recon-and-methodology

Create structured reconnaissance plans for authorized security testing and bug bounty engagements.

96|1|Updated Jun 4, 2026
One-click install
npx skills add https://github.com/langbyyi/CyberStrikeAI-SRC --skill recon-and-methodology-langbyyi
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: recon-and-methodology
Source: https://github.com/langbyyi/CyberStrikeAI-SRC/tree/main/skills/recon-and-methodology
Command: npx skills add https://github.com/langbyyi/CyberStrikeAI-SRC --skill recon-and-methodology-langbyyi

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill eliminates the risk of incomplete, ad-hoc reconnaissance that leads to missed high-severity vulnerabilities and inefficient bug bounty or penetration testing workflows.

Core Features & Use Cases

  • Systematic Recon Hierarchy: Follow a structured, step-by-step workflow from target scope definition through endpoint discovery to vulnerability testing, ensuring full attack surface coverage.
  • Proven Bug Bounty Methodology: Leverage tested frameworks from top bug hunters including Zseano's testing sequence and high-value target triage guidance to find bugs that others miss.
  • Use Case: A bug bounty hunter or authorized security tester can use this Skill to map all subdomains, discover hidden endpoints, fingerprint underlying technology, and prioritize testing on high-probability vulnerability areas for a new target program.

Quick Start

Use the recon-and-methodology skill to build a complete reconnaissance plan and attack surface map for the target domain example.com, following the provided bug bounty best practices.

Frequently Asked Questions about recon-and-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure reconnaissance for bug bounty hunting on a new target domain?▼

Bug bounty reconnaissance should follow a systematic hierarchy from target scope definition through subdomain mapping to endpoint discovery. This structured workflow ensures full attack surface coverage and prevents missing high-severity vulnerabilities during security testing.

What is the best way to map an attack surface for authorized penetration testing?▼

The best way to map an attack surface is through systematic asset enumeration, endpoint discovery, and technology fingerprinting. This approach identifies hidden endpoints and prioritizes testing on high-probability vulnerability areas for new target environments.

Can I use a structured methodology to find high-severity bugs that others miss?▼

Yes, applying proven bug bounty methodologies like Zseano's testing sequence helps triage high-value targets and identify vulnerabilities that ad-hoc testing misses. Structured vulnerability testing workflows prioritize high-probability areas for better bug discovery results.

Does technology fingerprinting help with endpoint discovery in security testing?▼

Technology fingerprinting identifies underlying target infrastructure during endpoint discovery, enabling testers to map subdomains and prioritize high-probability vulnerability areas. This systematic approach ensures full attack surface coverage across new target environments.

Why does ad-hoc reconnaissance lead to missed vulnerabilities in bug bounty programs?▼

Ad-hoc reconnaissance lacks systematic attack surface enumeration and structured vulnerability testing workflows, causing inefficient testing and missed high-severity bugs. Following a proven bug bounty methodology ensures complete asset mapping and endpoint discovery coverage.

What is systematic vulnerability mapping in penetration testing workflows?▼

Systematic vulnerability mapping is a structured process for identifying high-severity bugs through asset mapping, endpoint discovery, and technology fingerprinting. It adheres to industry-standard bug bounty testing methodologies for authorized security testing engagements.