recon-methodology

Enumerate attack surfaces and fingerprint technologies for penetration testing.

83|8|Updated May 6, 2026
One-click install
npx skills add https://github.com/Q16G/aster --skill recon-methodology
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-methodology
Source: https://github.com/Q16G/aster/tree/main/skills/pentest/recon-methodology
Command: npx skills add https://github.com/Q16G/aster --skill recon-methodology

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Systematic reconnaissance guides teams to enumerate a target's attack surfaces, fingerprint technologies, and collect signals that determine the relevance of subsequent tasks in a pentest workflow.

Core Features & Use Cases

  • Structured reconnaissance: Provides a checklist to map site structure, tech stack, input points, and authentication patterns for actionable planning.
  • Signal output: Outputs a structured signal list that informs task selection and prioritization during engagement.
  • Collaboration: Integrates with agent-browser to perform automated exploration with safety constraints.

Quick Start

Invoke recon-methodology to generate a structured reconnaissance signal list for the target site and outline follow-up tasks.

Frequently Asked Questions about recon-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I systematically enumerate an attack surface before a penetration test?

To systematically enumerate an attack surface, you map site structure, fingerprint technology stacks, identify input points, and collect signals to inform subsequent pentest tasks. This structured reconnaissance provides a checklist covering web apps, APIs, and infrastructure for actionable planning.

What signals should I collect during web application reconnaissance?

During web application reconnaissance, collect signals detailing site structure, technology stacks, input points, authentication patterns, and business workflows. Outputting a structured signal list informs task selection and prioritization during the full-scope penetration testing engagement.

Can I automate attack surface mapping with agent-browser integration?

You can automate attack surface mapping by integrating with agent-browser to perform automated exploration. This collaboration operates within safety constraints while fingerprinting technologies and collecting reconnaissance signals across the target's web apps and infrastructure.

Does this reconnaissance methodology work for both APIs and infrastructure targets?

This reconnaissance methodology works for APIs, infrastructure, and web apps across full-scope pentest engagements. It systematically enumerates target attack surfaces by detailing structure, technology stacks, input points, auth patterns, and business workflows for each environment.

How do I prioritize penetration testing tasks after mapping the attack surface?

Prioritize penetration testing tasks by using the structured signal list generated from mapping the attack surface. These collected signals determine the relevance of subsequent tasks, guiding actionable planning and task selection during the engagement.

What is the best way to fingerprint technology stacks during a pentest reconnaissance phase?

The best way to fingerprint technology stacks during pentest reconnaissance is to apply a systematic methodology that maps site structure and input points. This process collects actionable signals detailing the technology stack and authentication patterns for follow-up tasks.