recon-sweep

Perform passive and scoped active reconnaissance on network targets and domains.

2|Updated Apr 12, 2026
One-click install
npx skills add https://github.com/protoLabsAI/protoPen --skill recon-sweep
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: recon-sweep
Source: https://github.com/protoLabsAI/protoPen/tree/main/config/skills/recon-sweep
Command: npx skills add https://github.com/protoLabsAI/protoPen --skill recon-sweep

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill solves the challenge of performing thorough reconnaissance on a target without triggering security alerts or violating engagement scope, ensuring a disciplined and methodical approach to information gathering.

Core Features & Use Cases

  • Passive-First Enumeration: Prioritizes zero-touch OSINT and DNS discovery to map attack surfaces without sending packets to the target.
  • Scope-Aware Workflow: Enforces strict adherence to engagement modes, preventing unauthorized active probing.
  • Use Case: When tasked with assessing a new client network, use this Skill to safely identify live hosts, subdomains, and service versions while maintaining strict OPSEC compliance.

Quick Start

Use the recon-sweep skill to perform a passive reconnaissance scan on the target domain example.com within the current engagement scope.

Frequently Asked Questions about recon-sweep

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is passive-first network reconnaissance?

Passive-first network reconnaissance prioritizes zero-touch OSINT and DNS discovery to map attack surfaces without sending packets to the target. It identifies live hosts and service configurations while maintaining strict OPSEC compliance.

How do I perform structured reconnaissance on a domain without triggering alerts?

To perform structured reconnaissance without triggering alerts, use a scope-aware workflow that enforces strict adherence to engagement boundaries. This prevents unauthorized active probing by relying on passive enumeration and scoped active discovery.

Can I use OSINT sources for DNS enumeration during a pentest?

Yes, you can integrate OSINT sources with DNS enumeration tools to synthesize actionable intelligence. This combination maps subdomains and identifies service versions safely within defined engagement boundaries.

What is the best way to identify live hosts while maintaining OPSEC compliance?

The best way to identify live hosts while maintaining OPSEC compliance is to use a scope-aware workflow that enforces strict adherence to engagement modes, preventing unauthorized active probing and ensuring disciplined information gathering.

Does this network reconnaissance approach work within strict engagement boundaries?

Yes, this approach operates within defined engagement boundaries to identify attack surfaces, live hosts, and service configurations. It enforces strict adherence to engagement modes to prevent unauthorized active probing.

Why does passive enumeration prevent unauthorized active probing?

Passive enumeration prevents unauthorized active probing by prioritizing zero-touch OSINT and DNS discovery to map attack surfaces without sending packets to the target. This scope-aware workflow ensures disciplined information gathering.