Repository navigation
Recon Presets
📖 Canonical version: read this page on the official docs site — https://www.redamon.org/docs/recon-presets. The GitHub wiki is a mirror.
RedAmon has two preset systems that let you skip manual configuration:
- Built-in Recon Presets -- 21 curated recon pipeline configurations covering common scenarios from quick bug bounty scans to full-scale network audits. These configure only recon tool parameters (328+ settings across the Recon Pipeline tabs)
- My Project Presets -- save your entire project configuration (recon pipeline, agent behavior, tool matrix, agent skills, CypherFix, and all other settings) as a reusable preset, then load it on any future project. Includes AI-generated presets via natural language
- Open a project form (new or existing) and click the Recon Preset tab (lightning bolt icon) in the Recon Pipeline tab group
- Browse the Built-in Recon Presets grid and click a preset card
- Click Select and confirm -- all recon tabs update instantly, and on an existing project the change is saved straight away. Target fields (domain, IPs, subdomains) are preserved

The built-in library contains 21 presets organized as a card grid. Each card shows an icon, name, and short description. Click a card to see the full description with detailed sections explaining the goal, target audience, what the preset enables/disables, and how it works.

- Click a card to view its full description in the detail panel
- Click "Select" to apply the preset to the current project form
- A confirmation dialog appears first: the project's current settings are discarded and replaced with the preset's
- The preset overwrites all recon tool settings (modules, thresholds, toggles); every setting it does not define goes back to its default. It never touches target-specific fields (domain, subdomains, IP list)
- On an existing project the new settings are saved immediately -- there is no need to click Update Settings. On a new project they are saved when you create it
- An "Applied" badge appears on the project form showing which preset is active
- You can still override any individual setting after applying a preset
| # | Preset | Focus |
|---|---|---|
| 1 | Full Pipeline - Active Only | Every active tool maxed out, all passive sources disabled. Maximum noise, maximum coverage |
| 2 | Full Pipeline - Passive Only | Zero packets to target. Maximum intelligence from third-party sources, archives, and passive databases only |
| 3 | Full Pipeline - Maximum | Every tool enabled with every parameter pushed to the limit. The longest, most thorough scan possible |
| 4 | Bug Bounty - Quick Wins | Fast, lightweight scan for low-hanging fruit. Get actionable results in under 15 minutes |
| 5 | Bug Bounty - Deep Dive | Thorough single-target assessment. Deep crawling, JS analysis, all Nuclei severities, balanced to avoid IP bans |
| 6 | API Security Audit | Focused on REST/GraphQL API surface. Kiterunner, Arjun, ffuf with API extensions, Nuclei API tags |
| 7 | Infrastructure Mapper | Network perimeter mapping. Full port scanning, service detection, banner grabbing, Shodan enrichment, CVE lookup |
| 8 | OSINT Investigator | Maximum passive intelligence from all 10 OSINT providers, archives, and public databases. No active scanning |
| 9 | Web App Pentester | Web application focused. Aggressive crawling, directory fuzzing with recursion, parameter discovery, Nuclei DAST with all severities |
| 10 | JS Secret Miner | Deep JS analysis pipeline. Maximize JS file discovery, extract secrets, endpoints, and source maps |
| 11 | Subdomain Takeover Hunter | Maximize subdomain discovery and detect takeover opportunities. All subdomain tools at high limits, httpx CNAME probing, Nuclei takeover templates |
| 12 | Stealth Recon | Minimal detection footprint. Passive tools preferred, extremely low rate limits on active probes |
| 13 | CVE Hunter | Find known CVEs through port scanning, service detection, Nuclei templates, and passive CVE sources |
| 14 | Red Team Operator | Balanced stealth with targeted active validation. Connect scan, throttled probes, critical-only Nuclei, full OSINT enrichment |
| 15 | Directory & Content Discovery | Maximize hidden content discovery. ffuf with deep recursion, Kiterunner for API routes, deep crawling, GAU historical URLs |
| 16 | Cloud & External Exposure | Cloud-focused security assessment. OSINT providers for cloud-exposed services, TLS probes, security checks for cloud misconfigs |
| 17 | Compliance & Header Audit | Security posture validation. httpx with all header probes, TLS analysis, SPF/DMARC/DNSSEC checks, Nuclei misconfig scanning |
| 18 | Secret & Credential Hunter | Go beyond JS -- find secrets everywhere. Deep JS analysis, GAU for historical files, ffuf with sensitive extensions, Nuclei exposure/token detection |
| 19 | Parameter & Injection Surface | Maximize parameter discovery for injection testing. Arjun all methods, ParamSpider, GAU, Katana paramsOnly, Nuclei DAST with injection tags |
| 20 | DNS & Email Security | DNS infrastructure and email security audit. Full subdomain enumeration, WHOIS, SPF/DMARC/DNSSEC checks, zone transfer detection, SMTP open relay testing |
| 21 | Network Perimeter - Large Scale | Large-scale network scanning. Masscan at 10k pps, Naabu verification, Nmap service detection, banner grabbing, Shodan + Censys enrichment |
Unlike built-in presets which only configure recon tools, user project presets save your entire project configuration -- recon pipeline, agent behavior, tool matrix, agent skills, CypherFix settings, and everything else. This lets you create and reuse complete project templates across different targets.
Presets are stored per-user in the database and available across all your projects.
- Configure a project form with all the settings you want (recon, agent, skills, etc.)
- Click "Save as Preset" in the form header bar
- Enter a name (required) and optional description
- Click Save

