What problem does it solve? Raw port scans and banner grabs produce lists of open services but no insight into what those services mean for an attack surface. This Skill turns discovered ports, banners, certificates, and reverse DNS into an infrastructure role map, weak-boundary hypotheses, and a concrete follow-up validation plan. ## Core Features & Use Cases - Role-Based Clustering: Groups services into identity/directory, remote administration, file/data movement, data stores, and web/app management categories. - Correlation Analysis: Cross-references TLS certificate names, reverse DNS, host naming conventions, and adjacent web interfaces to reveal internal naming and environment drift (dev, test, backup, migration). - Weak-Boundary Hypotheses: Prioritizes exposed management planes, duplicated trust planes on one host, legacy nodes, and data services lacking segmentation. - Use Case: During an external assessment, a scan reveals LDAP, RDP, an SMB share, and an admin portal across several hosts. Use this Skill to map each service to its operating role, flag a backup server with looser controls, and produce a shortlist of management planes for manual review. ## Quick Start Triage these discovered services and banners into infrastructure roles and weak-boundary hypotheses with a follow-up validation plan.