What problem does it solve?
Reconnaissance and enumeration are foundational to security engagements. This Skill provides a structured, repeatable workflow to map an organization's attack surface, inventory endpoints, technologies, and potential entry points from passive OSINT through active scanning.
Core Features & Use Cases
- Passive OSINT collection and DNS/subdomain enumeration to identify target surface.
- Active port discovery and service fingerprinting using rustscan and nmap workflows.
- Web enumeration and technology stack detection to map web assets and tech.
- Network service enumeration (SMB, SNMP, LDAP, etc.) to reveal exposed services.
- SPA discovery and client-side routing analysis for modern apps.
- Phase-driven workflow with clear validation and fallback protocols to ensure robust recon data.
Quick Start
Provide a target and scope, then run recon-and-enumeration to generate a complete inventory of endpoints, technologies, and entry points for your security engagement.