Learn reconnaissance, hands-on

See exactly how a security assessment
is run — and why.

ReconLab is an interactive, educational reconnaissance lab. Point it at a domain or IP you own, prove ownership, and watch real security tools execute stage by stage — each one explained before it runs and interpreted after.

reconlab — stage 2 · tls_certificate_audit
$ internal:tls example.com:443
Protocol            : TLSv1.3
Issuer              : Let's Encrypt
Valid to            : Aug 14 2026
Days until expiry   : 64
Self-signed         : false
verdict ▸ NEGATIVE — transport security is healthy

What makes it a lab, not just a scanner

The goal is understanding. Each step is a small lesson in offensive recon and defensive hardening.

Authorization first

Every scan begins with domain-ownership verification (DNS TXT, file, meta tag, WHOIS email) or admin approval. Passive recon is free; active scans are gated.

Stage by stage

A guided pipeline walks you from passive recon to reporting — one tool at a time, in the right order.

Explained, not magic

Before each tool runs you see why it runs, what it does, and how to read the result as positive or negative.

Real tools, live output

Watch the actual command and its streaming output in a terminal, then get an automatic interpretation panel.

Extensible registry

Admins add, reorder, or remove tools and stages from a panel — the pipeline is data, not hard-coded.

Findings & remediation

Results roll up into a severity-ranked report with OWASP/CWE/MITRE links and fix guidance.

The pipeline

0 · Pre-flight1 · Passive Recon2 · Active Discovery3 · Enumeration4 · Vuln Assessment5 · Reporting

Stage 0

Pre-flight

Validate the target, confirm scope, verify you are authorized to scan it.

Stage 1

Passive Recon

WHOIS, DNS records, subdomains, certificate transparency — no packets to the target.

Stage 2

Active Discovery

Live-host probing, screenshots, TLS audit, port & service detection.

Stage 3

Enumeration

Content discovery, parameters, security headers, deep TLS configuration.

Stage 4

Vuln Assessment

Template & signature scanners — CVEs, misconfigurations, exposures.

Stage 5

Reporting

Findings by severity, OWASP/CWE mapping, remediation guidance, export.

Ready to look under the hood?

Sign in, verify a domain you control, and start learning.

Sign in to ReconLab →

ReconLab · hosted at sentinel.radiatus.com · Only scan systems you own or are explicitly authorized to test.