What problem does it solve?
This Skill reduces the uncertainty and manual effort involved in mapping an organization's authorized external attack surface by consolidating passive discovery, DNS intelligence, and domain registration data.
Core Features & Use Cases
- Passive Asset Discovery: Enumerate subdomains through certificate transparency, passive DNS, threat intelligence, and reconnaissance sources.
- Domain and DNS Intelligence: Perform WHOIS/RDAP lookups, catalog DNS records, identify SaaS tenancy signals, and confirm Microsoft 365 infrastructure.
- Evidence-Based Recon Handoffs: Deduplicate typed assets, assign confidence, preserve scope boundaries, and route domains, emails, and IPs to downstream analysis workflows.
- Use Case: For an authorized engagement, discover related subdomains, identify exposed services and SaaS providers from DNS records, and produce a prioritized asset inventory for web and infrastructure review.
Quick Start
Ask the recon asset discovery skill to passively enumerate the authorized root domain, perform WHOIS/RDAP and DNS cataloging, and return a deduplicated asset list with confidence labels.