What gets saved: every project setting in the settings registry (about 630 of them) -- recon pipeline configuration, agent behavior, tool matrix, agent skills, CypherFix settings, GVM scan config, integration settings, and everything else in the form -- minus the excluded classes below. A setting the form has not loaded yet is saved at its default, so a preset saved while creating a project is as complete as one saved from an existing project.
What is excluded: these classes of column never ride along in either direction -- a preset never CAPTURES them and never APPLIES them, so a preset saved before this rule shipped cannot carry them either.
| Class | Why |
|---|---|
| The scope and uploaded files -- target domain, subdomain list, IP mode, target IPs, the domain batch, domain-ownership verification, the target guardrail, the other scans' targets (GitHub org, GVM targets, supply-chain repository / org and input mode), project name and description, every uploaded wordlist, template and document | A preset that carried them would point a second project at the first one's scope, or at a file only the first one uploaded |
| The whole engagement -- its LIMITS (the rate ceiling, the never-touch hosts, the scanning window, the agent's denylists), its RECORD (the client name, the contacts, the dates, the document text), its kind and its identity header | A limit belongs to ONE engagement, not to a reusable configuration. Loading a preset from project A into project B used to overwrite B's rate ceiling and exclusion list with A's, and copy A's client contact details across |
| Credentials -- the CypherFix GitHub token, the GraphQL auth value, the phishing SMTP config, the ownership token | A per-target credential applied to another project would be sent to a target it was never issued for |
| The project row itself -- id, owner, timestamps, activation state | Not settings. A preset carrying the project id made the receiving project's next save try to rewrite its key |
| Switches that are not scan configuration -- Allow MCP Sandbox Commands and Update Graph DB | A preset resets every setting it does not name to its default, and both default to ON. When presets carried them, loading ANY preset silently switched the MCP sandbox back on for a project where you had turned it off |
The excluded set is built from registry queries, not a list of column names. That distinction is load-bearing: these columns are still called roe* and will stay called that, but they no longer mean "the RoE block" -- fifteen of them became ordinary settings and the rest became the contract. A guard written as a name-prefix match would survive that reclassification by accident, so reclassifying a field or renaming a column moves this boundary with it automatically.
There are two ways to load a saved preset:
- "Load Preset" button in the form header bar -- opens a side drawer listing your saved presets
- "My Recon Presets" tab in the Recon Preset modal -- shows your presets alongside the built-in library
Click a preset to load it. A confirmation dialog warns that the project's current settings will be discarded and replaced. On confirm, every setting takes the preset's value, and any setting the preset does not store (one added after it was saved, or one an AI-generated preset left out) goes back to its default, so the result never depends on what was configured before. Both recon and non-recon tabs are updated; the excluded classes above are left exactly as they were.
On an existing project the loaded settings are saved immediately. Only the preset's settings are written: an unsaved edit to the target or the RoE stays unsaved. On a new project they are saved when you create it.
If something else changed the project while you had the settings page open (an MCP agent, or you in another tab), Update Settings stops with This project changed since you opened it (possibly by an MCP agent). Reload to see the current settings. instead of overwriting that change with the values your page loaded. Reload, then make your edit again. Uploading a file from inside the form does not trigger it.
While the project's saved settings still match the loaded preset, a Preset applied badge with a check mark and the preset's name shows at the right end of the tab bar. Change any preset setting and save (Update Settings, a workflow toggle, or an MCP write) and the badge disappears; the target, the RoE and the project name do not count, because they are not part of a preset.
The badge follows the preset it names. Rename one of your presets and the badge on every project that loaded it shows the new name; delete it and those badges go away, while the projects keep their settings. Changing a preset's values leaves the badge where it is: it says the project still holds what loading that preset produced. A badge from before this release keeps the name it was written with, and one that disappeared when two settings left presets (the MCP sandbox switch and graph writes) shows again.

