recon-technique

Installation
SKILL.md

Recon technique

Goal: map the attack surface with minimal noise, identify high-value entry points, and produce a structured attack plan that drives the next phase (vulnerability scanning, exploitation).

When this technique applies

  • External perimeter scoping before a pentest or red team engagement.
  • Bug bounty scope expansion: discover assets before prioritizing targets.
  • Controlled lab or internal host/service mapping before authorized exploitation testing.
  • Pre-exploitation scoping: "where do I spend time?" before vuln scanning.
  • API attack-surface mapping before authz, injection, or workflow testing.

Boundary

  • vs. osint-technique: OSINT covers identity/person/organization research from public online sources. Recon-technique is attack-surface mapping — domains, IPs, services, endpoints. They overlap at passive DNS and infrastructure pivoting; when recon needs deeper person/company context, load osint-technique.
  • vs. network-technique: network-technique covers protocol analysis, PCAP, and in-engagement pivoting. Recon-technique is pre-exploitation surface mapping.
  • vs. vuln-scanners: recon produces the target list and service inventory that vuln scanners consume. Do not skip recon and throw scanners at the whole scope.

Initial triage

Installs
4
GitHub Stars
22
First Seen
Sep 5, 2026
recon-technique — aeondave/malskill