External Security Tools Integrated into Shannon: Nmap, Subfinder, WhatWeb, and Schemathesis
Shannon integrates four external security tools—nmap, subfinder, whatweb, and schemathesis—into its Pre‑Recon phase, executing them concurrently during Wave 1 of the penetration testing pipeline to perform network discovery, subdomain enumeration, technology fingerprinting, and API schema testing.
The KeygraphHQ/shannon repository automates penetration testing workflows by orchestrating industry‑standard command‑line scanners. Understanding the external security tools integrated into Shannon is essential for security engineers who want to leverage automated network reconnaissance and API testing capabilities without manually coordinating multiple binaries.
The Four External Security Tools in Shannon's Pre‑Recon Phase
Shannon defines supported scanners in src/tool‑checker.ts as a union type ToolName and a configuration map that includes installation hints【L10‑L21】. The actual invocation happens in src/phases/pre‑recon.ts inside a switch statement that routes each tool to its specific command‑line arguments【L72‑L124】.
Nmap for Network Service Discovery
Nmap handles network service discovery and version detection against the target URL.
- Definition: Listed in the
ToolNameunion andtoolsmap insrc/tool‑checker.tswith installation guidance【L10‑L18】【L52‑L53】. - Execution: Triggered in
src/phases/pre‑recon.tsundercase 'nmap':【L72‑L78】. Shannon spawns a subprocess runningnmap -sV --version-intensity 5 -p- <target>.
Subfinder for Subdomain Enumeration
Subfinder performs high‑speed subdomain enumeration for the target host.
- Definition: Declared in
src/tool‑checker.tsalongside other supported tools【L10‑L19】 with install notes at【L53‑L54】. - Execution: Invoked in
src/phases/pre‑recon.tsviacase 'subfinder':【L80‑L86】, executingsubfinder -d <domain> -all.
WhatWeb for Technology Fingerprinting
WhatWeb identifies web technologies, CMS platforms, and server frameworks.
- Definition: Registered in
src/tool‑checker.ts【L10‑L20】 with installation hint【L54‑L55】. - Execution: Called in
src/phases/pre‑recon.tsundercase 'whatweb':【L88‑L95】, runningwhatweb -a 3 <url>.
Schemathesis for API Schema Testing
Schemathesis runs automated property‑based tests against OpenAPI/Swagger schemas discovered during the code‑analysis stage.
- Definition: Included in the
ToolNameunion insrc/tool‑checker.ts【L10‑L21】 with pip‑install guidance【L55‑L56】. - Execution: Launched in
src/phases/pre‑recon.tsviacase 'schemathesis':【L97‑L124】. The logic iterates over schema files extracted earlier and executesschemathesis run <schema> --base-url <target>.
How Shannon Orchestrates External Security Tools
Shannon does not run tools sequentially; instead, it builds an operations array and executes eligible scanners concurrently during the Pre‑Recon phase.
Tool Availability Detection
Before execution, src/tool‑checker.ts verifies whether each binary exists on the host system. The tools map stores boolean availability flags and installation commands【L52‑L56】. Only tools marked as available are added to the operations queue.
Concurrent Execution Pattern
In src/phases/pre‑recon.ts, the orchestrator constructs the operations array by checking toolAvailability flags:
// src/phases/pre-recon.ts (excerpt)
if (toolAvailability.nmap) operations.push(runTerminalScan('nmap', webUrl));
if (toolAvailability.subfinder) operations.push(runTerminalScan('subfinder', webUrl));
if (toolAvailability.whatweb) operations.push(runTerminalScan('whatweb', webUrl));
if (toolAvailability.schemathesis) operations.push(runTerminalScan('schemathesis', webUrl, sourceDir));
These operations are then executed in parallel using Promise.all, and the resulting TerminalScanResult objects are merged into the Wave 1 report.
