{"_id":"@aquibk/reconix","_rev":"6-113c9dc056ea2045f0cf642bacca55ac","name":"@aquibk/reconix","dist-tags":{"latest":"1.1.0"},"versions":{"1.0.0":{"name":"@aquibk/reconix","version":"1.0.0","keywords":["recon","reconnaissance","leak","scanner","threat","intelligence","suite","security","pentest","bug bounty","ethical hacking","cybersecurity","reconix"],"author":{"name":"Aquib Khans"},"license":"ISC","_id":"@aquibk/reconix@1.0.0","maintainers":[{"name":"aquibk","email":"masteraquibkhan@gmail.com"}],"homepage":"https://github.com/AquibPro/reconix","bugs":{"url":"https://github.com/AquibPro/reconix/issues"},"bin":{"reconix":"index.js"},"dist":{"shasum":"b03bc94549677ea7ece4f7bf6e5879c03f27ab58","tarball":"https://registry.npmjs.org/@aquibk/reconix/-/reconix-1.0.0.tgz","fileCount":5,"integrity":"sha512-Fy6r4lkL1LIFUNhOLocp47yU7OOOcw5rLNJ+RFZH+RX0LeDJXHhGdtB5U8An1i5Nw7eM2q34sMl/zhHsi7dAmw==","signatures":[{"sig":"MEYCIQD3hWGAsmtUfigZfMXsIoYaM0pgs98TESzG5JxGPzZBagIhAJI3e2oAxjDnuKQDXJ+4cuhDICzM+cBs7MbO5m3op65e","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":214414},"main":"index.js","type":"commonjs","gitHead":"c16b4bd1f2a21f53a54c3bdc89f22d7578ba03a2","scripts":{"test":"echo \"Error: no test specified\" && exit 1"},"_npmUser":{"name":"aquibk","email":"masteraquibkhan@gmail.com"},"repository":{"url":"git+https://github.com/AquibPro/reconix.git","type":"git"},"_npmVersion":"11.1.0","description":"Reconnaissance Intelligence Engine | Leak Scanner | Threat Intelligence Suite","directories":{},"_nodeVersion":"22.18.0","dependencies":{"ora":"^5.4.1","chalk":"^4.1.2","figlet":"^1.11.0","cheerio":"^1.2.0","puppeteer":"^24.40.0","clipboardy":"^3.0.0","node-fetch":"^3.3.2","proxy-agent":"^8.0.0","puppeteer-extra":"^3.3.6","puppeteer-extra-plugin-stealth":"^2.11.2"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/reconix_1.0.0_1775556148153_0.35755304625946316","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@aquibk/reconix","version":"1.0.1","keywords":["recon","reconnaissance","leak","scanner","threat","intelligence","suite","security","pentest","bug bounty","ethical hacking","cybersecurity","reconix"],"author":{"name":"Aquib Khans"},"license":"ISC","_id":"@aquibk/reconix@1.0.1","maintainers":[{"name":"aquibk","email":"masteraquibkhan@gmail.com"}],"homepage":"https://github.com/AquibPro/reconix","bugs":{"url":"https://github.com/AquibPro/reconix/issues"},"bin":{"reconix":"index.js"},"dist":{"shasum":"2760840d329858bc6ae207755844df736067f115","tarball":"https://registry.npmjs.org/@aquibk/reconix/-/reconix-1.0.1.tgz","fileCount":5,"integrity":"sha512-Z3CjLeBuuC57wqrSAZnLwBspPosToumSWCevqHeROiPIH9YnNIwDdjXsPY++I8S60QeoMZx62ylXjBbJL1AXtg==","signatures":[{"sig":"MEUCIGWmhm575NSPJeu26X24fchGMGOyTBrQeBwpijbRboxtAiEAqRif8uGyiyhyrsnUI+bI/jETIfx+3zBSmUY1t9KjX88=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":214683},"main":"index.js","type":"commonjs","gitHead":"0be33f4ca19d8fc5efed929bffbbf7ae056cde61","scripts":{"test":"echo \"Error: no test specified\" && exit 1"},"_npmUser":{"name":"aquibk","email":"masteraquibkhan@gmail.com"},"repository":{"url":"git+https://github.com/AquibPro/reconix.git","type":"git"},"_npmVersion":"11.1.0","description":"Reconnaissance Intelligence Engine | Leak Scanner | Threat Intelligence