reconnaissance-planning

Plan phased low-to-high noise reconnaissance workflows for external attack surface management.

11|1|Updated May 4, 2026
One-click install
npx skills add https://github.com/dreadnode/capabilities --skill reconnaissance-planning
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: reconnaissance-planning
Source: https://github.com/dreadnode/capabilities/tree/main/capabilities/attack-surface-management/skills/reconnaissance-planning
Command: npx skills add https://github.com/dreadnode/capabilities --skill reconnaissance-planning

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill eliminates the guesswork and inefficiency of unstructured reconnaissance during external attack surface management engagements, which often leads to missed assets, wasted scanning resources, and incomplete coverage of the target's infrastructure.

Core Features & Use Cases

  • Phased Reconnaissance Framework: Provides a low-to-high noise, step-by-step workflow starting with passive subdomain enumeration, moving to active service detection, then targeted deep scanning, and finally synthesis of findings.
  • Context-Aware Decision Tree: Helps users select the right scan strategy based on their existing target data, whether they are starting a new engagement, have partial enumeration results, or are expanding coverage after initial scans.
  • Scale-Appropriate Guidance: Includes tailored recommendations for targets of all sizes, from single domains to large organizations with 500+ subdomains, to avoid data overload and ensure efficient resource use.
  • Use Case: For example, a security tester beginning an engagement against a corporate target can use this skill to first run passive OSINT-based subdomain enumeration to map the attack surface without generating detectable traffic, then only run active vulnerability scans on high-value assets identified in earlier phases.

Quick Start

Use the reconnaissance-planning skill to develop a tailored, phased reconnaissance strategy for your external attack surface management engagement against your specified target.

Frequently Asked Questions about reconnaissance-planning

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is the best way to structure external attack surface reconnaissance?

Structuring external attack surface reconnaissance requires a phased, low-to-high noise workflow that begins with passive subdomain enumeration, moves to active service detection, and concludes with targeted deep scanning to avoid data overload.

How do I plan a subdomain enumeration strategy for new target onboarding?

Plan your subdomain enumeration strategy by selecting context-aware scan phases based on existing target data, starting with passive OSINT-based asset discovery to map the attack surface without generating detectable traffic.

How do I avoid data overload when scanning large targets with 500+ subdomains?

Avoid data overload on large targets by applying scale-appropriate planning guidance that restricts active vulnerability scans to high-value assets identified during earlier passive enumeration phases.

When should I adjust my scan strategy after getting sparse initial enumeration results?

Adjust your scan strategy after sparse initial results by expanding attack surface coverage using context-aware decision trees that identify the next appropriate active scanning phase.

Does reconnaissance planning work for adjusting scope compliance during security testing?

Reconnaissance planning supports scope compliance during security testing by enforcing structured workflows that manage scan noise and resource use across target infrastructure expansion scenarios.