recon-full

Enumerate subdomains, scan ports, fingerprint assets, and validate POCs.

1.6k|234|Updated Dec 7, 2019
One-click install
npx skills add https://github.com/wgpsec/AboutSecurity --skill recon-full
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-full
Source: https://github.com/wgpsec/AboutSecurity/tree/main/skills/recon/recon-full
Command: npx skills add https://github.com/wgpsec/AboutSecurity --skill recon-full

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

主动式全流程资产侦察。当需要对目标进行从零到漏洞发现的完整侦察、渗透测试的第一阶段、或需要全面了解目标攻击面时使用。覆盖子域名枚举→端口扫描→存活检测→指纹识别→POC 扫描的完整链条

Core Features & Use Cases

  • 覆盖从子域名枚举到 POC 扫描的完整侦察链路,帮助安全团队快速映射攻击面。
  • 提供阶段性输出与优先级排序,便于后续利用与漏洞验证。
  • Use Case: 当需要对目标域名进行全面资产发现和风险评估时,执行本技能以形成完整资产地图和潜在漏洞线索。

Quick Start

Provide a target domain to begin full reconnaissance and receive an end-to-end asset map from subdomains to POC results.

Frequently Asked Questions about recon-full

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is end-to-end asset reconnaissance and when do I need it?

End-to-end asset reconnaissance maps a target's full attack surface from zero to vulnerability discovery. You need it for penetration testing or when requiring comprehensive subdomain enumeration, port scanning, liveliness checks, fingerprinting, and POC validation to identify exposures.

How do I perform full surface discovery from subdomain enumeration to POC scanning?

To perform full surface discovery, execute a structured workflow covering subdomain enumeration, port scanning, liveliness checks, fingerprinting, and POC-based validation. Provide a target domain to generate a complete asset map and potential vulnerability leads.

Can I use a single workflow for target fingerprinting and vulnerability probing?

Yes, you can use a single proactive reconnaissance workflow for target fingerprinting and vulnerability probing. It covers the complete scanning chain, applying fingerprinting and POC scanning to identify exposures and validate vulnerabilities across discovered assets.

Does the asset discovery workflow provide prioritized output for vulnerability validation?

Yes, the asset discovery workflow provides staged output and priority sorting for vulnerability validation. This structured output helps security teams quickly map the attack surface and prioritize subsequent exploitation and POC-based vulnerability verification.

What are the limitations of using a full reconnaissance chain for asset mapping?

The full reconnaissance chain is limited to proactive asset discovery and vulnerability probing. It focuses on mapping exposures from subdomains to POC scanning, serving as the initial penetration testing phase rather than providing deep exploitation or remediation capabilities.