PhantomRecon is a CLI-based, modular, agent-driven red team automation tool designed to demonstrate autonomous offensive security workflows powered by AI (Google's Gemini via Agent Development Kit - ADK).
# PhantomRecon
[](https://opensource.org/licenses/MIT)
**PhantomRecon** is a CLI-based, modular, agent-driven red team automation tool designed to demonstrate autonomous offensive security workflows powered by AI (Google's Gemini via Agent Development Kit - ADK).
## Quick Start (CLI)
- Run interactive console (metasploit-style):
```bash
python -m phantomrecon
```
- One-shot non-interactive run:
```bash
python -m phantomrecon --target example.com --auto \
--nmap-timeout 30 --nmap-top-ports 100 --nmap-args "-sV -Pn"
```
### CLI options
- `--target <domain|ip>`: Target to assess
- `--auto`: Run recon → plan → route → report
- `--nmap-timeout <seconds>`: Overrides `NMAP_TIMEOUT`
- `--nmap-top-ports <N>`: Overrides `NMAP_TOP_PORTS`
- `--nmap-args "..."`: Appends to Nmap args (`NMAP_ARGS`)
- `--nmap-disable`: Disable Nmap (sets `NMAP_DISABLE=1`)
Environment variables are also supported directly: `NMAP_TIMEOUT`, `NMAP_TOP_PORTS`, `NMAP_ARGS`, `NMAP_DISABLE`.
## Operational hygiene
- Reports are not versioned. `.gitignore` excludes `reports/*` except `reports/sample_report.md`.
- Generated HTML/MD reports live under `reports/` locally only.
- Remove or rotate reports as needed; they are never uploaded in commits.
Built as a proof-of-concept, it simulates identifying a target, performing broad reconnaissance (Nmap, DNS, Web Search), planning an attack strategy using an LLM, executing simulated exploits conditionally, and generating a report.
## Project Structure
```
phantomrecon/
├── phantomrecon/ # Main package (exported orchestrator agent)
│ ├── __init__.py
│ ├── __main__.py # CLI entrypoint (interactive and non-interactive)
│ └── agent/ # Agent graph and tools
├── agents/ # Python modules containing agent/tool logic
│ ├── recon_logic.py # Nmap, DNS (dig), seeded web analysis; ADK search enabled
│ ├── routing_Google's AI-powered research notebook that ingests your documents and becomes an expert on your content. Generates audio overviews, study guides, FAQs, and interactive discussions from uploaded sources.
Google DeepMind's experimental AI agent that can navigate websites, fill forms, and complete multi-step browser tasks autonomously. Uses Gemini's multimodal understanding to interact with web interfaces.
Google DeepMind's universal AI assistant prototype that can see, hear, and respond in real-time through your device camera and microphone. Demonstrates the future of multimodal AI interaction.
Google Cloud's enterprise platform for building, deploying, and managing AI agents powered by Gemini. Supports multi-agent orchestration, tool integration, and enterprise governance.
Gemini's agentic research capability that autonomously browses the web, synthesizes information from dozens of sources, and produces comprehensive research reports on any topic.
Interactive coding and content creation agent that generates, previews, and iterates on code, documents, and interactive applications in a side panel. Supports HTML/CSS/JS, Python, and more.