Suite","directories":{},"_nodeVersion":"22.18.0","dependencies":{"ora":"^5.4.1","chalk":"^4.1.2","figlet":"^1.11.0","cheerio":"^1.2.0","puppeteer":"^24.40.0","clipboardy":"^3.0.0","node-fetch":"^3.3.2","proxy-agent":"^8.0.0","puppeteer-extra":"^3.3.6","puppeteer-extra-plugin-stealth":"^2.11.2"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/reconix_1.0.1_1775556794710_0.9021348794814588","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@aquibk/reconix","version":"1.0.2","keywords":["recon","reconnaissance","leak","scanner","threat","intelligence","suite","security","pentest","bug bounty","ethical hacking","cybersecurity","reconix"],"author":{"name":"Aquib Khans"},"license":"ISC","_id":"@aquibk/reconix@1.0.2","maintainers":[{"name":"aquibk","email":"masteraquibkhan@gmail.com"}],"homepage":"https://github.com/AquibPro/reconix","bugs":{"url":"https://github.com/AquibPro/reconix/issues"},"bin":{"reconix":"index.js"},"dist":{"shasum":"441ba7c7bed474f5be1c6569ee10c7e592405ff1","tarball":"https://registry.npmjs.org/@aquibk/reconix/-/reconix-1.0.2.tgz","fileCount":5,"integrity":"sha512-2x8ROwZ29O2Zs61BwSQ9UE8S/wlggLDgfjzIhfT0UaDRRwGmd2ZEU14gkrB6pXkhHCy5dgEfgap+ssQ8M+9TXQ==","signatures":[{"sig":"MEQCIC9Wro4jVmolE/bK9Z7G8RZ4yusbnZGA6ftareThdCP0AiBkQVmo9JDlBftx+pe0pYjVWjd0uOUrHVzaRRDvsGNVBw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":215767},"main":"index.js","type":"commonjs","gitHead":"5b1712db27f6977828ca4077364558356cf217a5","scripts":{"test":"echo \"Error: no test specified\" && exit 1"},"_npmUser":{"name":"aquibk","email":"masteraquibkhan@gmail.com"},"repository":{"url":"git+https://github.com/AquibPro/reconix.git","type":"git"},"_npmVersion":"11.1.0","description":"Reconnaissance Intelligence Engine | Leak Scanner | Threat Intelligence Suite","directories":{},"_nodeVersion":"22.18.0","dependencies":{"ora":"^5.4.1","chalk":"^4.1.2","figlet":"^1.11.0","cheerio":"^1.2.0","puppeteer":"^24.40.0","clipboardy":"^3.0.0","node-fetch":"^3.3.2","proxy-agent":"^8.0.0","puppeteer-extra":"^3.3.6","update-notifier":"^7.3.1","puppeteer-extra-plugin-stealth":"^2.11.2"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/reconix_1.0.2_1775557487560_0.7520042292041296","host":"s3://npm-registry-packages-npm-production"}},"1.0.3":{"name":"@aquibk/reconix","version":"1.0.3","keywords":["recon","reconnaissance","leak","scanner","threat","intelligence","suite","security","pentest","bug bounty","ethical hacking","cybersecurity","reconix"],"author":{"name":"Aquib Khans"},"license":"SEE LICENSE IN LICENSE.txt","_id":"@aquibk/reconix@1.0.3","maintainers":[{"name":"aquibk","email":"masteraquibkhan@gmail.com"}],"homepage":"https://github.com/AquibPro/reconix","bugs":{"url":"https://github.com/AquibPro/reconix/issues"},"bin":{"reconix":"index.js"},"dist":{"shasum":"cf7992086c9b2db19f6183f5a1ba1fe0425ac9cd","tarball":"https://registry.npmjs.org/@aquibk/reconix/-/reconix-1.0.3.tgz","fileCount":5,"integrity":"sha512-2CK3ZmOAUgz6lw12tX/DYpCPYE7WC0O/gdrFslkBov2C0rfWJC17oUvZCCmak/FMjSQT9V7wfkLx/WWOxSGn+g==","signatures":[{"sig":"MEUCIGoWs+tUkWbwnL+q8OFkovr+pYJk/iTpidfoDR0povTJAiEAjz4/aLDUgy3RXrr/3zv0YGgMttb9ENlXIMGpO4yYTQw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":215790},"main":"index.js","type":"commonjs","gitHead":"ce58a955cfa3b31646e1e1d5a76bfc4e4b975f1c","scripts":{"test":"echo \"Error: no test specified\" && exit 