An MCP agent holding Manage your recon preset library can create, change and delete your presets, and one holding Apply a recon preset to a project can load a preset into a project the way the form does (see MCP Server). A preset an agent wrote last shows an Edited by an MCP agent badge, with the token's prefix, in both lists, until a person saves over it. Check what such a preset holds before you load it.
With more than 10 saved presets, both lists show a Filter by name box, and the most recently changed preset is listed first.
Click the trash icon on any user preset card. A confirmation dialog appears before the preset is permanently deleted. Projects that loaded it keep their settings and lose only its Preset applied badge.
Describe your scanning goals in natural language and let an LLM generate a validated recon configuration for you. The AI generates recon pipeline parameters only (not agent or CypherFix settings). Once saved, the generated preset is stored in your My Project Presets collection and can be loaded like any other user preset.
This feature requires at least one AI Model Provider configured in Global Settings. It runs on your Recon preset generator model, chosen once for your account in Models by feature and run on your own keys; the first time you press Generate, you are asked to choose one. AWS Bedrock models cannot be used here and are not offered.
- Open the My Recon Presets tab in the Recon Preset modal
- Click "Generate with AI" (sparkle icon)
- Type a natural language description of what you want to scan and how
The badge above the text box reads Model: X · Change: your Recon preset generator model, with a link to switch it. Example prompts:
- "Fast passive scan focused on subdomain discovery and OSINT, no active probing"
- "Deep web app pentest with full crawling, directory fuzzing, and Nuclei on all severities"
- "Stealth mode: minimal noise, only passive tools, no port scanning"
- "API-focused scan: enable Kiterunner, Arjun on all methods, ffuf with API extensions, disable crawling and OSINT"
- "Bug bounty quick scan for a single target -- subdomain enum, httpx, Katana shallow crawl, Nuclei critical+high only, finish in under 15 minutes"
- "Cloud exposure audit: all OSINT providers maxed out, httpx with ASN and CDN detection, TLS analysis, security header checks, Nuclei cloud and misconfig templates"
- "Secret hunting: enable JS recon with all modules, GAU for historical URLs, ffuf with sensitive file extensions (.env, .bak, .conf), Nuclei exposure and token templates"
- "Large network perimeter scan for /24 CIDR: Masscan at high rate for port discovery, Naabu verification, Nmap service detection, banner grabbing, Shodan and Censys enrichment, CVE lookup"

After generation, a review screen shows:
- Enabled tools (green tags) -- tools the preset turns on
- Disabled tools (grey tags) -- tools explicitly turned off
- Tuned parameters -- count of numeric/threshold parameters adjusted
Enter a name (required) and optional description, then click "Save Preset" to add it to your My Project Presets collection. Click "Regenerate" to go back and try a different description.

All AI-generated presets are validated through a strict pipeline:
- The LLM output is parsed as JSON (markdown fences are stripped automatically)
- Every parameter is validated against a Zod schema covering all 328+ recon settings
- Unknown keys are stripped to prevent prompt injection
- Type coercion handles numbers and booleans from the LLM response
- If validation fails, the error details are shown so you can adjust your prompt
- Built-in recon presets store a partial configuration covering only recon pipeline parameters. Any parameter not in the preset keeps its server default. They are read-only and ship with the application
- User project presets store all project settings (recon + agent + skills + CypherFix + everything else), minus target identity, uploaded files and the entire engagement. They are stored per-user in PostgreSQL and can be created, loaded, and deleted at any time
- AI-generated presets produce recon-only parameters (validated against a 328-parameter Zod schema), then get saved into the user preset collection like any manually saved preset
- Loading merges preset values over server defaults, then applies to the form. Target fields and the engagement are never overwritten, at capture OR at apply
-
extractPresetSettings()strips the excluded columns before saving;stripExcludedOnApply()strips them again when a preset is loaded. Both, not either: the first stops new presets carrying them, the second neutralises every preset saved before the rule existed -
The engagement's own defaults never reach the form either.
/api/projects/defaultsdeliberately emits no engagement limit, because a limit is a property of one engagement rather than of the installation. Applying a preset resets every field that appears in that payload, so a default there would zero a configured rate ceiling and empty an exclusion list on every preset apply
- Creating a Project -- full project form walkthrough
- Running Reconnaissance -- the parallelized scanning pipeline
- Project Settings Reference -- complete list of all 196+ configurable parameters
- AI Model Providers -- set up LLM providers for AI-generated presets
Getting Started
- Getting Started
- Deploying to a Server
- User Management & Roles
- Creating a Project
- Recon Presets
- Global Settings
Core Workflow
- Red Zone
- Recon Pipeline Workflow
- Running Reconnaissance
- Scan Timeline
- AI Agent Guide
- Fireteam — Parallel Specialists
- Exploit-Path Search (LATS)
- Agent Workspace
- Reverse Shells
Scanning & OSINT
- AI in the Recon Pipeline
- Adversarial AI Recon
- AI Gauntlet
- JS Reconnaissance
- GraphQL Security Testing
- Subdomain Takeover Detection
- VHost & SNI Enumeration
- TLS Certificate Grab
- Web Cache Poisoning
- Serialized Object Detection
- Origin Discovery
- GVM Vulnerability Scanning
- GitHub Secret Hunting
- Secret Multiscanner
- Supply-Chain Scanning
AI & Automation
- AI Model Providers
- MCP Tool Plugins
- MCP Server
- Knowledge Base & Web Search
- Agent Skills
- Chat Skills
- Tradecraft Lookup
- CVE Intel
- Playwright Browser Automation
- CypherFix — Automated Remediation
- Priority Board
- Rules of Engagement (RoE)
HackLab
Analysis & Reporting
- Insights Dashboard
- TrafficMind
- Authenticated Session Recording
- proxy_brain — web hacking in code
- Pentest Reports
- Attack Surface Graph
- Surface Shaper
- EvoGraph — Attack Chain Evolution
- Data Export & Import
Contributing
Reference & Help