DEV Community

Dendi Prayogo Hidayat
Dendi Prayogo Hidayat

Posted on

Building SecOps Recon Bot: Enterprise-Grade Web Auditing via Telegram

This is a submission for the MLH x DEV Writing Challenge

What I Built

I built SecOps Recon Bot, an automated, asynchronous Telegram bot designed for enterprise-grade web reconnaissance and objective security auditing.

What it does

It allows security analysts, pentesters, and CTF players to perform rapid reconnaissance directly from their phones via Telegram. The bot features three main modules:

HTTP Security Headers Audit: Analyzes critical headers (HSTS, CSP, etc.) with automatic protocol fallback and final URL resolution.

Cookie Security Inspector: Audits session cookies for missing Secure and HttpOnly flags.

Sensitive Path Scanner (Dir-Buster Lite): Concurrently brute-forces exposed administrative endpoints (e.g., .env, .git/HEAD) while smartly filtering out generic 301/302 catch-all redirects to prevent false positives.
Finally, it uses Zero Disk I/O to generate a beautifully formatted Markdown report directly in memory and sends it as a downloadable file.
Enter fullscreen mode Exit fullscreen mode

What inspired it

During CTFs and bug bounty hunting, I realized that firing up heavy desktop tools (like Burp Suite or dedicated terminal scanners) just to do a quick initial recon on a target is highly inefficient. I wanted a tool that lives in my pocket, works instantly, and delivers professional, objective data without the noise of false positives.

What I learned

I leveled up my Python architecture skills significantly. I learned how to seamlessly blend synchronous I/O operations (like the requests library) with asynchronous non-blocking frameworks (aiogram) using ThreadPoolExecutor. I also learned how to enforce strict type-guarding with Pylance and how to properly handle HTTP redirect blind spots to ensure the bot always reports the final resolved URL.

Demo

Here is a look at the bot's interface and the Enterprise Markdown Report it generates:

Check out the source code on GitHub:

SecOps Recon Bot

An automated, asynchronous Telegram bot designed for enterprise-grade web reconnaissance and objective security auditing. Built as a submission for the MLH Community Event.

Overview

SecOps Recon Bot is a Red Teaming and Web Security utility that allows security analysts to perform rapid, concurrent reconnaissance directly from Telegram. It is engineered with strict type checking, robust error handling, and Application Performance Monitoring (APM) to ensure production-level stability.

Core Capabilities

  • HTTP Security Headers Audit: Objectively analyzes critical security headers (e.g., HSTS, CSP, X-Frame-Options) with automatic protocol fallback (HTTPS to HTTP) and final URL resolution.
  • Cookie Security Flag Inspector: Scans target responses for missing Secure and HttpOnly flags on session cookies.
  • Sensitive Path Scanner (Dir-Buster Lite): Utilizes thread-pooling to concurrently brute-force common administrative endpoints and sensitive files (e.g., .env, robots.txt, .git/HEAD) while intentionally filtering out generic 301/302 catch-all redirects to eliminate false positives.
  • In-Memory Report Generation: Concurrently…




Partner Technologies

Sentry (Application Performance Monitoring & Error Tracking)
To ensure this tool meets enterprise standards, I integrated the Sentry SDK deep into the application's core. Rather than just wrapping the bot in a generic try-catch block, I utilized Sentry's start_transaction and start_span features to monitor specific reconnaissance operations.

For example, during the concurrent Sensitive Path scanning, Sentry tracks the performance of the thread pool and monitors HTTP client spans. If a target server drops the connection or times out, Sentry instantly logs the deadline exceedance or internal errors without crashing the bot's main polling loop. This gave me incredible visibility into how the bot performs under the hood when scanning slow or heavily protected targets.

Sentry

Hackathon Experience

I built this for the MLH Community Event (CEV). The atmosphere was incredibly inspiring—seeing hackers from all over the world turning ideas into reality pushed me to not just "make a bot that works", but to engineer a production-ready application.

My biggest takeaway from this event is the shift in my development mindset. Instead of rushing to build features, I focused on clean code, strict type-checking, handling edge cases (like URL redirects), and writing professional documentation. The sense of community and the drive to build something genuinely useful for the cybersecurity space is what I will remember most about this MLH event!

Top comments (0)