advanced-reconnaissance
Elite methodology for discovering maximum attack surface with minimal detection (5-Layer Approach).
التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.
القائمة
Elite methodology for discovering maximum attack surface with minimal detection (5-Layer Approach).
التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.
استنادا إلى تصنيف SOC المهني
Elite AI/LLM exploitation specialist - prompt injection, jailbreaking, agent exploitation, RAG poisoning, multi-modal attacks, model extraction, and system prompt leakage for CTF and red team engagements
Build a full API inventory, trust-boundary map, and prioritized test matrix from specification and observed behavior.
Convert API vulnerability leads into confirmed impact or cleanly disproven outcomes with reproducible evidence.
Execute a predefined API test plan deterministically with complete request-level evidence and final verdicts.
Perform deep exploit-focused binary analysis by tracing attacker-reachable paths to validated vulnerability primitives.
Execute systematic static and dynamic binary analysis to uncover exploitable vulnerability primitives.
| name | Advanced Reconnaissance |
| description | Elite methodology for discovering maximum attack surface with minimal detection (5-Layer Approach). |
| author | 1ikeadragon |
| license | GPLv3 |
Prerequisites: DNS, HTTP, command-line tools
Goal: Discover maximum attack surface with minimal detection
Breadth → Depth → Exploitation Wide net → Focus → Attack
Key Principle: 80% of bugs come from assets others miss.
whois and amass intel to find ASNs and IP ranges.active_discovery workflows.subfinder, amass, crt.sh.puredns, shuffledns.altdns).naabu, nmap.live.txt (Httpx results)web_application_security skills.nuclei -t technologies, whatweb.waf_bypass skill if blocked).katana, hakrawler.javascript_analysis skill for deobfuscation).tmux or axiom for distributed scanning.Maintain a standardized directory structure (recon/target/subdomains, recon/target/web, etc.) as defined in the overarching methodology.