27 scanners · AI-native · multi-identity

Find what single-session
scanners can't see.

Multi-identity access-control testing, AI-validated findings, and a report your team will actually read.

27
Scanners
6
Profiles
10
OWASP Categories
scan complete
2 critical found
27Scanner Modules
5AI Features
2AI Providers
10OWASP Top 10
6Scan Profiles
4Report Formats

Why Security Teams Choose ReconX

One tool. Full OWASP coverage. AI that actually reduces triage work instead of adding to it.

AC

Multi-Identity Access Control Testing

Capture two or more authenticated sessions and automatically detect broken object- and function-level authorization (BOLA/BFLA) that single-session scanners cannot see.

27

27 Scanner Modules

Comprehensive coverage from SQL injection to multi-tenant access control.

AI

Multi-LLM AI Engine

Supports Claude (Anthropic) and GPT-4/GPT-4o (OpenAI), plus any OpenAI-compatible endpoint including local and self-hosted models.

RP

Professional Reports

Generate HTML, PDF, DOCX, and JSON reports with executive summaries and OWASP coverage mapping.

OW

OWASP Top 10

Full coverage of every OWASP Top 10 (2021) vulnerability category.

SP

Scan Profiles

Quick, standard, deep, API-only, OWASP Top 10, and passive scan modes.

FP

Deterministic FP Verification

Structural verification runs on every scan with no AI key required. Likely false positives (empty-body exposures, SPA catch-alls, unproven CVE matches) are downgraded and labelled, never shipped as a false "confirmed".

AI

AI False Positive Validation

Optional AI review adds a second pass of noise reduction on top of the deterministic layer. Confirmed findings are never downgraded.

DR

Deep Subdomain Recon

Exhaustive enumeration via CT logs, subfinder, and label, environment, and version permutations discovers the full estate, then scans every live host, not just the apex.

AP

Attack Path Analysis

AI maps how vulnerabilities chain together for maximum impact.

PL

Smart Payloads

Context-aware payload generation that adapts to the target.

EX

Extensible

Drop-in Python scanner plugins and no-code YAML check templates extend coverage without touching the core.

27 Security Scanner Modules

SQL injection, XSS, SSRF, JWT flaws, multi-identity access control, and 22 more -- plus subdomain enumeration, port scanning, and tech fingerprinting before scanning starts. Each module runs multiple detection techniques, not just pattern matching.

ACAccess Control (BOLA/BFLA)Multi-identity tenant/object isolation and privilege-escalation testing
DBSQL InjectionError-based, blind boolean, and blind time-based SQLi
XSXSS ScannerReflected cross-site scripting via parameter injection
SRSSRF ScannerServer-side request forgery, in-band and out-of-band
CICommand InjectionOS command injection, in-band and out-of-band
XEXXE ScannerXML external entity injection, in-band and out-of-band
TISSTI DetectionServer-side template injection (Jinja2, Twig, Freemarker)
NQNoSQL InjectionMongoDB operator and JavaScript injection
IOIDOR ScannerInsecure direct object references and ID enumeration
JWJWT AnalysisAlgorithm confusion, weak signing keys, forged tokens
CFCSRF DetectionMissing tokens on state-changing forms
COCORS MisconfigWildcard origins and credential exposure
CJClickjackingMissing X-Frame-Options / frame-ancestors
FUFile UploadExtension and content-type bypass detection
DTDirectory TraversalPath traversal via ../ sequences in parameters
OROpen RedirectUnvalidated redirects via URL parameters
APAPI SecurityAuth bypass, rate limiting, verbose error disclosure
HDSecurity HeadersMissing CSP, HSTS, X-Content-Type-Options, and more
CKCookie SecurityMissing Secure, HttpOnly, and SameSite flags
SSSession SecuritySession fixation, predictable tokens, weak invalidation
TLSSL/TLS AnalysisCertificate issues, weak ciphers, protocol versions
STSubdomain TakeoverDangling DNS records pointing to unclaimed services
SFSensitive FilesExposed configs, backups, source code, admin panels
HMHTTP MethodsDangerous methods enabled (PUT, DELETE, TRACE)
INInfo DisclosureServer version leaks, debug info, stack traces
EMEmail SecuritySPF, DKIM, and DMARC misconfigurations
TCTemplate ChecksYAML-based checks for CVEs, exposures, and misconfigs

AI That Does More Than Write Summaries

Most tools slap an LLM on top of raw scanner output. ReconX uses AI at five stages: analysis, validation, attack path mapping, payload generation, and reporting.

01

Intelligent Analysis

AI analyzes raw scanner output to identify patterns humans might miss, correlating findings across modules to uncover complex vulnerability chains.

02

False Positive Validation

Machine learning models evaluate each finding against known patterns, reducing noise by up to 60% and letting you focus on real threats.

03

Attack Path Mapping

AI constructs exploitation chains showing how individual vulnerabilities combine for maximum impact, from initial access to data exfiltration.

04

Smart Payload Generation

Context-aware payload generation that adapts to the target application, bypassing WAFs and custom input validation.

05

Executive Reporting

AI-generated executive summaries translate technical findings into business impact language for stakeholder communication.

Scan Profiles

Choose the right level of depth for every engagement.

Quick

Headers, SSL, sensitive files, and email security in under a minute

6 modules

Standard

Balanced default coverage for routine testing

All 27 modules

Deep

Maximum depth with browser-based crawling for JS-heavy apps

All 27 modules

API Only

Focused on REST/GraphQL auth, injection, and CORS

8 modules

OWASP Top 10

Scoped to the OWASP Top 10 (2021) categories

13 modules

Passive

No active probing -- safe for production systems

4 modules

Start Scanning in 60 Seconds

Run ReconX from the CloudDrove container image and get a full report on your first scan.

docker run ghcr.io/clouddrove/reconx scan example.com -y