recon-and-methodology

Create structured reconnaissance plans for authorized security testing and bug bounty engagements.

96|1|Updated Jun 4, 2026
One-click install
npx skills add https://github.com/langbyyi/CyberStrikeAI-SRC --skill recon-and-methodology-langbyyi
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-and-methodology
Source: https://github.com/langbyyi/CyberStrikeAI-SRC/tree/main/skills/recon-and-methodology
Command: npx skills add https://github.com/langbyyi/CyberStrikeAI-SRC --skill recon-and-methodology-langbyyi

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill eliminates the risk of incomplete, ad-hoc reconnaissance that leads to missed high-severity vulnerabilities and inefficient bug bounty or penetration testing workflows.

Core Features & Use Cases

  • Systematic Recon Hierarchy: Follow a structured, step-by-step workflow from target scope definition through endpoint discovery to vulnerability testing, ensuring full attack surface coverage.
  • Proven Bug Bounty Methodology: Leverage tested frameworks from top bug hunters including Zseano's testing sequence and high-value target triage guidance to find bugs that others miss.
  • Use Case: A bug bounty hunter or authorized security tester can use this Skill to map all subdomains, discover hidden endpoints, fingerprint underlying technology, and prioritize testing on high-probability vulnerability areas for a new target program.

Quick Start

Use the recon-and-methodology skill to build a complete reconnaissance plan and attack surface map for the target domain example.com, following the provided bug bounty best practices.

Frequently Asked Questions about recon-and-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure reconnaissance for bug bounty hunting on a new target domain?

Bug bounty reconnaissance should follow a systematic hierarchy from target scope definition through subdomain mapping to endpoint discovery. This structured workflow ensures full attack surface coverage and prevents missing high-severity vulnerabilities during security testing.

What is the best way to map an attack surface for authorized penetration testing?

The best way to map an attack surface is through systematic asset enumeration, endpoint discovery, and technology fingerprinting. This approach identifies hidden endpoints and prioritizes testing on high-probability vulnerability areas for new target environments.

Can I use a structured methodology to find high-severity bugs that others miss?

Yes, applying proven bug bounty methodologies like Zseano's testing sequence helps triage high-value targets and identify vulnerabilities that ad-hoc testing misses. Structured vulnerability testing workflows prioritize high-probability areas for better bug discovery results.

Does technology fingerprinting help with endpoint discovery in security testing?

Technology fingerprinting identifies underlying target infrastructure during endpoint discovery, enabling testers to map subdomains and prioritize high-probability vulnerability areas. This systematic approach ensures full attack surface coverage across new target environments.

Why does ad-hoc reconnaissance lead to missed vulnerabilities in bug bounty programs?

Ad-hoc reconnaissance lacks systematic attack surface enumeration and structured vulnerability testing workflows, causing inefficient testing and missed high-severity bugs. Following a proven bug bounty methodology ensures complete asset mapping and endpoint discovery coverage.

What is systematic vulnerability mapping in penetration testing workflows?

Systematic vulnerability mapping is a structured process for identifying high-severity bugs through asset mapping, endpoint discovery, and technology fingerprinting. It adheres to industry-standard bug bounty testing methodologies for authorized security testing engagements.