RXScan
Fast, bounded reconnaissance in Rust. RXScan combines port discovery, service identification, protocol-aware probing, and evidence-driven follow-up while keeping network activity and resource usage controlled.

RXScan — Raw Excess Scan
RXScan is a native reconnaissance tool written in Rust for structured network and service discovery.
The project focuses on getting more useful information from the evidence already collected rather than generating additional traffic without a reason. Scanning behavior is bounded by explicit scope, speed, depth, and resource controls.
What it does
RXScan brings several reconnaissance stages into one workflow:
- TCP port discovery
- UDP-aware scanning
- Service identification
- HTTP and TLS inspection
- DNS-related evidence
- Protocol-aware probing
- Evidence-driven follow-up tasks
- Structured reporting
Instead of treating every discovered port as a reason to launch every available probe, RXScan uses collected evidence to decide what should happen next.
Design
The core pipeline follows:
Target → Scope → Scan Plan → Scheduler → Modules → Evidence → Decision Engine → Follow-up Tasks → Reporting
The scheduler keeps work bounded while modules produce typed evidence that can be reused by later stages.
Scan level controls how deeply RXScan investigates a target, while speed controls how aggressively scheduled work is performed. These are intentionally separate concepts.
Engineering priorities
RXScan is built around a few constraints:
- Native Rust implementation
- Bounded concurrency and queues
- Controlled memory and network usage
- Lazy initialization where practical
- Deterministic behavior
- Minimal unnecessary dependencies
- No browser runtime, daemon, or heavyweight application layer
New capabilities are expected to justify their cost in CPU, memory, binary size, startup time, disk usage, and network activity.
Status
RXScan is under active development. The architecture, scanning engine, protocol intelligence, evidence model, and reporting capabilities continue to evolve as the project is tested against real reconnaissance workflows.
The goal is not to generate the largest possible amount of traffic. It is to extract useful reconnaissance evidence efficiently and make follow-up work deliberate.
Source
The project is developed openly on GitHub:
github.com/DarkRX1/RXScan