Quick Contact

Talk to our team

Social

fb-footer
instagram-footer
Twiiter
youtube-footer
linkedin-footer
Blog --------

RACCOON Tool : The Reconnaissance Tool

Share
racoon tool logo

SECURE YOUR BUSINESS WITH EXPERT VAPT STRATEGIES

How Secure Is Your Infrastructure? Book a Free Consultation with Wattlecorp’s Experts to identify vulnerabilities, develop a robust VAPT strategy, and safeguard your business with tailored protection solutions.

data privacy company

 Several ways are used for collecting information like DNS, TLS, web applications, etc.. Raccoon is a tool that brings out these data from different sources.

What is Raccoon tool?

Raccoon is an open-source information gathering and observation tool. It collects information like WHOIS record, Port Scanning, DNS details, DNS mapping, Web Application Firewall (WAF) information and sub-domains enumeration, etc.. The tool has the ability to gather details from websites, such as information about the web server, information on the Control Management Systems, HTML forms, email addresses, etc.. It also gives details about any kind of vulnerability chances.

One of the important steps of reconnaissance is Port scanning and enumeration. The raccoon tool uses the well-known nmap tool to find open ports and makes use of some other nmap scripts and features. It must be installed on OS before running Raccoon on the target host. OpenSSL is used for TLS/SSL scans and should be installed as well.

Features of Raccoon tool:

Raccoon tool collects details like

Ø Domain Name System

Ø DNS visual mapping

Ø WHOIS information

Ø TLS Data

Ø Services and scripts scan

Ø Subdomain enumeration

Ø Web application data retrieval

Ø Detects known WAFs

Ø Supports anonymous routing

Ø Uses asyncio for improved performance

Ø Saves output to files

Installation of Raccoon

Raccoon is a Python developed tool. To run this tool Python 3.5+ is needed. There are two methods to install Raccoon scanner in Linux. The first method is by cloning the Github repository of Racoon using the following commands.

1. Run, “git clone https://github.com/evyatarmeged/Raccoon.git” to clone the repository.

2. Then go into the directory by “cd Raccoon”.

3. Then run python raccoon_src/main.py to install the tool.

 Another way for installation is,

 1. Run “pip3 install raccoon-scanner” if pip3 is not present in the system run,

2. Sudo apt-get install python3-pip

After proper installation of the Raccoon tool, you can use the following syntax to use the tool.

 racoon

 There are several options available to gather valuable information about the target. All the accessible options can be explored by executing the “raccoon –help” command.

 For a usage example, we can execute the “-t” parameter. the –t (or –target) option to scan the target host to gather a handful of information

 So the full command would be raccoon -t

The Raccoon tool first detects the protocol of the application. Whether it is HTTP or HTTPS. Then it collects the Domain Name System, Transport Layer Security, and Web Application Firewall information about the target.

Raccoon is considered as an information-gathering tool. In a way, it helps to decode data. But attack may raise as it gives out information about the user.

Join 15,000+ Cybersecurity Innovators

Protect. Comply. Lead.

Secure your stack, stay compliant, and outpace threats with concise, field‑tested guidance on VAPT, cloud security, and regional privacy laws delivered by Wattlecorp’s
trusted advisors across the globe.

Leave a Comment

Your email address will not be published. Required fields are marked *

Qatar cybersecurity framework Qatar Cybersecurity Boardroom Accountability: Why QCB and NCSA Now Expect Executive Ownership  

Key Takeaways: Cybersecurity in Qatar is increasingly becoming an executive governance responsibility, with national cybersecurity initiatives and sector-specific requirements encouraging organizations to establish stronger leadership oversight. QCB and NCSA play important roles in strengthening cybersecurity governance in Qatar, with QCB focusing on financial sector requirements and NCSA supporting national-level cybersecurity coordination and guidance. Executives can’t […]

Read more >>
Saudi data protection law Data Privacy Consulting for Saudi Enterprises: How to Operationalize PDPL Data Subject Rights in 2026

Key Takeaways: The Saudi data protection law may apply to organizations outside the Kingdom when they process personal data related to individuals in Saudi Arabia, meaning geographic location alone does not automatically exclude an organization from PDPL obligations. PDPL data subject rights span access, correction, deletion, and consent withdrawal, and enterprises are on the hook […]

Read more >>
third-party vendor risk assessment DPDP Third-Party Vendor Security Risk Assessment Under DPDP: A Guide for Indian Enterprises

Key Takeaways: Third-party vendor risk assessment with DPDP practices helps Indian enterprises to verify that external partners handle personal data with adequate safeguards. The Digital Personal Data Protection Act holds data fiduciaries accountable for vendor conduct, which makes due diligence a legal and operational necessity. A structured vendor security questionnaire, covering encryption, access control, and […]

Read more >>
virtual CISO UAE Virtual CISO Services for UAE Free Zone Startups: Affordable Security Leadership for Growing Companies

Key Takeaways: Most startups already hold sensitive data such as customer info, source code, financials, long before they feel big enough to take security seriously, and that’s exactly when the risk starts. A virtual CISO gets you someone who’s done this before, setting up strategy and guiding compliance, without the cost of putting a full-time […]

Read more >>
SOC as a service for BFSI and FinTech India SOC as a Service for Indian BFSI and FinTech Companies: 24/7 Monitoring for CERT-In Readiness

Key Takeaways: SOC as a Service for BFSI and FinTech India gives banks, NBFCs, insurers and digital lenders continuous security visibility without the cost and hiring effort of building an in-house operations centre. CERT-In directions require regulated entities to report qualifying cyber incidents within six hours of detection, and implementing SOC for BFSI and FinTech […]

Read more >>
SOC as a service SOC as a Service in India: How It Works, Pricing, and Why Businesses Need It 

Key Takeaways: SOC as a Service helps Indian businesses to get 24×7 security monitoring without huge cost and complexity of building a full in-house security operations center. A managed SOC check and analyse beyond basic log monitoring, which combining SIEM, threat intelligence, analyst-led alert triage, incident escalation, reporting, and security response support. SOC as a […]

Read more >>