recon-and-methodology

Structure subdomain enumeration, service discovery, and vulnerability testing for bug bounty targets.

Updated Jun 11, 2026
One-click install
npx skills add https://github.com/utsavthakur/agenticskills --skill recon-and-methodology-utsavthakur
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-and-methodology
Source: https://github.com/utsavthakur/agenticskills/tree/main/recon-and-methodology
Command: npx skills add https://github.com/utsavthakur/agenticskills --skill recon-and-methodology-utsavthakur

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a comprehensive recon and methodology playbook for bug bounty hunters, helping them systematically map assets, discover endpoints, fingerprint technology, and build structured testing plans for new targets.

Core Features & Use Cases

  • Systematic Recon: Offers a structured approach to reconnaissance, including subdomain enumeration, endpoint discovery, tech fingerprinting, and vulnerability testing.
  • Methodology: Delivers a methodology for bug bounty hunting, covering key insights and testing sequences.
  • Use Case: Ideal for hunters looking to enhance their recon process and find high-severity bugs through systematic coverage.

Quick Start

Use the recon-and-methodology skill to perform a comprehensive recon on a target domain 'example.com'.

Frequently Asked Questions about recon-and-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a structured bug bounty recon methodology?

A structured bug bounty recon methodology systematically maps target assets through subdomain enumeration, endpoint discovery, and tech fingerprinting before vulnerability testing. This approach ensures comprehensive attack surface coverage to identify high-severity bugs.

How do I perform subdomain enumeration and tech fingerprinting for a new target?

Subdomain enumeration and tech fingerprinting involve mapping target assets and identifying underlying technologies. Using tools like subfinder for subdomain discovery and nmap for service mapping builds a structured testing plan for the target domain.

Do I need specific tools like subfinder and nuclei to use this recon playbook?

Yes, this bug bounty recon playbook requires tools like subfinder, nmap, and nuclei to execute its systematic methodology. These tools handle subdomain enumeration, service discovery, and vulnerability testing across the target domain.

What's the best way to approach vulnerability testing for bug bounty hunting?

The best approach to vulnerability testing for bug bounty hunting is systematic coverage. By performing thorough subdomain enumeration and service discovery first, you build a structured testing plan to find high-severity bugs across the target.

Can I use this reconnaissance methodology for any target domain?

Yes, this reconnaissance methodology applies to any target domain like 'example.com'. It provides a universal testing sequence for bug bounty hunters to map assets, discover endpoints, and fingerprint technology systematically.