finds.dev← search

// the find

nahamsec/lazyrecon

★ 2,035 · Shell · updated Aug 2021

This script is intended to automate your reconnaissance process in an organized fashion

LazyRecon is a Bash script that chains the usual recon steps for one domain: subdomain enumeration through Sublist3r, certspotter, cert.sh and massdns brute force, then live-host probing, screenshots, Wayback mining, nmap and dirsearch. It bundles the output into an HTML report in a dated folder. It is aimed at people doing authorized bug bounty or pentest recon who would rather run one command than wire the tools together by hand.

The HTML report is the most useful part. It is searchable by string, endpoint, response size and status code, which goes beyond what most glue scripts bother with. Dirsearch runs against up to 10 subdomains at once, and the -e flag for excluding out-of-scope hosts is a sensible default to have in a tool like this. The Wayback step pulls out JS files, .php/.jsp/.aspx URLs and a parameter wordlist, which are the outputs people actually reach for next.

The last push was August 2021, so anything that depends on upstream APIs, certificate-transparency endpoints or tool output formats has had five years to drift. The README still sends you to the bbht repo for the install script, and most of the work is delegated to external binaries (massdns, Sublist3r, dirsearch, Go, screenshot tooling), so the first session is usually dependency hunting. The whole tool is one shell script, and the README says nothing about how failures in those dependencies are handled. It also warns that it generates a lot of traffic and was written for personal use, and beyond -e it does not describe any rate limiting or scope controls you could rely on.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →