Open-source project
evyatarmeged/Raccoon avatar
evyatarmeged/Raccoon

Raccoon's asynchronous design assumes its scans never depend on each other

A high performance offensive security tool for reconnaissance and vulnerability scanning

4,041 stars505 forksPythonMIT

At a glance

What is it?
evyatarmeged/Raccoon is a reconnaissance scanner whose stated reason for using asynchronous execution is that its scans are independent and do not rely on each other's results. The roadmap is honest about what is missing, including rate limit evasion, network range support and any machine-readable output.
Who is it for?
Raccoon suits a tester who wants one command that gathers DNS, certificate, port, service and web application data about a single host and writes each result to its own file, and who is scanning from a machine where Nmap and OpenSSL are already installed. It suits a beginner, because the emphasis is stated as simplicity and the option set is short.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 166 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 4, 2026, and from our analysis. They are not legal advice.

Editorial analysis

Asynchronous execution rests on one assumption the author states outright

The reason given for the tool's concurrency model is worth quoting because it bounds the design. Most of the scans are run asynchronously because, as the project puts it, most scans are independent and do not rely on each other's results. That is the whole justification: there is no dependency graph between a DNS lookup and a port scan, so both can be in flight at once. It is also the limitation. Anything that would need a prior result, such as taking a discovered hostname and scanning it, would break the assumption and force sequencing. The roadmap reflects that constraint: support for multiple hosts read from a file is still unchecked, and so are network ranges and CIDR notation. In other words the asynchronous design and the single-target requirement are the same fact seen from two sides.

Eleven modules, and one of them is the reason you need root-adjacent tooling

The feature list is a checklist of eleven capabilities that all run in one pass. There are DNS record queries and a visual mapping of the results through a third-party service, WHOIS lookups, and TLS data covering supported ciphers, protocol versions, certificate details and subject alternative names. Then come the active parts: a port scan, a service and script scan, URL fuzzing with directory and file detection, and subdomain enumeration that combines several techniques including certificate alternative names. The web application module is the largest, covering content management system detection, server and header information, robots and sitemap extraction, cookie inspection, extraction of every fuzzable URL, form discovery, email address harvesting and a scan for exposed object storage buckets. Finally there is web application firewall detection and the option to route through Tor or a proxy list. Port scanning is delegated to an external tool, which is the dependency that catches people out.

Two external tools are mandatory, and the documentation says so

The prerequisites section is unusually direct about this. Port scanning is delegated to Nmap, and some of the other scans use its scripts and features too, so having it installed is described as mandatory before running the tool at all. OpenSSL is used for the transport security scans and should be installed as well. There is no bundled fallback and no error message about a missing dependency described in the documentation, which means a first-time user is expected to have installed both. That is a real cost to weigh: a scanner that needs a full network mapping tool and a cryptography toolkit installed system-wide is a heavier commitment than a single-purpose script, even though the result is one command. It also means the tool inherits whatever version of those tools the machine has, which is worth keeping in mind when comparing results across hosts.

Each module writes its own file, and the folder tree is the deliverable

Output organisation is stated twice, in the feature list and in the screenshots section. Every scan writes to a corresponding file, targets are separated into folders and modules into files, and the screenshots include a shot of the folder tree after a run. That is a deliberate choice about what a scan produces: not a report but a directory of artefacts you can read individually. For a reconnaissance tool it makes sense, because the interesting output is often one specific artefact rather than a summary, and because the folder tree survives between runs for comparison. It also means there is no single file to hand to someone else, which connects to the roadmap item about output formats. Without a machine-readable format, an automated pipeline has to scrape the text files, which is exactly the friction that item would remove.

