What problem does it solve?
This skill eliminates the guesswork and inefficiency of unstructured reconnaissance during external attack surface management engagements, which often leads to missed assets, wasted scanning resources, and incomplete coverage of the target's infrastructure.
Core Features & Use Cases
- Phased Reconnaissance Framework: Provides a low-to-high noise, step-by-step workflow starting with passive subdomain enumeration, moving to active service detection, then targeted deep scanning, and finally synthesis of findings.
- Context-Aware Decision Tree: Helps users select the right scan strategy based on their existing target data, whether they are starting a new engagement, have partial enumeration results, or are expanding coverage after initial scans.
- Scale-Appropriate Guidance: Includes tailored recommendations for targets of all sizes, from single domains to large organizations with 500+ subdomains, to avoid data overload and ensure efficient resource use.
- Use Case: For example, a security tester beginning an engagement against a corporate target can use this skill to first run passive OSINT-based subdomain enumeration to map the attack surface without generating detectable traffic, then only run active vulnerability scans on high-value assets identified in earlier phases.
Quick Start
Use the reconnaissance-planning skill to develop a tailored, phased reconnaissance strategy for your external attack surface management engagement against your specified target.