What problem does it solve? Subdomains with dangling CNAME, NS, or MX records pointing to deprovisioned cloud resources can be claimed by attackers, enabling cookie theft, phishing under trusted domains, and email interception. This Skill provides a systematic playbook to identify, verify, and demonstrate these vulnerabilities during authorized security assessments. ## Core Features & Use Cases - Provider Fingerprint Matching: Match HTTP error responses against a fingerprint table covering AWS S3, GitHub Pages, Heroku, Azure, Shopify, Fastly, and more to confirm claimability. - CNAME, NS, and MX Takeover Workflows: Step-by-step claim procedures for common providers, plus high-severity NS zone takeover and MX email interception scenarios. - Decision Tree & Impact Assessment: A structured decision tree guides detection through exploitation, including post-takeover impact analysis for cookies, CORS, CSP, and OAuth redirect abuse. - Use Case: During a bug bounty recon phase, you enumerate subdomains with subfinder, resolve their CNAMEs, and use this playbook to confirm a NoSuchBucket S3 response is claimable, then document the takeover proof-of-concept. ## Quick Start Ask the agent to check whether any of the target's subdomains have dangling CNAME records vulnerable to takeover using the subdomain-takeover playbook.