What problem does it solve?
Standard HTTP-based web reconnaissance often misses exposed backend infrastructure services like unauthenticated databases, internal APIs, and admin ports that represent critical, high-severity vulnerabilities for target systems.
Core Features & Use Cases
- Tiered Port Scanning: Runs fast top-100, top-1000, and fragmented SYN scans to map exposed ports while bypassing basic firewall rules.
- Critical Service Validation: Automatically checks for high-risk exposures including unauthenticated Redis, anonymous FTP login, and open MySQL/MongoDB instances with basic banner and access testing.
- Use Case: Use this skill during a deep invade phase on a WordPress target or after discovering a staging subdomain to quickly identify exposed database or backend API ports that could enable full system compromise.
Quick Start
Use the port-service-discovery skill to run a fast top-100 port scan on the target domain example.com and identify any exposed critical services like MySQL or Redis.