# External Security Tools Integrated into Shannon: Nmap, Subfinder, WhatWeb, and Schemathesis

> Shannon's Pre-Recon phase integrates Nmap, Subfinder, WhatWeb, and Schemathesis concurrently for network discovery, subdomain enumeration, technology fingerprinting, and API schema testing.

- Repository: [KeygraphHQ/shannon](https://github.com/keygraphhq/shannon)
- Tags: how-to-guide
- Published: 2026-02-16

---

**Shannon integrates four external security tools—nmap, subfinder, whatweb, and schemathesis—into its Pre‑Recon phase, executing them concurrently during Wave 1 of the penetration testing pipeline to perform network discovery, subdomain enumeration, technology fingerprinting, and API schema testing.**

The KeygraphHQ/shannon repository automates penetration testing workflows by orchestrating industry‑standard command‑line scanners. Understanding the external security tools integrated into Shannon is essential for security engineers who want to leverage automated network reconnaissance and API testing capabilities without manually coordinating multiple binaries.

## The Four External Security Tools in Shannon's Pre‑Recon Phase

Shannon defines supported scanners in `src/tool‑checker.ts` as a union type `ToolName` and a configuration map that includes installation hints【L10‑L21】. The actual invocation happens in `src/phases/pre‑recon.ts` inside a `switch` statement that routes each tool to its specific command‑line arguments【L72‑L124】.

### Nmap for Network Service Discovery

**Nmap** handles network service discovery and version detection against the target URL.

- **Definition**: Listed in the `ToolName` union and `tools` map in `src/tool‑checker.ts` with installation guidance【L10‑L18】【L52‑L53】.
- **Execution**: Triggered in `src/phases/pre‑recon.ts` under `case 'nmap':`【L72‑L78】. Shannon spawns a subprocess running `nmap -sV --version-intensity 5 -p- <target>`.

### Subfinder for Subdomain Enumeration

**Subfinder** performs high‑speed subdomain enumeration for the target host.

- **Definition**: Declared in `src/tool‑checker.ts` alongside other supported tools【L10‑L19】 with install notes at【L53‑L54】.
- **Execution**: Invoked in `src/phases/pre‑recon.ts` via `case 'subfinder':`【L80‑L86】, executing `subfinder -d <domain> -all`.

### WhatWeb for Technology Fingerprinting

**WhatWeb** identifies web technologies, CMS platforms, and server frameworks.

- **Definition**: Registered in `src/tool‑checker.ts`【L10‑L20】 with installation hint【L54‑L55】.
- **Execution**: Called in `src/phases/pre‑recon.ts` under `case 'whatweb':`【L88‑L95】, running `whatweb -a 3 <url>`.

### Schemathesis for API Schema Testing

**Schemathesis** runs automated property‑based tests against OpenAPI/Swagger schemas discovered during the code‑analysis stage.

- **Definition**: Included in the `ToolName` union in `src/tool‑checker.ts`【L10‑L21】 with pip‑install guidance【L55‑L56】.
- **Execution**: Launched in `src/phases/pre‑recon.ts` via `case 'schemathesis':`【L97‑L124】. The logic iterates over schema files extracted earlier and executes `schemathesis run <schema> --base-url <target>`.

## How Shannon Orchestrates External Security Tools

Shannon does not run tools sequentially; instead, it builds an `operations` array and executes eligible scanners concurrently during the Pre‑Recon phase.

### Tool Availability Detection

Before execution, `src/tool‑checker.ts` verifies whether each binary exists on the host system. The `tools` map stores boolean availability flags and installation commands【L52‑L56】. Only tools marked as available are added to the operations queue.

### Concurrent Execution Pattern

In `src/phases/pre‑recon.ts`, the orchestrator constructs the `operations` array by checking `toolAvailability` flags:

```typescript
// src/phases/pre-recon.ts (excerpt)
if (toolAvailability.nmap)   operations.push(runTerminalScan('nmap', webUrl));
if (toolAvailability.subfinder) operations.push(runTerminalScan('subfinder', webUrl));
if (toolAvailability.whatweb)   operations.push(runTerminalScan('whatweb', webUrl));
if (toolAvailability.schemathesis) operations.push(runTerminalScan('schemathesis', webUrl, sourceDir));

```

These operations are then executed in parallel using `Promise.all`, and the resulting `TerminalScanResult` objects are merged into the Wave 1 report.

