| Google Dorking | Advanced search queries | --dork "site:example.com filetype:pdf" |
| Subdomain Finder | Subdomain enumeration | --subdomains example.com |
| Wayback Machine | Archive.org history | --wayback example.com |
| Common Crawl | CC index search | --common-crawl example.com |
| Pastebin Search | Paste dumps | --pastebin password |
| Leak Search | Breach / leak signals | --leak user@example.com |
| Google Drive Leaks | Public Drive finds | --gdrive folderID |
| Maps Parser | Google Maps link parse | --maps "https://maps.google.com/..." |
| Module | Description | Example |
|---|---|---|
| Shodan Lookup | Host intel via Shodan API | --shodan 8.8.8.8 |
# one-time setup
bloodrecon --shodan-api "your_shodan_api_key_here"
# then use
bloodrecon --shodan 8.8.8.8- Storage:
~/.config-vritrasecz/bloodrecon-shodan.json - Directory is created automatically; new keys replace old ones
- Get a key at account.shodan.io
# environment variable
export SHODAN_API_KEY="your_api_key_here"
bloodrecon --shodan 8.8.8.8Optional file (outside the package tree):
# ~/.config-vritrasecz/config.py
SHODAN_API_KEY = 'your_shodan_api_key_here'If no key is configured, interactive mode prompts and saves it.
BloodRecon/
βββ bloodrecon.py # Legacy launcher
βββ pyproject.toml # Package / PyPI metadata
βββ setup.py # Wheel build hook (excludes local secrets)
βββ MANIFEST.in
βββ requirements.txt
βββ LICENSE
βββ README.md
βββ CHANGELOG.md
βββ SECURITY.md
βββ .github/ # CI + issue templates
βββ tests/ # Offline pytest suite
βββ bloodrecon/ # Installable package
βββ __init__.py
βββ __main__.py # python -m bloodrecon
βββ cli.py # Banner, menu, argparse, dispatch
βββ modules/
βββ registry.py # Single source of truth for modules
βββ colors.py
βββ list-imp/
β βββ common.txt # Dir-bruteforce wordlist
β βββ temp_domains.txt # Disposable-mail domains
βββ *.py # 34 OSINT modules
pip install -e ".[dev]"
pytest -q
bloodrecon --version
bloodrecon --help
bloodrecon --list
bloodrecon --temp-email test@10minutemail.com # offline-friendly
bloodrecon --dns google.com # live networkThis tool is for educational use and authorized security testing only.
- Learning OSINT techniques
- Authorized pentests and assessments
- In-scope bug bounty work
- Authorized digital forensics / security research
- Unauthorized surveillance or stalking
- Illegal data collection or privacy violations
- Malicious recon or attack preparation
- Anything that violates applicable law
You are responsible for lawful use in your jurisdiction.
- Fork the repository
- Create a branch (
git checkout -b feature/AmazingFeature) - Commit (
git commit -m 'Add some AmazingFeature') - Push (
git push origin feature/AmazingFeature) - Open a Pull Request
Ideas: bug reports, new modules (add one row in registry.py), docs, tests.
See LICENSE.
β If you found BloodRecon useful, please consider giving it a star!
Made with β€οΈ by Alex Butler
