A practical guide to automating bug bounty reconnaissance using a Python script that orchestrates Subfinder, Httpx, Nuclei, and Nmap. The workflow discovers subdomains, filters live hosts, runs 9,000+ vulnerability templates via Nuclei, and performs port scanning — all generating a consolidated report. Includes an advanced extension using Waybackurls for historical URL discovery, ethical usage rules, and tips on what to do when vulnerabilities are found.
Table of contents
What Is Recon and Why Automate It?Tools We’ll UseGet Hacker MD’s stories in your inboxThe Recon Automation ScriptHow to Run ItUnderstanding Each StepStep 1 SubfinderStep 2 HttpxStep 3 NucleiStep 4 NmapAdvanced: Adding Waybackurls for Historical ReconImportant Rules — Read ThisReal Results From My WorkflowWhat to Do When Nuclei Finds SomethingFinal Thoughts724 Impressions