What problem does it solve?
This Skill automates the complex and time-consuming process of gathering intelligence on targets, identifying their digital presence, and mapping their attack surface.
Core Features & Use Cases
- Passive Reconnaissance: Gathers information from public sources like Certificate Transparency logs, WHOIS records, and Shodan without directly interacting with the target.
- Active Enumeration: Discovers subdomains, open ports, and live web services through DNS queries, port scanning, and web probing.
- Cloud Asset Discovery: Identifies cloud storage buckets and other cloud-specific assets.
- Username & Social OSINT: Maps user identities across various platforms.
- Use Case: An organization needs to understand its external attack surface. This Skill can be used to discover all publicly accessible subdomains, identify running services on those subdomains, and find associated cloud assets, providing a comprehensive view of potential vulnerabilities.
Quick Start
Use the OSINT and Reconnaissance skill to discover all subdomains for the target domain 'example.com'.