1"},"_npmUser":{"name":"aquibk","email":"masteraquibkhan@gmail.com"},"repository":{"url":"git+https://github.com/AquibPro/reconix.git","type":"git"},"_npmVersion":"11.1.0","description":"Reconnaissance Intelligence Engine | Leak Scanner | Threat Intelligence Suite","directories":{},"_nodeVersion":"22.18.0","dependencies":{"ora":"^5.4.1","chalk":"^4.1.2","figlet":"^1.11.0","cheerio":"^1.2.0","puppeteer":"^24.40.0","clipboardy":"^3.0.0","node-fetch":"^3.3.2","proxy-agent":"^8.0.0","puppeteer-extra":"^3.3.6","update-notifier":"^7.3.1","puppeteer-extra-plugin-stealth":"^2.11.2"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/reconix_1.0.3_1775557614107_0.6336426337923298","host":"s3://npm-registry-packages-npm-production"}},"1.0.4":{"name":"@aquibk/reconix","version":"1.0.4","keywords":["recon","reconnaissance","leak","scanner","threat","intelligence","suite","security","pentest","bug bounty","ethical hacking","cybersecurity","reconix"],"author":{"name":"Aquib Khans"},"license":"SEE LICENSE IN LICENSE.txt","_id":"@aquibk/reconix@1.0.4","maintainers":[{"name":"aquibk","email":"masteraquibkhan@gmail.com"}],"homepage":"https://github.com/AquibPro/reconix","bugs":{"url":"https://github.com/AquibPro/reconix/issues"},"bin":{"reconix":"index.js"},"dist":{"shasum":"bd4b3a4ab8390a8aa1be03725c747c4144248be3","tarball":"https://registry.npmjs.org/@aquibk/reconix/-/reconix-1.0.4.tgz","fileCount":7,"integrity":"sha512-xP9rbCT7Ddlbn7uGHGxldYoo8tXHziPJ/UAkGHi0012qe+kt3l1n9WfFYsR8D8jrix6FhCBNn0rQkk1FjBCmcA==","signatures":[{"sig":"MEUCIQC7rh4yQqSCti+bC6b5zT/c1mH1yAWrGURbhJma7dVd5gIgTJ9KJ7AxC0lJ2RJK4xPDZKiyKWPaz4ejQ3eM64Qq4vw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":216041},"main":"index.js","type":"commonjs","gitHead":"865ca1682cac1b43f77d82b58e46cc892e54d6a8","scripts":{"test":"echo \"Error: no test specified\" && exit 1"},"_npmUser":{"name":"aquibk","email":"masteraquibkhan@gmail.com"},"repository":{"url":"git+https://github.com/AquibPro/reconix.git","type":"git"},"_npmVersion":"11.1.0","description":"Reconnaissance Intelligence Engine | Leak Scanner | Threat Intelligence Suite","directories":{},"_nodeVersion":"22.18.0","dependencies":{"ora":"^5.4.1","chalk":"^4.1.2","figlet":"^1.11.0","cheerio":"^1.2.0","puppeteer":"^24.40.0","clipboardy":"^3.0.0","node-fetch":"^3.3.2","proxy-agent":"^8.0.0","puppeteer-extra":"^3.3.6","update-notifier":"^7.3.1","puppeteer-extra-plugin-stealth":"^2.11.2"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/reconix_1.0.4_1775580294654_0.7907292881276495","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@aquibk/reconix","version":"1.1.0","description":"Reconnaissance Intelligence Engine | Leak Scanner | Threat Intelligence Suite","main":"index.js","scripts":{"test":"echo \"Error: no test specified\" && exit 1"},"bin":{"reconix":"index.js"},"repository":{"type":"git","url":"git+https://github.com/AquibPro/reconix.git"},"homepage":"https://github.com/AquibPro/reconix","keywords":["recon","reconnaissance","leak","scanner","threat","intelligence","suite","security","pentest","bug bounty","ethical hacking","cybersecurity","reconix"],"author":{"name":"Aquib Khans"},"license":"SEE LICENSE IN LICENSE.txt","type":"commonjs","dependencies":{"chalk":"^4.1.2","cheerio":"^1.2.0","clipboardy":"^3.0.0","figlet":"^1.11.0","node-fetch":"^3.3.2","ora":"^5.4.1","proxy-agent":"^8.0.0","puppeteer":"^24.40.0","puppeteer-extra":"^3.3.6","puppeteer-extra-plugin-stealth":"^2.11.2","update-notifier":"^7.3.1"},"_id":"@aquibk/reconix@1.1.0","gitHead":"6234a629d38bc96a09e0edd197772494f7440f4a","bugs":{"url":"https://github.com/AquibPro/reconix/issues"},"_nodeVersion":"22.18.0","_npmVersion":"11.1.0","dist":{"integrity":"sha512-Szq8jBDtmL4B/OUGJ+wp5wXjLHu2tg3U7DpjLJZBK9gGot7UQ7MXeiI69QBRK8m3QLhFnYPojiRNpmRy8uTUWQ==","shasum":"06ac984b32573c11a4bee0739dbfae7f8051a0bd","tarball":"https://registry.npmjs.org/@aquibk/reconix/-/reconix-1.1.0.tgz","fileCount":7,"unpackedSize":365321,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCZJbuizJ+dq3azZgDrKQi7Z8tPP5Njqxwru5aKrooRMAIgVLOSvjH7uITx2LrshXsNHEepUO0oZCprg27t+Tibs1Q="}]},"_npmUser":{"name":"aquibk","email":"masteraquibkhan@gmail.com"},"directories":{},"maintainers":[{"name":"aquibk","email":"masteraquibkhan@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/reconix_1.1.0_1776419292294_0.9940778678080742"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-07T10:02:28.084Z","modified":"2026-04-17T09:48:12.550Z","1.0.0":"2026-04-07T10:02:28.318Z","1.0.1":"2026-04-07T10:13:14.848Z","1.0.2":"2026-04-07T10:24:47.718Z","1.0.3":"2026-04-07T10:26:54.246Z","1.0.4":"2026-04-07T16:44:54.806Z","1.1.0":"2026-04-17T09:48:12.448Z"},"bugs":{"url":"https://github.com/AquibPro/reconix/issues"},"author":{"name":"Aquib Khans"},"license":"SEE LICENSE IN LICENSE.txt","homepage":"https://github.com/AquibPro/reconix","keywords":["recon","reconnaissance","leak","scanner","threat","intelligence","suite","security","pentest","bug bounty","ethical hacking","cybersecurity","reconix"],"repository":{"type":"git","url":"git+https://github.com/AquibPro/reconix.git"},"description":"Reconnaissance Intelligence Engine | Leak Scanner | Threat Intelligence Suite","maintainers":[{"name":"aquibk","email":"masteraquibkhan@gmail.com"}],"readme":"# Reconix\r\n\r\n<div align=\"center\">\r\n\r\n**Reconnaissance Intelligence Engine | Leak Scanner | Threat Intelligence Suite**\r\n\r\n[![Node.js Version](https://img.shields.io/badge/node-%3E%3D18.0-brightgreen)](https://nodejs.org/)\r\n[![License](https://img.shields.io/badge/license-RECONIX-blue)](LICENSE.txt)\r\n\r\n**🔍 Deep Exposure Intelligence • ⚡ High-Signal Recon Engine**\r\n\r\n</div>\r\n\r\n---\r\n\r\n## ⚠️ LEGAL DISCLAIMER\r\n\r\n**Reconix is designed EXCLUSIVELY for authorized security testing, bug bounty programs, and defensive research.**\r\n\r\n- ✅ **DO** scan targets you own\r\n- ✅ **DO** scan targets with explicit written permission\r\n- ✅ **DO** use in CTF competitions\r\n- ❌ **DO NOT** scan systems without authorization\r\n- ❌ **DO NOT** use for malicious purposes\r\n\r\n**Unauthorized scanning is illegal and punishable under computer fraud laws.**  \r\nRead the full disclaimer in [DISCLAIMER.md](./DISCLAIMER.md).\r\n\r\n---\r\n\r\n## 🔥 What Makes Reconix Powerful\r\n\r\nUnlike basic scanners that just regex-match and dump findings, Reconix:\r\n\r\n- **Validates secrets live** — Calls actual APIs (GitHub, Stripe, OpenAI, Supabase, SendGrid, Anthropic, HuggingFace, Linear) to confirm if keys are **VALID**, **INVALID**, **EXPIRED**, or **LONG-LIVED** — no more guessing if a key actually works\r\n\r\n- **Builds exploit chains** — Automatically connects related findings into actionable attack paths like \"JWT + Supabase + API endpoints → Unauthorized data access\" or \"Validated secret + Admin panel → Privilege escalation\"\r\n\r\n- **Filters false positives with 10-layer analysis** — Ignores React internals, CSS classes, documentation URLs, placeholders, and minified junk that other tools falsely report as secrets\r\n\r\n- **Reconstructs source maps** — Recovers original source code from `.map` files and inline source maps, then scans the reconstructed code for secrets hidden in minified bundles\r\n\r\n- **Self-healing browser** — Automatically detects and restarts crashed Puppeteer instances mid-scan without losing progress\r\n\r\n- **Extracts client intelligence** — Aggregates all JavaScript to find API endpoints (user/admin/internal), environment variables (`NEXT_PUBLIC_*`, `REACT_APP_*`), third-party services (Supabase, Stripe, Firebase, Clerk), and feature flags\r\n\r\n- **Priority-driven crawling** — Intelligently scores URLs (JS files, APIs, source maps first) to find high-value targets before wasting time on static assets\r\n\r\n- **Live JWT introspection** — Decodes JWTs to reveal issuer, role, and expiry — flags **LONG-LIVED** (1+ year) and **NO EXPIRY** tokens as security concerns\r\n\r\n- **Supabase service_role detection** — Identifies when a JWT has `service_role` privileges, which bypasses all Row Level Security (RLS) — critical database compromise path\r\n\r\n- **Firebase Realtime DB testing** — Detects Firebase credentials and tests if `/.json` endpoint allows unauthenticated database dumps\r\n\r\n- **GraphQL introspection detection** — Automatically probes `/graphql` endpoints to check if schema introspection is enabled (information leak)\r\n\r\n- **CORS misconfiguration scanning** — Checks API endpoints for wildcard (`*`) or reflective `Access-Control-Allow-Origin` headers\r\n\r\n- **WordPress user enumeration** — Detects when `/wp-json/wp/v2/users` exposes user IDs and names\r\n\r\n- **Next.js environment variable leakage** — Scans `/_next/static/chunks/` for embedded `process.env` references in client bundles\r\n\r\n- **Archive digging** — Fetches historical URLs from Wayback Machine and scans archived content for secrets that were removed from the live site\r\n\r\n- **Proxy failover** — Automatically falls back to direct connection after 3 consecutive proxy failures, so scans don't die\r\n\r\n- **Resumable scans** — Saves state every 10 resources and can resume from `.reconix-state.json` if interrupted\r\n\r\n- **Multi-format reporting** — Generates beautiful HTML reports, structured JSON exports, and plaintext `discovered_api_keys.txt` for quick reference\r\n\r\n- **680+ technology fingerprints** — Detects frameworks, hosting providers, CDNs, analytics, payment processors, auth systems, and UI libraries from headers, HTML, JS, cookies, TLS certs, and DNS\r\n\r\n- **200+ real-world secret detection patterns** — Covers API keys, tokens, private keys, OAuth secrets, database credentials, CI/CD tokens, and webhook URLs across major platforms with high-confidence matching\r\n\r\n- **Browser network capture** — When `--js` is enabled, captures all outgoing network requests to fingerprint additional services and APIs\r\n\r\n- **Rate limit awareness** — Detects 429 responses and `Retry-After` headers, adjusts accordingly without crashing\r\n\r\n---\r\n\r\n## 📦 