domain-reconlisted
Install: claude install-skill f5-sales-demo/marketplace
**Canonical skill URI**: `skill://osint-framework:domain-recon`
# Domain Reconnaissance
Comprehensive domain investigation — WHOIS, DNS, subdomains,
certificates, reputation, hosting, and technology detection.
## Legal Notice
All tools use publicly available information only. Users must comply
with applicable laws and platform terms of service.
## Tools Reference
Read `skills/domain-recon/references/tools.md` for the complete
list of 131 free tools in this category — the largest category.
## Key command-line tools
| Tool | Install | Usage |
| ------ | --------- | ------- |
| subfinder | `go install github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest` | `subfinder -d domain.com` |
| amass | `go install github.com/owasp-amass/amass/v4/...@master` | `amass enum -d domain.com` |
| dnsrecon | `pip install dnsrecon` | `dnsrecon -d domain.com` |
| whois | Pre-installed on most systems | `whois domain.com` |
| dig | Pre-installed on most systems | `dig domain.com ANY` |
| nslookup | Pre-installed on most systems | `nslookup domain.com` |
| httpx | `go install github.com/projectdiscovery/httpx/cmd/httpx@latest` | `echo domain.com \| httpx` |
| dnsx | `go install github.com/projectdiscovery/dnsx/cmd/dnsx@latest` | `echo domain.com \| dnsx` |
## Subcategories
- **Whois Records** — Domain ownership and registration data
- **Subdomains** — Enumerate subdomains via DNS, certificates, scraping
- **Discovery** — Find related domains, reverse lookups
- **DNS Records** — A,