Quick Contact

Talk to our team

Social

fb-footer
instagram-footer
Twiiter
youtube-footer
linkedin-footer
Blog --------

RACCOON Tool : The Reconnaissance Tool

Share
racoon tool logo

SECURE YOUR BUSINESS WITH EXPERT VAPT STRATEGIES

How Secure Is Your Infrastructure? Book a Free Consultation with Wattlecorp’s Experts to identify vulnerabilities, develop a robust VAPT strategy, and safeguard your business with tailored protection solutions.

data privacy company

 Several ways are used for collecting information like DNS, TLS, web applications, etc.. Raccoon is a tool that brings out these data from different sources.

What is Raccoon tool?

Raccoon is an open-source information gathering and observation tool. It collects information like WHOIS record, Port Scanning, DNS details, DNS mapping, Web Application Firewall (WAF) information and sub-domains enumeration, etc.. The tool has the ability to gather details from websites, such as information about the web server, information on the Control Management Systems, HTML forms, email addresses, etc.. It also gives details about any kind of vulnerability chances.

One of the important steps of reconnaissance is Port scanning and enumeration. The raccoon tool uses the well-known nmap tool to find open ports and makes use of some other nmap scripts and features. It must be installed on OS before running Raccoon on the target host. OpenSSL is used for TLS/SSL scans and should be installed as well.

Features of Raccoon tool:

Raccoon tool collects details like

Ø Domain Name System

Ø DNS visual mapping

Ø WHOIS information

Ø TLS Data

Ø Services and scripts scan

Ø Subdomain enumeration

Ø Web application data retrieval

Ø Detects known WAFs

Ø Supports anonymous routing

Ø Uses asyncio for improved performance

Ø Saves output to files

Installation of Raccoon

Raccoon is a Python developed tool. To run this tool Python 3.5+ is needed. There are two methods to install Raccoon scanner in Linux. The first method is by cloning the Github repository of Racoon using the following commands.

1. Run, “git clone https://github.com/evyatarmeged/Raccoon.git” to clone the repository.

2. Then go into the directory by “cd Raccoon”.

3. Then run python raccoon_src/main.py to install the tool.

 Another way for installation is,

 1. Run “pip3 install raccoon-scanner” if pip3 is not present in the system run,

2. Sudo apt-get install python3-pip

After proper installation of the Raccoon tool, you can use the following syntax to use the tool.

 racoon

 There are several options available to gather valuable information about the target. All the accessible options can be explored by executing the “raccoon –help” command.

 For a usage example, we can execute the “-t” parameter. the –t (or –target) option to scan the target host to gather a handful of information

 So the full command would be raccoon -t

The Raccoon tool first detects the protocol of the application. Whether it is HTTP or HTTPS. Then it collects the Domain Name System, Transport Layer Security, and Web Application Firewall information about the target.

Raccoon is considered as an information-gathering tool. In a way, it helps to decode data. But attack may raise as it gives out information about the user.

Join 15,000+ Cybersecurity Innovators

Protect. Comply. Lead.

Secure your stack, stay compliant, and outpace threats with concise, field‑tested guidance on VAPT, cloud security, and regional privacy laws delivered by Wattlecorp’s
trusted advisors across the globe.

Leave a Comment

Your email address will not be published. Required fields are marked *

mobile application penetration testing qatar Mobile Application Penetration Testing for Qatar Government Digital Services: NCSA- Aligned Security Assurance 

Key Takeaways: Mobile Application Penetration Testing Qatar must cover the app, device storage, APIs, authentication and third-party components. Qatar’s NCSA assurance environment combines the National Information Assurance (NIA) Standard, the National Information Security Compliance Framework (NISCF) and accredited security assessment services. OWASP MASVS defines mobile security controls, while MASTG supplies practical test methods for Android […]

Read more >>
qatar data protection law Qatar Data Protection Law: Implementing PDPPL Data Subject Rights Processes for Businesses 

Key Takeaways: The Qatar Data Protection Law (Law No. 13 of 2016) for Personal Data Privacy Protection, grants individuals specific rights such as right to access, correct, erase, object, withdraw consent, and right to be notified of processing or inaccurate disclosure. Beyond having a privacy policy, businesses or controllers, under Article 11 of Personal Data […]

Read more >>
AI governance india AI Governance for Indian Enterprises: Building Internal Controls Before Key DPDP Obligations Take Effect 

Key Takeaways: The DPDP Act does not contain AI-specific provisions. Its requirements, however, apply in situations when an AI system processes digital personal data within its territorial and material scope. India is working on building a broader governance framework around safety, accountability, transparency and trust via programs like the IndiaAI Mission. Indian organizations should inventory […]

Read more >>
cloud security audit uae Cloud Security Audit for UAE Government Cloud Migration: NCAP and Security Requirements

Key Takeaways: A cloud security audit UAE helps government entities identify security, governance, configuration, access, data-protection and resilience gaps, before and after shifting critical workloads to the cloud. UAE National Cloud Security Policy has defined cloud governance, data security, data sovereignty, IAM, incident management, resilience, portability and cloud operations requirements. The National Cyber Accreditation Program […]

Read more >>
Data Privacy Consulting UAE – Building a PDPL-Compliant Data Governance Program

Key Takeaways: PDPL compliance requires ongoing operational governance that goes beyond policies to demonstrate how personal data is collected, used, protected, transferred, retained, and deleted. Data mapping helps businesses move from reactive compliance to proactive risk management by establishing a comprehensive inventory of the data ecosystem, helping build a mature data privacy and governance program. […]

Read more >>
critical systems cybersecurity controls Saudi Arabia’s Critical Systems Controls: What CSP-Linked Enterprises Must Comply With in 2026

Key Takeaways: The Critical Systems Cybersecurity Controls (CSCC) are more applicable to critical systems than to all IT assets owned or operated by an organization. To be in full compliance or to remain in full compliance with CSCC, organizations must maintain continuous adherence to NCA ECC. CSCC has 32 core controls and 73 sub-controls across […]

Read more >>