◈ RECON CONSOLE
INTERFACE —
HOSTS0
GATEWAY
UPTIME00:00:00
PORTFOLIO DEMO · SYNTHETIC DATA · ⓘ
SONAR — LAN SWEEP 0 CONTACTS
SCANNING…
◇ AI ANALYZER
Awaiting data…
ROUTER / ISP INTEL ⟳ LOOKUP
LAN 0
WIFI 0
BLE 0
IPv4MACVENDORHOSTNAMESEEN
ROUTER ⇄ ENDPOINT LINK
TRAFFIC TELEMETRY
▲ TX SENT0 B
▼ RX RECEIVED0 B
PACKETS CAPTURED0
EVENT STREAM 0
✦ AI ANALYSIS — ASK ABOUT YOUR NETWORK
☣ THREAT INTEL — VirusTotal · ANY.RUN · Hybrid Analysis
Check any indicator against VirusTotal, ANY.RUN & Hybrid Analysis. Files are hashed in your browser — only the SHA-256 is sent. Set VT_API_KEY / HYBRID_ANALYSIS_KEY (or serve --vt-key) for inline verdicts.
DETAIL
⌗ NMAP SCAN · netrecon port scan
idle
No scan results yet.
Pick a target and hit SCAN — open ports appear here as netrecon finds them.

◈ RECON CONSOLE

The web console for netrecon — an open-source Python network reconnaissance & monitoring toolkit. Live host discovery, port scanning, per-device drill-down, ARP-spoof MITM traffic interception, passive flow/DNS capture, and an on-device analyzer — all in one operator UI, running on your real network via the netrecon engine.

WHAT IT DOES

Polls a local capture engine (bettercap's REST API) to render a live operations picture: a sonar radar of discovered hosts, per-device drill-down with vendor/OS/open-port intel, a WiFi channel-activity chart, router↔endpoint link telemetry with a live bytes/sec graph, a Zenmap-style port scanner, and one-click scoped actions (ARP-spoof + filtered sniff) for authorized MITM diagnostics. An on-device heuristic analyzer writes a plain-English risk assessment — no data leaves the box.

ARCHITECTURE

1Engine — netrecon (Python): concurrent ping/ARP discovery, async TCP port scan, raw-socket flow/DNS capture, and Scapy-based ARP-spoof MITM. No admin needed for the core scan.
2APInetrecon serve hosts this console and a local REST API (session, hosts, per-IP traffic, events, MITM control, AI) over a SQLite asset inventory.
3UI — a single self-contained HTML/JS console (zero framework) polling every 2s: canvas radar & charts, drill-down drawer, port scanner, and an AI analyst tab.
4SIEMnetrecon ingest pulls Suricata/Zeek logs into the store; netrecon alerts surfaces IDS detections. Roadmap: threat-intel enrichment + anomaly scoring.

SKILLS DEMONSTRATED

Recon / Nmap-class scanningMITM / ARP-spoofWiFi/BLE reconPenTest+
Network monitoringDetection engineeringMITRE ATT&CK mappingSIEM designCySA+
Go build-from-source (Windows/cgo)REST API integrationCanvas data-vizPowerShell toolingOn-device LLM/heuristics

TECH

Python · asyncio · Scapy · Npcap · SQLite · stdlib http.server · vanilla HTML/JS/Canvas · Anthropic API · (SIEM: Suricata · Zeek · ntfy)

BUILT BY

Terrill Hilliard — IT Support & Security Operations · M.S. Cybersecurity · CySA+ / PenTest+ / ISC² CC

⚖ Reconnaissance & MITM features are for networks you own or are authorized to test. This public demo uses synthetic data only.