## Running Shannon with External Security Tools

### Default Execution

To run Shannon with all available external security tools, ensure the binaries are installed on your system (the CLI will prompt with installation commands from `src/tool‑checker.ts` if any are missing):

```bash

# Install dependencies (macOS example)

brew install nmap
go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest
brew install whatweb
pip install schemathesis

# Run Shannon

./shannon start URL=https://example.com REPO=my-repo

```

During this execution, Shannon will launch nmap, subfinder, whatweb, and schemathesis concurrently during the Pre‑Recon phase, embedding their raw stdout into the generated report under sections for network scanning, subdomain discovery, technology detection, and API schema testing.

### CI and Testing Mode

For continuous integration environments or rapid dry‑runs where you want to skip the heavy external scans, set the `PIPELINE_TESTING` environment variable:

```bash
PIPELINE_TESTING=true ./shannon start URL=https://example.com REPO=my-repo

```

When `PIPELINE_TESTING=true`, the `runTerminalScan` calls are replaced by `skippedResult` placeholders【pre‑recon.ts L174‑L176】, producing a lightweight report while still exercising the rest of the workflow logic.

## Extending Shannon with Additional Security Tools

To integrate a new external scanner into Shannon’s Pre‑Recon phase, modify three specific locations in the source code:

1. **Register the tool** in `src/tool‑checker.ts`:
   - Add the tool name to the `ToolName` union type【L10‑L21】.
   - Add an entry to the `tools` map with availability flag and installation command【L52‑L56】.

2. **Implement the execution logic** in `src/phases/pre‑recon.ts`:
   - Add a `case` block inside the tool switch statement【L72‑L124】 that constructs the command arguments and spawns the subprocess.

3. **Update the orchestration** in `src/phases/pre‑recon.ts`:
   - Add an availability check to the `operations` array builder so the tool runs concurrently with the others when present.

```typescript
// Example: Adding masscan (illustrative)
// src/tool-checker.ts
type ToolName = 'nmap' | 'subfinder' | 'whatweb' | 'schemathesis' | 'masscan';
...
masscan: false,
...
'masscan': 'apt install masscan',

// src/phases/pre-recon.ts
case 'masscan': {
  result = await $({ silent: true, stdio: ['ignore', 'pipe', 'ignore'] })`masscan -p0-65535 ${target}`;
  // ... build and return TerminalScanResult
}

```

## Summary

- **Shannon integrates four external security tools**—**nmap**, **subfinder**, **whatweb**, and **schemathesis**—into its automated penetration testing pipeline.
- **All tools execute during the Pre‑Recon phase** (Wave 1), running concurrently via an `operations` array built in `src/phases/pre‑recon.ts`.
- **Tool availability is verified** by `src/tool‑checker.ts`, which defines the `ToolName` union, binary detection logic, and installation hints.
- **CI environments can skip heavy scans** by setting `PIPELINE_TESTING=true`, which triggers placeholder results instead of invoking the external binaries.
- **The architecture is extensible**: adding a new scanner requires updating the `ToolName` type, the `tools` map, and adding a `case` block in the Pre‑Recon phase.

## Frequently Asked Questions

### What external security tools does Shannon support out of the box?

Shannon supports four command‑line scanners: **nmap** for network service discovery, **subfinder** for subdomain enumeration, **whatweb** for technology fingerprinting, and **schemathesis** for automated API testing against OpenAPI schemas. These are defined in `src/tool‑checker.ts` and invoked during the Pre‑Recon phase.

### When does Shannon execute these external tools during a scan?

The tools are executed during the **Pre‑Recon phase** (also referred to as Wave 1), which is the first stage of Shannon’s penetration testing pipeline. The orchestrator in `src/phases/pre‑recon.ts` builds an `operations` array and runs all available tools concurrently using `Promise.all`.

### Can I run Shannon without installing the external security tools?

Yes, but with limited functionality. If the binaries are missing, Shannon will skip the external scans and note their absence in the report. For CI environments or dry‑runs, set the environment variable `PIPELINE_TESTING=true` to bypass the external tool execution entirely and receive placeholder results instead.

### How do I add a custom security scanner to Shannon?

To integrate a new tool, modify `src/tool‑checker.ts` to add the tool name to the `ToolName` union and the `tools` map with installation instructions. Then, in `src/phases/pre‑recon.ts`, add a `case` block to handle the tool’s command‑line invocation and append an availability check to the `operations` array so it runs concurrently with the other scanners.