Red Team Tools and Methodology

Automates red-team reconnaissance and vulnerability discovery across targets using Amass, Subfinder, httpx, nucleli.

Updated Jan 12, 2026
One-click install
npx skills add https://github.com/jcastillotx/vibe-skeleton-app --skill red-team-tools-and-methodology-jcastillotx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Red Team Tools and Methodology
Source: https://github.com/jcastillotx/vibe-skeleton-app/tree/main/setup/skills/red-team-tools
Command: npx skills add https://github.com/jcastillotx/vibe-skeleton-app --skill red-team-tools-and-methodology-jcastillotx

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill streamlines red-team reconnaissance, vulnerability discovery, and tool-driven attack workflows, reducing manual toil and enabling repeatable security assessments.

Core Features & Use Cases

  • Automated Recon Pipelines: Orchestrate subdomain enumeration, live host discovery, technology fingerprinting, and content discovery across targets.
  • Vulnerability Discovery Focus: Identify attack surfaces and potential vectors for bug bounty programs, with structured outputs for reporting.
  • Use Case: When tasked with assessing a new target, run the automated recon pipeline to produce a prioritized list of live hosts, technologies, and exposed endpoints ready for testing.

Quick Start

Acquire a Linux-based attack machine, ensure Amass/Subfinder/HTTPX/Nuclei/etc. are installed, configure API keys, and run the included recon script to begin enumeration on a target domain.

Frequently Asked Questions about Red Team Tools and Methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate red-team reconnaissance and subdomain enumeration for a new target?

This skill streamlines red-team reconnaissance by orchestrating subdomain enumeration, live host discovery, and technology fingerprinting. It produces prioritized lists of live hosts and exposed endpoints ready for vulnerability testing.

What is the best way to set up an automated pentest pipeline for bug bounty workflows?

The best way is using a Linux-based attack machine with Amass, Subfinder, httpx, and Nuclei installed. Configuring API keys for third-party services enables structured vulnerability discovery and automated reporting for bug bounty workflows.

Do I need specific API keys to run automated security recon and vulnerability discovery?

Yes, automated security recon and vulnerability discovery requires API keys for third-party services. These keys enhance subdomain enumeration and data enrichment when running tools like Amass and Subfinder against your target domains.

Can I use this automated recon pipeline for technology fingerprinting and live host discovery?

Yes, the automated recon pipeline covers technology fingerprinting and live host discovery. It identifies active attack surfaces across targets and outputs structured data for reporting within bug bounty programs.

What tools are required to perform automated vulnerability discovery and threat hunting?

Performing automated vulnerability discovery and threat hunting requires a Linux-based attack machine with Amass, Subfinder, httpx, and Nuclei installed. These toolchains enable subdomain enumeration, live host discovery, and technology fingerprinting.

Does this red-team toolchain provide structured outputs for bug bounty reporting?

Yes, the red-team toolchain provides structured outputs for bug bounty reporting. It identifies potential attack vectors and exposed endpoints, reducing manual toil and enabling repeatable security assessments.