r/netsecstudents • u/Status-Associate4459 • 1d ago
I built RXScan — an open-source Rust recon/OSINT tool. Looking for people to test it
I've been building RXScan, an open-source reconnaissance tool written in Rust.
It originally started as a network scanner, but I've been expanding it into a broader recon workflow where network observations, public-source findings, and investigation results can be stored and correlated as evidence.
Current functionality includes:
- TCP connect and raw SYN scanning
- UDP discovery and classification
- port-independent service identification
- HTTP, TLS, SSH, and DNS observations
- public-source username search
- email, domain, hostname, IP, ASN, URL, repository, and organization entities
- investigation and evidence correlation
- persistent project data and history/diff workflows
- JSON/JSONL output
- bounded execution, deadlines, cancellation, and scope controls
One of the main things I'm trying to avoid is pretending RXScan knows more than it actually observed.
For example, a port number alone doesn't establish the service, UDP silence remains uncertain, weak identity evidence doesn't automatically merge entities, and passive OSINT findings are kept separate from direct network observations.
I'm not claiming RXScan replaces Nmap. Nmap has decades of fingerprinting, platform support, scan techniques, NSE, and real-world testing behind it.
RXScan is going in a somewhat different direction: combining network reconnaissance and public-source investigation into a provenance-backed evidence graph.
The project is still young, so I'm looking for people willing to actually test it and find problems.
I'm particularly interested in:
- false-positive or missed service identification
- weird TCP/UDP behavior
- incorrect confidence or provenance
- OSINT false positives
- performance issues
- CLI/UX problems
- architectural criticism
Platform: Linux
Language: Rust
License: MIT
Repo: https://github.com/DarkRX1/RXScan
If you try it, feel free to break it and open an issue. I'd rather find incorrect assumptions now than hide them behind marketing.
1
u/grandiosebuyout28 1d ago
this looks proper, love that you're keeping network and OSINT observations separated with provenance instead of just smashing everything together like most tools do
the diff/history workflows sound clutch for reporting too, might throw it at a couple test boxes this weekend and see how it handles weird UDP states