The option list is four entries, and only two of them change behaviour

The usage block shows a single positional target and a short option list. One flag prints the version. One takes a comma separated list of record types to query and defaults to a set of six covering the common records. One routes traffic through the local Tor proxy on a fixed port and the documentation warns that it slows the total runtime significantly. One takes a path to a proxy list from which one entry will be chosen per request. That is the whole surface, and the contrast with the eleven-module feature list is instructive: there are no switches to select modules, no output format option and no verbosity control. Everything runs, and the flags only adjust where requests go and which record types come back. Wordlists come from a well-known public collection by default and can be replaced by passing a different one.

macOS needs a GNU coreutils shim, and the Docker image needs an output path

The package install itself is one line, and there is a second route for people who want the newest code rather than the published package:

code
pip install raccoon-scanner
# To run:
raccoon [OPTIONS]

The alternative is to clone the repository and run the packaging script in one of two modes, which is worth reading closely because the two behave differently afterwards. An install copies the code once, so later changes to the source are not reflected when you invoke the command. A develop install links to the working copy instead, so edits take effect immediately, and it can be undone with the same command and an uninstall flag. Two installation notes then carry the kind of detail that saves an afternoon. On macOS the tool needs a program that the base system does not ship, and the fix is given as a single package install of the GNU core utilities. That is a signal about the implementation: something calls a GNU-style time command by name. The Docker instructions are more interesting, because they encode a constraint rather than a workaround. The image runs as a non-root user, so the output directory has to live inside that user's home, and the example passes that path explicitly after the target and an output flag. Anyone containerising the tool against a mounted volume needs to make sure the path resolves inside the container's home rather than on the host where they expected it.

Eight dependencies, pinned to versions from before the current Python

The packaging is a small setuptools script and it is informative. The console script maps one name to the package's main function, the package data section ships a wordlists directory inside the source package, and the install requirements name eight libraries: an HTML parser, an HTTP client, a DNS library, an XML parser, a command line parser, a user agent generator, the SOCKS extra for the HTTP client, and an XML to dictionary converter. The separate requirements file pins those same libraries to exact versions, several of which are old: a command line parser at a version in the single digits, an HTML parser at four point six, and a DNS library at two point six. The manifest itself declares a version in the zero eight series, and the container base image is a Python three point eight Alpine image. None of that is a problem on its own; it is simply a snapshot of a dependency set chosen when those versions were current.

Editorial conclusion

Raccoon suits a tester who wants one command that gathers DNS, certificate, port, service and web application data about a single host and writes each result to its own file, and who is scanning from a machine where Nmap and OpenSSL are already installed. It suits a beginner, because the emphasis is stated as simplicity and the option set is short. It does not suit anyone scanning a network range, since range and CIDR notation are both still open roadmap items, and it does not suit a pipeline that needs JSON output, since that is listed as a to-do as well. Before adopting it, install the two external prerequisites, expect the Tor route to slow the run substantially as documented, and remember that a single-target tool is what you are getting rather than something you can point at a subnet.

Frequently asked questions

What does Raccoon reconnaissance tool do?

It gathers DNS records, WHOIS information, TLS data including ciphers, versions, certificate details and subject alternative names, then port scans, runs service and script scans, fuzzes URLs, enumerates subdomains, retrieves web application data such as forms and emails, and detects web application firewalls. Every scan writes to its own file, with targets in folders and modules in files.

What must I install before running Raccoon?

Nmap is mandatory, because port scanning and some other scans are delegated to it and its scripts. OpenSSL is also used for the transport security scans and should be installed. On macOS you additionally need the GNU core utilities, installed with `brew install coreutils`.

How do I install Raccoon?

Run `pip install raccoon-scanner` and then invoke `raccoon [OPTIONS]`. You can also clone the repository and either run `python setup.py install` for a fixed copy or `python setup.py develop` so later source changes are reflected, which can be undone with the uninstall flag. A Docker image can be built from the included Dockerfile.

Can Raccoon scan a network range?

Not yet. Reading multiple hosts from a file, network range support and CIDR notation support are all still open items on the project's roadmap, as are JSON output and rate limit evasion. The tool takes a single target on the command line.

Official sources

  1. evyatarmeged/Raccoon on GitHub
  2. Issues
  3. License: MIT
  4. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/evyatarmeged-raccoon.svg)](https://hysenlabs.com/projects/evyatarmeged-raccoon)