initial-access-recon

Map external attack surfaces with OSINT and subdomain enumeration.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/0X6C7879/aegissec --skill initial-access-recon
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: initial-access-recon
Source: https://github.com/0X6C7879/aegissec/tree/main/skills/initial-access-recon
Command: npx skills add https://github.com/0X6C7879/aegissec --skill initial-access-recon

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Performs comprehensive OSINT reconnaissance to map an external attack surface for initial access.

Core Features & Use Cases

  • OSINT gathering and passive reconnaissance for target mapping
  • Subdomain enumeration and external exposure discovery
  • Port and service discovery for exposed assets
  • Web application reconnaissance and cloud asset discovery

Quick Start

Provide a target domain and I will perform OSINT and reconnaissance to map the attack surface and identify initial access opportunities.

Frequently Asked Questions about initial-access-recon

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map an external attack surface for initial access?

Cloud asset discovery identifies exposed cloud assets and external exposures by performing OSINT reconnaissance. It maps cloud infrastructure to pinpoint potential entry points and exposed services within the target's cloud environment.

Can I use OSINT reconnaissance for subdomain enumeration and cloud discovery?

Web application reconnaissance identifies exposed web assets and potential entry points by performing OSINT and service fingerprinting. It maps the external attack surface to reveal vulnerabilities and initial access opportunities.

What is the best way to perform passive reconnaissance and email harvesting?

Service fingerprinting identifies exposed assets and potential entry points by analyzing responses from discovered ports. It maps the external attack surface to reveal specific service versions and vulnerability screening results.

Does this attack surface mapping workflow support port scanning and service fingerprinting?

To map an external attack surface for initial access, you perform comprehensive OSINT gathering, subdomain enumeration, and port scanning to identify exposed assets and potential entry points. This reveals external exposures and service fingerprints.

How does cloud asset discovery work during external reconnaissance?

OSINT reconnaissance supports subdomain enumeration and cloud discovery by passively mapping target domains. It identifies external assets, exposed services, and cloud infrastructure to reveal potential initial access opportunities.

What does web application reconnaissance reveal about potential entry points?

The best way to perform passive reconnaissance and email harvesting is through a modular OSINT workflow. This approach maps the attack surface and identifies exposure without directly interacting with the target's internal systems.