Running Shannon with External Security Tools
Default Execution
To run Shannon with all available external security tools, ensure the binaries are installed on your system (the CLI will prompt with installation commands from src/tool‑checker.ts if any are missing):
# Install dependencies (macOS example)
brew install nmap
go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest
brew install whatweb
pip install schemathesis
# Run Shannon
./shannon start URL=https://example.com REPO=my-repo
During this execution, Shannon will launch nmap, subfinder, whatweb, and schemathesis concurrently during the Pre‑Recon phase, embedding their raw stdout into the generated report under sections for network scanning, subdomain discovery, technology detection, and API schema testing.
CI and Testing Mode
For continuous integration environments or rapid dry‑runs where you want to skip the heavy external scans, set the PIPELINE_TESTING environment variable:
PIPELINE_TESTING=true ./shannon start URL=https://example.com REPO=my-repo
When PIPELINE_TESTING=true, the runTerminalScan calls are replaced by skippedResult placeholders【pre‑recon.ts L174‑L176】, producing a lightweight report while still exercising the rest of the workflow logic.
Extending Shannon with Additional Security Tools
To integrate a new external scanner into Shannon’s Pre‑Recon phase, modify three specific locations in the source code:
-
Register the tool in
src/tool‑checker.ts:- Add the tool name to the
ToolNameunion type【L10‑L21】. - Add an entry to the
toolsmap with availability flag and installation command【L52‑L56】.
- Add the tool name to the
-
Implement the execution logic in
src/phases/pre‑recon.ts:- Add a
caseblock inside the tool switch statement【L72‑L124】 that constructs the command arguments and spawns the subprocess.
- Add a
-
Update the orchestration in
src/phases/pre‑recon.ts:- Add an availability check to the
operationsarray builder so the tool runs concurrently with the others when present.
- Add an availability check to the
// Example: Adding masscan (illustrative)
// src/tool-checker.ts
type ToolName = 'nmap' | 'subfinder' | 'whatweb' | 'schemathesis' | 'masscan';
...
masscan: false,
...
'masscan': 'apt install masscan',
// src/phases/pre-recon.ts
case 'masscan': {
result = await $({ silent: true, stdio: ['ignore', 'pipe', 'ignore'] })`masscan -p0-65535 ${target}`;
// ... build and return TerminalScanResult
}
Summary
- Shannon integrates four external security tools—nmap, subfinder, whatweb, and schemathesis—into its automated penetration testing pipeline.
- All tools execute during the Pre‑Recon phase (Wave 1), running concurrently via an
operationsarray built insrc/phases/pre‑recon.ts. - Tool availability is verified by
src/tool‑checker.ts, which defines theToolNameunion, binary detection logic, and installation hints. - CI environments can skip heavy scans by setting
PIPELINE_TESTING=true, which triggers placeholder results instead of invoking the external binaries. - The architecture is extensible: adding a new scanner requires updating the
ToolNametype, thetoolsmap, and adding acaseblock in the Pre‑Recon phase.
Frequently Asked Questions
What external security tools does Shannon support out of the box?
Shannon supports four command‑line scanners: nmap for network service discovery, subfinder for subdomain enumeration, whatweb for technology fingerprinting, and schemathesis for automated API testing against OpenAPI schemas. These are defined in src/tool‑checker.ts and invoked during the Pre‑Recon phase.
When does Shannon execute these external tools during a scan?
The tools are executed during the Pre‑Recon phase (also referred to as Wave 1), which is the first stage of Shannon’s penetration testing pipeline. The orchestrator in src/phases/pre‑recon.ts builds an operations array and runs all available tools concurrently using Promise.all.
Can I run Shannon without installing the external security tools?
Yes, but with limited functionality. If the binaries are missing, Shannon will skip the external scans and note their absence in the report. For CI environments or dry‑runs, set the environment variable PIPELINE_TESTING=true to bypass the external tool execution entirely and receive placeholder results instead.
How do I add a custom security scanner to Shannon?
To integrate a new tool, modify src/tool‑checker.ts to add the tool name to the ToolName union and the tools map with installation instructions. Then, in src/phases/pre‑recon.ts, add a case block to handle the tool’s command‑line invocation and append an availability check to the operations array so it runs concurrently with the other scanners.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →