reconnaissance--osint-automation
FeaturedPassive and active reconnaissance, subdomain enumeration, DNS analysis, technology fingerprinting, and OSINT data correlation for authorized security assessments
Install
Quality Score: 95/100
Skill Content
Details
- Author
- Masriyan
- Repository
- Masriyan/Claude-Code-CyberSecurity-Skill
- Created
- 6 months ago
- Last Updated
- 3 days ago
- Language
- Python
- License
- MIT
Bundled in these plugins
Similar Skills
Semantically similar based on skill content — not just same category
recon-asset-discovery
Subdomain enumeration, CT logs, DNS record catalog, WHOIS/RDAP, and passive reconnaissance for authorized external recon.
domain-recon
Domain name reconnaissance — WHOIS, DNS records, subdomains, certificates, reputation, and hosting analysis. Use when the user wants to investigate a domain, find subdomains, check DNS records, look up WHOIS data, analyze SSL certificates, or assess domain reputation. Activates for "domain lookup", "WHOIS", "DNS records", "subdomains", "find subdomains", "certificate transparency", "who owns this domain", "domain reputation", "hosting provider".
recon-a-domain-passively
End-to-end passive reconnaissance for a domain, website or IP — builds an asset inventory covering registration, DNS, subdomains, infrastructure, tech stack, history and ownership without sending a single packet to the target. Use when asked to research or profile a domain or website, map what an organisation runs, or investigate a suspicious site without alerting its operator. Applies to vendor and third-party risk assessment, attack-surface review, M&A technical diligence, phishing and fraud-site investigation, and pre-engagement scoping. Reference at useosint.com/skills/recon-a-domain-passively.