What problem does it solve?
Generic recon workflows miss sector-specific attack surfaces unique to property management, apartment rental, and real estate management company websites, which often store highly sensitive tenant PII (SSNs, bank account details, lease agreements) and run niche platforms and plugins that require targeted discovery techniques.
Core Features & Use Cases
- Sector-specific endpoint discovery: Automatically identifies tenant portals, property listing APIs, maintenance request systems, and common property management software (AppFolio, Buildium, Yardi) fingerprints.
- WordPress and SaaS stack recon: Includes checks for CORS credential reflection, unauthenticated REST API endpoints, exposed debug logs, and vulnerable plugins common to property management sites.
- Field-validated workflows: Built from a 20-target batch recon across US property management companies, with real-world examples of common findings like exposed lease PDFs with tenant SSNs and unauthenticated property data APIs.
Use case: A pentester scoping a property management firm can use this skill to quickly locate exposed tenant portals and debug logs containing sensitive financial data without manual trial-and-error of generic recon tools.
Quick Start
Use the recon-property-management skill to conduct a complete sector-specific recon against a target property management company domain, including tenant portal discovery, WordPress vulnerability checks, and maintenance request endpoint enumeration.