red-team-recon

Gather open-source intelligence on payment systems using Shodan, Censys, and Amass.

Updated May 8, 2026
One-click install
npx skills add https://github.com/reececoakes99/openclaw-brain-v2 --skill red-team-recon
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-recon
Source: https://github.com/reececoakes99/openclaw-brain-v2/tree/main/skills/red-team-recon
Command: npx skills add https://github.com/reececoakes99/openclaw-brain-v2 --skill red-team-recon

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill streamlines the collection of open-source intelligence to identify payment infrastructure exposure and vulnerabilities.

Core Features & Use Cases

  • Automated Reconnaissance: Performs multi-source intelligence gathering from Shodan, Censys, certificate logs, subdomain enumeration, GitHub code scanning, and dark web monitoring.
  • Target Mapping: Generates structured data files like active_targets.json to assist in initial attack surface mapping.
  • Use Case: Security teams preparing for red-team engagement can quickly assemble comprehensive target profiles of payment systems and related infrastructure.

Quick Start

Initiate reconnaissance on your target domain with simple natural language instructions like "recon on payment-processor.com".

Frequently Asked Questions about red-team-recon

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate OSINT gathering for payment infrastructure mapping?

Automated OSINT gathering for payment infrastructure mapping collects external data from Shodan, Censys, certificate logs, and GitHub to identify security exposure. It streamlines target reconnaissance by generating structured files like active_targets.json for attack surface profiling.

What is multi-source reconnaissance for payment systems security assessments?

Multi-source reconnaissance for payment systems security assessments aggregates exposed infrastructure data across Shodan, Censys, subdomain enumeration, and dark web monitoring. It enables red-team operations to quickly assemble comprehensive target profiles of payment systems.

Do I need Shodan and Censys CLI tools to perform dark web monitoring and subdomain enumeration?

You need tools like Shodan, Censys, amass, and git CLI integrations to reliably collect and process external data sources. These dependencies are required to perform subdomain enumeration, dark web monitoring, and certificate log scanning.

What's the best way to map a target domain's attack surface before a red-team engagement?

The best way to map an attack surface before red-team operations is initiating automated reconnaissance on the target domain using natural language instructions. This generates structured target profiles by scanning GitHub code, certificate logs, and external infrastructure.

How do I scan GitHub code for payment infrastructure exposure and vulnerabilities?

Scanning GitHub code for payment infrastructure exposure uses automated git CLI integrations to process repository data alongside Shodan and Censys queries. This identifies vulnerable payment systems and related infrastructure for security assessments.

Can I generate structured target profiles for payment systems reconnaissance?

You can generate structured target profiles for payment systems reconnaissance by running automated multi-source intelligence gathering. The process outputs structured data files like active_targets.json to assist in initial attack surface mapping.