AutoRecon AI combines Nmap scanning, Python automation, and a local LLM (Ollama) to perform automated reconnaissance, service analysis, and security triage for network environments.
The tool is designed for security labs, learning environments, and defensive analysis.
• Automated Nmap scanning
• XML parsing and structured service extraction
• Host classification (Windows / Linux / Network device / Unknown)
• Full network overview scanning
• Target prioritization for further analysis
• AI-assisted service analysis using a local LLM
• Service-specific enumeration hints
• Security remediation suggestions
• Local-first architecture (no cloud APIs required)
Kali / Linux machine
│
├─ Nmap scanning
│
├─ Python parser
│
├─ Host classification
│
└─ AI analysis via Ollama API
↓
LLM Server (Ollama)
Model example:
qwen2.5:7b
The system can run:
• entirely locally
• with a remote LLM server
• across VLANs using Tailscale
scan → parse → classify → analyze → report
python3 main.py 192.168.1.0/24
Network overview example output:
" # AutoRecon AI Network Overview
**Target Network:** 192.168.X.X/24
**Scan Mode:** network_overview
**Generated:** 2026-03-12 23:04:18
## Overview
- Active hosts: 22
- Hosts with open ports: 11
- Likely Windows: 0
- Likely Linux: 2
- Likely network devices: 1
- Likely IoT/embedded: 0
- Unknown: 19
## Discovered Hosts
| IP | Status | Open Ports | Likely Type | Notes |
|----|--------|------------|-------------|-------|
| 192.168.x.1 | up | 53, 80 | network-device | Likely gateway, firewall, router, or DNS-enabled net>
| 192.168.x.2 | up | 80 | unknown | Insufficient evidence for confident classification. |
| 192.168.x.3 | up | 80 | unknown | Insufficient evidence for confident classification. |
| 192.168.x.4 | up | 80 | unknown | Insufficient evidence for confident classification. |
| 192.168.x.5 | up | 80 | unknown | Insufficient evidence for confident classification. |
| 192.168.x.6 | up | 8080 | unknown | Insufficient evidence for confident classification. |
| 192.168.x.7 | up | none | unknown | Host is up but no open ports were detected in this scan. |
| 192.168.x.8 | up | none | unknown | Host is up but no open ports were detected in this scan. |
| 192.168.x.11 | up | 22, 80, 443 | linux | Likely Linux host based on SSH/banner details. |
| 192.168.x.13 | up | none | unknown | Host is up but no open ports were detected in this scan. |
| 192.168.x.14 | up | none | unknown | Host is up but no open ports were detected in this scan. |
| 192.168.x.15 | up | none | unknown | Host is up but no open ports were detected in this scan. |
| 192.168.x.17 | up | none | unknown | Host is up but no open ports were detected in this scan. |
| 192.168.x.18 | up | none | unknown | Host is up but no open ports were detected in this scan. |
| 192.168.x.19 | up | none | unknown | Host is up but no open ports were detected in this scan. |
| 192.168.x.20 | up | 80 | unknown | Insufficient evidence for confident classification. |
| 192.168.x.27 | up | none | unknown | Host is up but no open ports were detected in this scan. |
| 192.168.x.29 | up | 80, 443 | unknown | Insufficient evidence for confident classification. |
| 192.168.x.30 | up | 22, 111 | linux | Likely Linux host based on SSH/banner details. |
| 192.168.x.101 | up | none | unknown | Host is up but no open ports were detected in this scan. |
| 192.168.x.102 | up | 80 | unknown | Insufficient evidence for confident classification. |
| 192.168.x.103 | up | none | unknown | Host is up but no open ports were detected in this scan. |
## Interpretation
This network appears to contain a mixture of servers, network infrastructure, and possibly embedded>
Further investigation should prioritize hosts exposing multiple services or critical infrastructure>
## Suggested Next Hosts to Analyze
- `192.168.x.11`
- `192.168.x.1`
- `192.168.x.29`
- `192.168.x.2`
- `192.168.x.3`
## Suggested Next Commands
- Deep analysis of one host:
- `python3 main.py <ip>`
- `python3 main.py <ip> dual`
- `python3 main.py <ip> offensive`
- `python3 main.py <ip> defensive`
- If a host appears filtered:
- `nmap -Pn -sC -sV <ip>`
- `nmap -Pn -p- <ip>`
dual offensive defensive
Active hosts: 22 Hosts with open ports: 11 Likely Linux: 2 Likely network devices: 1
Hosts are classified automatically and prioritized for investigation.
Example detected services: 135/tcp msrpc 139/tcp netbios-ssn 445/tcp microsoft-ds 3389/tcp rdp 5985/tcp winrm
The LLM generates:
• safe enumeration steps
• possible attack paths (lab environments only)
• remediation suggestions
• risk analysis
git clone https://github.com/andreagovons/autorecon-ai.git cd autorecon-ai
python3 -m venv .venv source .venv/bin/activate
pip install -r requirements.txt
cp .env.example .env
Example .env:
OLLAMA_URL=http://localhost:11434/api/generate
OLLAMA_MODEL=qwen2.5:7b
OLLAMA_TIMEOUT=420
If using a remote LLM server, update the URL accordingly.
• Python 3.10+
• Nmap installed
• Ollama installed
• LLM model (example):
Network scan: python3 main.py 192.168.1.100
Advanced modes: python3 main.py 192.168.1.100 dual python3 main.py 192.168.1.100 offensive python3 main.py 192.168.1.100 defensive
autorecon-ai
│
├── core
│ ├── analyzer.py
│ ├── classifier.py
│ ├── parser.py
│ ├── reporter.py
│ ├── scanner.py
│ └── utils.py
│
├── scans
├── reports
│
├── main.py
├── requirements.txt
├── .env.example
├── README.md
└── .gitignore
This tool is intended for:
• personal labs
• educational environments
• authorized testing
Do not use against systems without permission.
• risk scoring system
• network attack surface summary
• JSON / CSV export
• improved service fingerprinting
• automatic enumeration plugins
• vulnerability database integration
• exploit suggestion mapping
• graphical network visualization
The goal of this project is to explore the intersection of:
• network reconnaissance
• security automation
• AI-assisted analysis
while keeping the entire workflow local-first and privacy friendly.
MIT License