Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Local-first AI-assisted network reconnaissance and host triage tool

AutoRecon AI combines Nmap scanning, Python automation, and a local LLM (Ollama) to perform automated reconnaissance, service analysis, and security triage for network environments.

The tool is designed for security labs, learning environments, and defensive analysis.


Features

• Automated Nmap scanning
• XML parsing and structured service extraction
• Host classification (Windows / Linux / Network device / Unknown)
• Full network overview scanning
• Target prioritization for further analysis
• AI-assisted service analysis using a local LLM
• Service-specific enumeration hints
• Security remediation suggestions
• Local-first architecture (no cloud APIs required)


Architecture

Kali / Linux machine
│
├─ Nmap scanning
│
├─ Python parser
│
├─ Host classification
│
└─ AI analysis via Ollama API
↓

LLM Server (Ollama)

Model example:
qwen2.5:7b

The system can run:

• entirely locally
• with a remote LLM server
• across VLANs using Tailscale


Example Workflow

scan → parse → classify → analyze → report

Example commands:

python3 main.py 192.168.1.0/24

Network overview example output: 
 " # AutoRecon AI Network Overview

**Target Network:** 192.168.X.X/24
**Scan Mode:** network_overview
**Generated:** 2026-03-12 23:04:18

## Overview

- Active hosts: 22
- Hosts with open ports: 11
- Likely Windows: 0
- Likely Linux: 2
- Likely network devices: 1
- Likely IoT/embedded: 0
- Unknown: 19

## Discovered Hosts
| IP | Status | Open Ports | Likely Type | Notes |
|----|--------|------------|-------------|-------|
| 192.168.x.1 | up | 53, 80 | network-device | Likely gateway, firewall, router, or DNS-enabled net>
| 192.168.x.2 | up | 80 | unknown | Insufficient evidence for confident classification. |
| 192.168.x.3 | up | 80 | unknown | Insufficient evidence for confident classification. |
| 192.168.x.4 | up | 80 | unknown | Insufficient evidence for confident classification. |
| 192.168.x.5 | up | 80 | unknown | Insufficient evidence for confident classification. |
| 192.168.x.6 | up | 8080 | unknown | Insufficient evidence for confident classification. |
| 192.168.x.7 | up | none | unknown | Host is up but no open ports were detected in this scan. |
| 192.168.x.8 | up | none | unknown | Host is up but no open ports were detected in this scan. |
| 192.168.x.11 | up | 22, 80, 443 | linux | Likely Linux host based on SSH/banner details. |
| 192.168.x.13 | up | none | unknown | Host is up but no open ports were detected in this scan. |
| 192.168.x.14 | up | none | unknown | Host is up but no open ports were detected in this scan. |
| 192.168.x.15 | up | none | unknown | Host is up but no open ports were detected in this scan. |
| 192.168.x.17 | up | none | unknown | Host is up but no open ports were detected in this scan. |
| 192.168.x.18 | up | none | unknown | Host is up but no open ports were detected in this scan. |
| 192.168.x.19 | up | none | unknown | Host is up but no open ports were detected in this scan. |
| 192.168.x.20 | up | 80 | unknown | Insufficient evidence for confident classification. |
| 192.168.x.27 | up | none | unknown | Host is up but no open ports were detected in this scan. |
| 192.168.x.29 | up | 80, 443 | unknown | Insufficient evidence for confident classification. |
| 192.168.x.30 | up | 22, 111 | linux | Likely Linux host based on SSH/banner details. |
| 192.168.x.101 | up | none | unknown | Host is up but no open ports were detected in this scan. |
| 192.168.x.102 | up | 80 | unknown | Insufficient evidence for confident classification. |
| 192.168.x.103 | up | none | unknown | Host is up but no open ports were detected in this scan. |

## Interpretation
This network appears to contain a mixture of servers, network infrastructure, and possibly embedded>

Further investigation should prioritize hosts exposing multiple services or critical infrastructure>

## Suggested Next Hosts to Analyze

- `192.168.x.11`
- `192.168.x.1`
- `192.168.x.29`
- `192.168.x.2`
- `192.168.x.3`
## Suggested Next Commands

- Deep analysis of one host:
  - `python3 main.py <ip>`
  - `python3 main.py <ip> dual`
  - `python3 main.py <ip> offensive`
  - `python3 main.py <ip> defensive`
- If a host appears filtered:
  - `nmap -Pn -sC -sV <ip>`
  - `nmap -Pn -p- <ip>`

Modes available:

dual offensive defensive


Example Output

Network Overview

Active hosts: 22 Hosts with open ports: 11 Likely Linux: 2 Likely network devices: 1

Hosts are classified automatically and prioritized for investigation.

Example: 192.168.0.11 → linux 192.168.0.1 → network-device 192.168.0.29 → unknown

Host Analysis

Example detected services: 135/tcp msrpc 139/tcp netbios-ssn 445/tcp microsoft-ds 3389/tcp rdp 5985/tcp winrm

The LLM generates:

• safe enumeration steps
• possible attack paths (lab environments only)
• remediation suggestions
• risk analysis


Installation

Clone the repository:

git clone https://github.com/andreagovons/autorecon-ai.git cd autorecon-ai

Create virtual environment:

python3 -m venv .venv source .venv/bin/activate

Install dependencies:

pip install -r requirements.txt


Configuration

Create environment configuration:

cp .env.example .env

Example .env: OLLAMA_URL=http://localhost:11434/api/generate OLLAMA_MODEL=qwen2.5:7b OLLAMA_TIMEOUT=420

If using a remote LLM server, update the URL accordingly.


Requirements

• Python 3.10+
• Nmap installed
• Ollama installed
• LLM model (example):

ollama pull qwen2.5:7b

Usage

Network scan: python3 main.py 192.168.1.100

Advanced modes: python3 main.py 192.168.1.100 dual python3 main.py 192.168.1.100 offensive python3 main.py 192.168.1.100 defensive


Project Structure

autorecon-ai
│
├── core
│   ├── analyzer.py
│   ├── classifier.py
│   ├── parser.py
│   ├── reporter.py
│   ├── scanner.py
│   └── utils.py
│
├── scans
├── reports
│
├── main.py
├── requirements.txt
├── .env.example
├── README.md
└── .gitignore

Security Notice

This tool is intended for:

• personal labs
• educational environments
• authorized testing

Do not use against systems without permission.


Roadmap

V1.2

• risk scoring system
• network attack surface summary
• JSON / CSV export
• improved service fingerprinting

V2

• automatic enumeration plugins
• vulnerability database integration
• exploit suggestion mapping
• graphical network visualization


Why This Project

The goal of this project is to explore the intersection of:

• network reconnaissance
• security automation
• AI-assisted analysis

while keeping the entire workflow local-first and privacy friendly.


License

MIT License

About

AI-assisted network reconnaissance tool combining Nmap scanning, host classification and local LLM analysis via Ollama.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages