What problem does it solve? Penetration testers and red teams often miss critical assets because reconnaissance is fragmented across dozens of tools and data sources. This Skill provides a structured, end-to-end methodology for mapping a target's full attack surface—domains, IPs, cloud assets, mobile apps, employees, and leaked credentials—then prioritizing which assets to attack first. ## Core Features & Use Cases - Full-Spectrum Reconnaissance: Covers passive OSINT (WHOIS, ICP filings, certificate transparency, code leaks, breach databases, dark web monitoring) and active techniques (subdomain brute-forcing, port scanning, fingerprinting, directory fuzzing) with stealth guidance on proxy rotation and rate limiting. - Cloud & Mobile Asset Discovery: Detects subdomain takeover candidates, exposed object storage buckets (S3/OSS/COS), serverless endpoints, and extracts API endpoints and hardcoded keys from WeChat mini-programs and Android APKs. - Attack Surface Prioritization: Provides a risk-scoring model and decision methodology to rank assets by reachability, vulnerability, intelligence hits, and business value, plus AI-assisted triage of recon output. - Use Case: During an authorized red team engagement, run passive enumeration (subfinder, crt.sh, FOFA) against a target corporation, validate live hosts with httpx, check dangling CNAMEs for takeover, query breach databases for employee credentials, and produce a ranked target list with three candidate attack paths. ## Quick Start Ask the AI to perform full attack surface reconnaissance on an authorized target domain and produce a prioritized asset list with recommended entry points.