bbot-module-reference

Select BBOT modules, presets, and flags for reconnaissance scans.

11|1|Updated May 4, 2026
One-click install
npx skills add https://github.com/dreadnode/capabilities --skill bbot-module-reference
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bbot-module-reference
Source: https://github.com/dreadnode/capabilities/tree/main/capabilities/attack-surface-management/skills/bbot-module-reference
Command: npx skills add https://github.com/dreadnode/capabilities --skill bbot-module-reference

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Users conducting reconnaissance scans with BBOT waste time trial-and-erroring module, preset, and flag combinations or miss optimal configurations for their specific use case, leading to incomplete or inefficient scans.

Core Features & Use Cases

  • Comprehensive Preset Reference: Curated lists of BBOT presets organized by use case (discovery, web scanning, vulnerability scanning, fuzzing, specialized) with clear purpose and key module breakdowns for quick selection.
  • Flag & Module Documentation: Full reference for BBOT flags to filter modules by risk level (passive, safe, active, aggressive) and detailed explanations of key modules across subdomain discovery, web analysis, cloud resources, and security testing.
  • Common Scan Recipes: Pre-built example scan configurations for frequent use cases including passive subdomain enumeration, targeted nuclei scans, cloud resource hunting, and full kitchen-sink scans for small targets.

Quick Start

Use the bbot-module-reference skill to look up the correct preset and flags for a passive subdomain discovery scan of target.com.

Frequently Asked Questions about bbot-module-reference

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find the right BBOT preset for subdomain enumeration?

BBOT presets for subdomain enumeration can be selected from curated lists organized by use case, such as discovery or web scanning, to ensure optimal module configurations without manual lookup.

What BBOT flags should I use to filter modules by risk level?

BBOT flags allow you to filter modules by risk level including passive, safe, active, and aggressive, ensuring your reconnaissance scans match the required operational security posture.

Can I use BBOT for cloud resource discovery and vulnerability scanning?

Yes, BBOT supports cloud resource discovery and vulnerability scanning through specialized presets and dedicated modules designed for security testing and attack surface mapping.

What is the best way to configure a passive subdomain discovery scan in BBOT?

Pre-built scan recipes provide exact configurations for passive subdomain discovery, allowing you to execute targeted reconnaissance scans without trial-and-error module combinations.

Does BBOT include pre-built scan recipes for targeted nuclei scans?

Yes, BBOT offers common scan recipes including targeted nuclei scans, cloud resource hunting, and full kitchen-sink scans for small targets to eliminate configuration guesswork.

Why does my BBOT web scanning configuration miss key modules?

Missing modules during web scanning often results from incorrect preset selection or failing to apply the right flags to filter for active or aggressive risk levels.