pentest-recon
Pentest: Reconnaissance, OSINT, subdomain enumeration, attack surface mapping.
ソース情報
- リポジトリ
- aurict/aurict
- ソースの最終更新活動
- 2026年6月24日 19:34
- 検出された SKILL.md の言語
- 英語
- スター
- 33
- フォーク
- 2
インストール方法
デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。
ソースファイルを確認
インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。
SKILL.md を表示中
SKILL.md
ソースの指示 · 読み取り専用プレビュー- name
- pentest-recon
- description
- Pentest: Reconnaissance, OSINT, subdomain enumeration, attack surface mapping.
- triggers
- {"keywords":["recon","reconnaissance","osint","subdomain","attack surface","footprint","enumeration","passive recon","active recon","information gathering"]}
- auto_load_when
- Reconnaissance phase of a penetration test or attack surface mapping
- agent
- pentest
- tools
- ["Read","Bash","WebFetch","WebSearch"]
# Reconnaissance & Attack Surface Mapping
---
## Passive Recon (no direct contact with target)
### DNS & Subdomain Discovery
```bash
# Passive subdomain enumeration (certificate transparency, APIs)
subfinder -d TARGET.com -silent -o subdomains_passive.txt
# Certificate transparency logs
webfetch https://crt.sh/?q=%.TARGET.com&output=json
# DNS records
dig TARGET.com ANY
dig _dmarc.TARGET.com TXT
dig _spf.TARGET.com TXT
# Zone transfer attempt (often blocked but worth trying)
dig axfr TARGET.com @ns1.TARGET.com
```
### Google Dorks
```
site:TARGET.com filetype:pdf
site:TARGET.com inurl:admin
site:TARGET.com inurl:login
site:TARGET.com "internal use only"
site:TARGET.com ext:env OR ext:config OR ext:bak
"TARGET.com" inurl:github
```
### Shodan / Censys
```
# Search exposed services (via websearch or API)
websearch "site:shodan.io TARGET.com"
websearch "TARGET.com port:8080 http.title:admin"
# Look for: exposed admin panels, default creds, unpatched versions
```
### GitHub OSINT
```
websearch "site:github.com TARGET.com password OR secret OR api_key"
websearch "site:github.com TARGET.com .env"
# Search for leaked credentials, internal URLs, API documentation
```
---
## Active Recon (direct contact with target)
### Port & Service Enumeration
```bash
# Fast full port scan
nmap -p- --min-rate 5000 -T4 TARGET -oN ports.txt
# Detailed scan on discovered ports
PORTS=$(grep "^[0-9]" ports.txt | cut -d/ -f1 | tr '\n' ',')
nmap -sV -sC -p $PORTS TARGET -oN services.txt
# Service-specific scripts
nmap --script http-headers,http-title -p 80,443,8080,8443 TARGET
nmap --script ssl-cert,ssl-enum-ciphers -p 443 TARGET
nmap --script smb-vuln* -p 445 TARGET
```
### Web Technology Fingerprinting
```bash
# Detect tech stack from response headers
curl -Is https://TARGET | grep -i "server\|x-powered-by\|x-aspnet\|x-generator"
# Detect CMS / framework
curl -s https://TARGET | grep -Ei "wordpress|drupal|joomla|django|rails|laravel"
# Check robots.txt and sitemap
curl -s https://TARGET/robots.txt
curl -s https://TARGET/sitemap.xml
```
### Web Crawling & Content Discovery
```bash
# Directory and file brute force
ffuf -w /usr/share/wordlists/dirb/common.txt \
-u https://TARGET/FUZZ -fc 404 -o dirs.json
# Crawl with katana (finds JS-rendered content)
katana -u https://TARGET -o crawl.txt -jc -kf all
# Find API endpoints
grep -Eo '"\/api\/[^"]+' crawl.txt | sort -u
```
### Screenshot & Visual Recon
```bash
# Take screenshots of all discovered subdomains (requires gowitness)
gowitness file -f subdomains.txt --screenshot-path ./screenshots/
# Quick HTTP probe: find which subdomains are alive
cat subdomains.txt | httpx -silent -o live_hosts.txt
```
---
## Attack Surface Map (output format)
After recon, document findings as:
```markdown
## Target: TARGET.com
### Scope
- In scope: *.TARGET.com, 192.168.1.0/24
- Out of scope: mail.TARGET.com
### Discovered Hosts
| Host | IP | Ports | Tech Stack | Notes |
|---|---|---|---|---|
| app.TARGET.com | 1.2.3.4 | 80,443 | React/Node.js | Login page |
| api.TARGET.com | 1.2.3.5 | 443,8080 | Express 4.17 | API server |
| admin.TARGET.com | 10.0.0.1 | 443 | PHP 7.4 | Admin panel |
### Interesting Findings
- admin.TARGET.com accessible from internet (expected to be internal)
- api.TARGET.com running Express 4.17 — check CVE-2022-24999
- api.TARGET.com/api/v1/swagger exposed — full API documentation
### Prioritized Attack Vectors
1. SSRF via image URL parameter (app.TARGET.com/resize?url=)
2. Admin panel exposed — default credentials attempt
3. Outdated Express → prototype pollution CVE
```
---
## Recon Checklist
```
[ ] DNS records (A, MX, TXT, NS, CNAME)
[ ] Certificate transparency → subdomains
[ ] Zone transfer attempt
[ ] Port scan all discovered hosts
[ ] Service version detection on open ports
[ ] Web technology fingerprinting
[ ] robots.txt, sitemap.xml, /.well-known/
[ ] Directory/file brute force on web services
[ ] API endpoint discovery (JS files, crawling)
[ ] Google dorking for sensitive files
[ ] GitHub/code repository search
[ ] Shodan/Censys for internet-exposed services
[ ] SSL/TLS configuration (cipher suites, cert info)
[ ] HTTP security headers check
```
GitHubで見る