Installation\r\n\r\n```bash\r\n# Global installation\r\nnpm install -g @aquibk/reconix\r\n\r\n# Or run directly\r\nnpx reconix target.com\r\n\r\n# Verify everything works\r\nreconix --self-test\r\n````\r\n\r\n### Requirements\r\n\r\n* Node.js 18 or higher\r\n* Internet access\r\n* Chrome/Chromium (installed automatically for `--js` mode)\r\n\r\n---\r\n\r\n## 🚀 Quick Start\r\n\r\n```bash\r\n# Basic scan (low footprint)\r\nreconix example.com\r\n\r\n# Full power (maximum findings)\r\nreconix example.com --js --aggressive --deep --only-critical\r\n\r\n# Bug bounty mode (balanced)\r\nreconix target.com --js --deep --historical --delay=500 --output=report.json\r\n\r\n# Stealth mode (avoid detection)\r\nreconix target.com --delay=2000 --jitter=1000 --threads=5 --proxy=socks5://127.0.0.1:9050\r\n```\r\n\r\n---\r\n\r\n## 📖 Full Command Reference\r\n\r\n### Basic Usage\r\n\r\n```bash\r\nreconix <url> [options]\r\nreconix scan <url> [options]\r\n```\r\n\r\n---\r\n\r\n### 🎨 Output & Reporting\r\n\r\n| Flag              | Description             | Default |\r\n| ----------------- | ----------------------- | ------- |\r\n| `--output=<file>` | Save full JSON report   | None    |\r\n| `--html=<file>`   | Generate HTML report    | None    |\r\n\r\n```bash\r\nreconix example.com --output=scan.json --html=report.html\r\n```\r\n\r\n---\r\n\r\n### 🔍 Discovery & Reconnaissance\r\n\r\n| Flag              | Description                 | Default |\r\n| ----------------- | --------------------------- | ------- |\r\n| `--no-subdomains` | Disable subdomain discovery | -       |\r\n| `--historical`    | Fetch archived URLs         | false   |\r\n| `--deep`          | Increase crawl depth        | false   |\r\n\r\n```bash\r\nreconix example.com --historical --deep\r\n```\r\n\r\n---\r\n\r\n### 🧠 Scanning Engine\r\n\r\n| Flag                  | Description                 | Default |\r\n| --------------------- | --------------------------- | ------- |\r\n| `--threads=<n>`       | Concurrent requests (1–100) | 20      |\r\n| `--delay=<ms>`        | Base delay between requests | 500     |\r\n| `--jitter=<ms>`       | Random delay variation      | 300     |\r\n| `--max-bytes=<bytes>` | Max download size per file  | 4000000 |\r\n| `--resume`            | Resume previous scan        | false   |\r\n\r\n```bash\r\n# Fast but risky\r\nreconix example.com --threads=50 --delay=100 --jitter=50\r\n\r\n# Polite crawling\r\nreconix example.com --threads=10 --delay=2000 --jitter=1000\r\n```\r\n\r\n---\r\n\r\n### 🔥 Advanced Features\r\n\r\n* `--no-js` → Disable headless browser (Puppeteer)\r\n* `--aggressive` → Deep full-scope scan\r\n* `--proxy=<host:port>` → Proxy support\r\n* `--auth=<user:pass>` → Authentication (Basic or Bearer)\r\n* `--cookie=<string>` → Custom cookies\r\n* `--user-agent=<string>` → Custom user-agent\r\n\r\n```bash\r\n# Authenticated scan\r\nreconix api.example.com --auth=\"Bearer:sk_live_xxx\" --js\r\n\r\n# Proxy usage\r\nreconix example.com --proxy=\"http://user:pass@proxy:8080\" --delay=1000\r\n```\r\n\r\n---\r\n\r\n### 🎯 Finding Filters\r\n\r\n| Flag               | Description                  | Default |\r\n| ------------------ | ---------------------------- | ------- |\r\n| `--only-critical`  | Show only critical findings  | false   |\r\n| `--no-low`         | Hide low-confidence findings | false   |\r\n| `--include-medium` | Include medium findings      | true    |\r\n| `--no-medium`      | Exclude medium findings      | -       |\r\n\r\n```bash\r\nreconix example.com --only-critical --no-low\r\n```\r\n\r\n---\r\n\r\n## 🎯 Use Cases\r\n\r\n### 1. Bug Bounty (Balanced)\r\n\r\n```bash\r\nreconix target.com --deep --historical --threads=25 --delay=500 --output=bounty.json --html=report.html\r\n```\r\n\r\n### 2. Maximum Findings (Most Powerful)\r\n\r\n```bash\r\nreconix target.com --aggressive --deep --historical --threads=50 --delay=150 --jitter=50 --only-critical --output=full.json --html=full.html\r\n```\r\n\r\n### 3. Stealth Mode\r\n\r\n```bash\r\nreconix target.com --threads=5 --delay=2000 --jitter=1500 --no-subdomains --proxy=socks5://127.0.0.1:9050\r\n```\r\n\r\n### 4. Fast Triage\r\n\r\n```bash\r\nreconix target.com --threads=30 --delay=200 --no-js --no-subdomains --only-critical\r\n```\r\n\r\n---\r\n\r\n## 🛡️ Rate Limiting & WAF Avoidance\r\n\r\n| Target Type | Threads | Delay     | Jitter | JS |\r\n| ----------- | ------- | --------- | ------ | -- |\r\n| Production  | 5–10    | 2000–3000 | 1000   | ❌  |\r\n| Staging     | 15–20   | 800–1200  | 500    | ✅  |\r\n| Bug Bounty  | 20–30   | 400–600   | 200    | ✅  |\r\n| CTF / Lab   | 50–100  | 0–100     | 0      | ✅  |\r\n\r\n---\r\n\r\n## 📊 What Reconix Reports\r\n\r\n### Technology Stack\r\n\r\n* Confirmed (90%+)\r\n* Likely (70–89%)\r\n* Theoretical (<70%)\r\n\r\n### Secrets & Credentials\r\n\r\n* VALID\r\n* INVALID\r\n* LONG-LIVED\r\n* NO EXPIRY\r\n* UNVERIFIED\r\n\r\n### Client Intelligence\r\n\r\n* API endpoints\r\n* Environment variables\r\n* External services\r\n* Authentication mechanisms\r\n\r\n### Exploit Chains\r\n\r\n* JWT + API → Unauthorized access\r\n* API key → Third-party abuse\r\n* Firebase credentials → Database exposure\r\n\r\n---\r\n\r\n## 🧪 Self-Test Mode\r\n\r\n```bash\r\nreconix --self-test\r\n```\r\n\r\n---\r\n\r\n## 💡 Pro Tips\r\n\r\n```bash\r\n# Phase 1: Quick recon\r\nreconix target.com --only-critical\r\n\r\n# Phase 2: Deep analysis\r\nreconix target.com --deep --delay=1000\r\n\r\n# Phase 3: Aggressive scan\r\nreconix target.com --aggressive --deep --only-critical\r\n```\r\n\r\n---\r\n\r\n## 🚨 Common Issues & Solutions\r\n\r\n| Issue               | Solution                       |\r\n| ------------------- | ------------------------------ |\r\n| Browser timeout     | Reinstall Puppeteer            |\r\n| Too many open files | Reduce threads                 |\r\n| Proxy failed        | Check proxy URL                |\r\n| Rate limited (429)  | Increase delay & jitter        |\r\n| No findings         | Use `--js --deep --historical` |\r\n\r\n---\r\n\r\n## 📁 Output Files\r\n\r\n| File                      | Description       |\r\n| ------------------------- | ----------------- |\r\n| `discovered_api_keys.txt` | All secrets found |\r\n| `*.json`                  | Full scan report  |\r\n| `*.html`                  | Visual report     |\r\n| `.reconix-state.json`     | Resume state      |\r\n\r\n---\r\n\r\n## 🤝 Contributing\r\n\r\nIssues and pull requests are welcome.\r\n\r\n```bash\r\nreconix --self-test\r\n```\r\n\r\n---\r\n\r\n## 📄 License\r\n\r\nSee LICENSE.txt\r\n\r\n---\r\n\r\n<div align=\"center\">\r\n\r\n⚠️ USE RESPONSIBLY. ONLY ON AUTHORIZED TARGETS. ⚠️\r\n\r\n</div>\r\n</div>","readmeFilename":"README.md"}