What problem does it solve?
Unstructured or incomplete reconnaissance for authorized penetration tests leads to missed attack vectors, wasted effort, and incomplete security assessments. This Skill provides a standardized, PTES-aligned workflow to conduct thorough, scoped information gathering for authorized security testing engagements.
Core Features & Use Cases
- PTES-Aligned Recon Workflow: Covers passive OSINT (DNS, WHOIS, Shodan, GitHub secret scanning) and active enumeration (port scanning, service fingerprinting, SMB/LDAP/SNMP enumeration) in a structured four-phase approach.
- CVE Prioritization & Attack Surface Reporting: Maps discovered services and versions to relevant CVEs, prioritizes findings by exploitability, and generates a standardized attack surface summary template for client reporting.
- Use Case: For an authorized penetration test of example.com, use this Skill to gather all subdomains, identify open ports and running services, find associated high-risk CVEs, and compile a prioritized list of attack paths to guide subsequent testing.
Quick Start
Use the pentest-recon skill to perform full reconnaissance and generate a prioritized attack surface summary for the authorized target example.com.