What problem does it solve?
This Skill eliminates the guesswork and wasted effort of targeting low-yield or regulated sectors during offensive recon campaigns, using field-validated data from 600+ US companies across 28 sectors to prioritize high-vulnerability, low-effort targets.
Core Features & Use Cases
- Sector Vulnerability Tiering: Categorizes sectors into Tier 1 (high yield, 15-25% vulnerability rate), Tier 2 (medium yield, 5-14%), and Tier 3 (zero/low yield, skip unless specific intelligence exists) to focus effort on the most productive targets.
- Automated Target Compilation: Generates cleaned domain lists for selected sectors via crt.sh and subfinder, with built-in filtering for CDNs, parking pages, and SaaS platforms that are not self-hosted WordPress.
- OPSEC-Controlled Batch Probing: Includes a Python script for serial, delayed domain probing that checks for WordPress, user enumeration, CORS reflection, XMLRPC, and exposed .git/.env files without triggering WAF blocks.
- Use Case: If you are planning a WordPress-focused recon campaign, use this Skill to first identify that landscaping and dental clinics have 30-50% WordPress adoption rates with minimal WAF protection, then compile a vetted target list of 100+ domains in those sectors for batch scanning.
Quick Start
Use the sector-recon-methodology skill to identify the top 3 high-yield sectors for WordPress recon and compile a cleaned target list of 50 domains for batch scanning.