reconnaissance-knowledge

Plan and document network reconnaissance with phase-based workflows and JSON-ready outputs.

Updated Nov 22, 2025
One-click install
npx skills add https://github.com/CharlesKozel/vulhub_automated_pentester --skill reconnaissance-knowledge
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: reconnaissance-knowledge
Source: https://github.com/CharlesKozel/vulhub_automated_pentester/tree/main/agents/claude/skills/recon
Command: npx skills add https://github.com/CharlesKozel/vulhub_automated_pentester --skill reconnaissance-knowledge

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill consolidates proven network reconnaissance methodologies and templates to systematically gather target information without exploitation, enabling efficient planning and risk-free assessment.

Core Features & Use Cases

  • Layered Reconnaissance Framework: Structure scans with quick, deep, and alternative approaches for ports, services, and web enumeration.
  • Phase-Oriented Guidance: Step-by-step workflows for Port Discovery, Service Detection, Web Enumeration, and Specific Service Enumeration.
  • Use Case: Security teams performing blue-team validation or pentest recon in lab environments can quickly assemble a complete reconnaissance plan and produce structured outputs.

Quick Start

Load the reconnaissance knowledge base and perform a basic planning exercise: identify a target, plan a quick port discovery, and outline the JSON-ready report.

Frequently Asked Questions about reconnaissance-knowledge

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan network reconnaissance phases without performing exploitation?

Structure network reconnaissance using phase-oriented workflows for port discovery, service detection, and web enumeration. This methodology enables security teams to document target information systematically without exploitation, ensuring repeatable lab assessments and structured JSON-ready outputs.

What is the best way to document port scanning and service fingerprinting for assessments?

Document port scanning and service fingerprinting by applying a layered reconnaissance framework with quick, deep, and alternative approaches. This generates JSON-ready outputs and reference guidance, making your network scanning methodology repeatable for assessment reports.

How does web enumeration fit into a phase-based network scanning workflow?

Web enumeration fits into network scanning workflows as a dedicated phase following port discovery and service detection. It structures the identification of web technologies and vulnerabilities, ensuring enumeration remains documented, repeatable, and separated from exploitation.

Can I use this methodology for blue-team validation in lab environments?

Yes, you can use this methodology for blue-team validation in lab environments. It consolidates proven network reconnaissance techniques to systematically gather target information, allowing security teams to assemble complete reconnaissance plans and produce structured outputs without active exploitation.

Do I need specific tools to follow a layered reconnaissance framework?

The framework provides reference guidance for recommended tools like nmap and whatweb to execute scans. It structures the workflow into quick, deep, and alternative approaches for ports, services, and web enumeration, ensuring your scanning layers are properly documented.