recon-technique
Installation
SKILL.md
Recon technique
Goal: map the attack surface with minimal noise, identify high-value entry points, and produce a structured attack plan that drives the next phase (vulnerability scanning, exploitation).
When this technique applies
- External perimeter scoping before a pentest or red team engagement.
- Bug bounty scope expansion: discover assets before prioritizing targets.
- Controlled lab or internal host/service mapping before authorized exploitation testing.
- Pre-exploitation scoping: "where do I spend time?" before vuln scanning.
- API attack-surface mapping before authz, injection, or workflow testing.
Boundary
- vs. osint-technique: OSINT covers identity/person/organization research from public online sources. Recon-technique is attack-surface mapping — domains, IPs, services, endpoints. They overlap at passive DNS and infrastructure pivoting; when recon needs deeper person/company context, load
osint-technique. - vs. network-technique: network-technique covers protocol analysis, PCAP, and in-engagement pivoting. Recon-technique is pre-exploitation surface mapping.
- vs. vuln-scanners: recon produces the target list and service inventory that vuln scanners consume. Do not skip recon and throw scanners at the whole scope.