External (perimeter / internet-facing) infrastructure penetration testing. Use when the user mentions external pentest, perimeter test, OSINT, subdomain enumeration, ASN, BBOT, Shodan, port scan, banner grab, service enumeration, edge-device CVEs (Ivanti, Citrix, F5, Fortinet, PAN, Sophos, MOVEit, ScreenConnect, Confluence, vCenter), credential stuffing/spraying against public portals, or cloud bucket enumeration.
Installation
Installer avec Codex ou Claude Copiez ce prompt, collez-le dans Codex, Claude ou un autre assistant, puis laissez-le vérifier la page du skill et l'installer pour vous.
Passive before active. BBOT-led recon for the deep passive pass; mark active items with 🛰 vs ⚠ per CONVENTIONS.md.
Nuclei + targeted version-CVE matching for vulnerability analysis. Track edge-device CVEs current to year of engagement (see tool-mappings/03-infra-external-tools.md).
Each finding maps to stable ID in the relevant phase file. Generate findings via templates/finding-template.md.
On foothold, transition to pentest-infra-internal. Web app at the perimeter → also pentest-web-api.