recon-deep

Automate comprehensive reconnaissance to map a target's attack surface.

7|Updated Feb 11, 2026
One-click install
npx skills add https://github.com/valITino/blhackbox --skill recon-deep
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-deep
Source: https://github.com/valITino/blhackbox/tree/main/.claude/skills/recon-deep
Command: npx skills add https://github.com/valITino/blhackbox --skill recon-deep

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Comprehensive reconnaissance and attack surface mapping against a target to identify exposure without exploitation.

Core Features & Use Cases

  • Domain intelligence, DNS reconnaissance, and OSINT collection to build an attack surface model.
  • Subdomain enumeration, network mapping, and technology fingerprinting to guide subsequent testing.
  • Use Case: When the user needs an in-depth recon plan for a new target before any exploitation.

Quick Start

Initiate a comprehensive reconnaissance pass against the target using passive and active techniques, then compile the Reconnaissance Report.

Frequently Asked Questions about recon-deep

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map a target's complete attack surface before penetration testing?

Attack surface mapping requires comprehensive reconnaissance across domains, subdomains, and networks. This Skill automates passive and active collection to identify exposure and technology fingerprints, compiling the results into a detailed Reconnaissance Report without exploitation.

What is deep reconnaissance and when do I need it for security assessments?

Deep reconnaissance is the end-to-end discovery of a target's external exposure. You need it before any exploitation phase to gather domain intelligence, perform subdomain enumeration, and map networks so subsequent testing targets valid assets.

Can I use domain intelligence and OSINT collection to identify exposed subdomains?

Yes, domain intelligence and OSINT collection are core features used for subdomain enumeration. This Skill aggregates DNS data and open-source intelligence to build a complete attack surface model of the target environment.

Does this reconnaissance process include active network mapping and technology fingerprinting?

Yes, the reconnaissance process includes both active network mapping and technology fingerprinting. It applies passive and active techniques to identify live hosts, map network infrastructure, and detect technologies guiding subsequent testing steps.

What is the best way to automate subdomain enumeration and DNS reconnaissance?

Automating subdomain enumeration and DNS reconnaissance is best handled through a structured workflow. This Skill applies required steps to aggregate data, map networks, and fingerprint technologies, outputting a comprehensive Reconnaissance Report.