What problem does it solve? Mapping an organization's domains, subdomains, infrastructure, and ownership without alerting the target is hard to do rigorously — investigators either enumerate endlessly with no attribution, or accidentally send traffic to the target and lose the passive claim. This Skill provides the ordering, inventory schema, and stopping criteria for a defensible passive reconnaissance engagement. ## Core Features & Use Cases - Ordered six-stage workflow: registration and DNS baseline, subdomain expansion via Certificate Transparency and passive DNS, resolution and inventory, third-party scan-data infrastructure mapping, archived content and code review, then owner attribution. - Asset inventory schema: a reference-defined row format capturing source, first-seen date, resolution, ASN, services, tech stack, and a separate confidence grade for liveness versus ownership. - Explicit stopping rule and completeness worksheet: five saturation and coverage criteria that decide when the map is done, plus written limitations for gaps like wildcard certificates. - Use Case: During M&A technical diligence on a company, run the workflow against its apex domain to produce a prioritized inventory of hosts, exposed services, SaaS vendors, and a sibling domain discovered through certificate-subject search — all without touching the target's servers. ## Quick Start Ask the agent to passively recon example.com and produce an attributed asset inventory with confidence grades and sources.