End-to-end passive reconnaissance for a domain, website or IP — builds an asset inventory covering registration, DNS, subdomains, infrastructure, tech stack, history and ownership without sending a single packet to the target. Use when asked to research or profile a domain or website, map what an organisation runs, or investigate a suspicious site without alerting its operator. Applies to vendor and third-party risk assessment, attack-surface review, M&A technical diligence, phishing and fraud-s
Detected risks:
Recon a Domain Passively is an OSINT workflow that turns a single domain, website, or IP into a defensible inventory of an organization's internet-facing estate and the owner behind it — without sending a single packet to the target. Its distinctive contribution is not new techniques but the order, the inventory discipline, and a stopping rule. It explicitly guards against two failure modes: enumerating for hours and producing an unattributed pile of hostnames, and quietly drifting from passive into active probing.
The workflow runs six ordered, cheapest-and-quietest-first stages as a loop: registration and DNS baseline, name-space expansion from archival sources like Certificate Transparency and passive DNS, resolution and inventory building, infrastructure and services from third-party scan platforms only, content/history/code/tech-stack assembly from archives and indexes, and owner attribution. Each stage has a written 'done when' criterion and feeds selectors back to earlier stages. It leans on companion skills (who-owns-this-domain, find-hidden-subdomains, find-exposed-servers, read-deleted-pages, google-like-a-spy, secrets-in-git-history, find-the-original-image) and a reference schema for the asset inventory. Step 1 requires writing down authorized scope, jurisdiction, and the passive boundary, and references a repository ETHICS.md; the skill also sets disable-model-invocation so it is not auto-triggered.
It targets security teams and analysts doing vendor and third-party risk assessment, attack-surface review, M&A technical diligence, phishing and fraud-site investigation, and pre-engagement scoping. This is dual-use reconnaissance tooling, but the framing is strictly passive, authorization-gated, and defensively oriented — it uses only third-party archival and scan data and forbids probing the target directly. The reconnaissance nature and the fact that it profiles third parties are the only notable considerations, and both are heavily mitigated by the scope and passive-boundary discipline built into the workflow.
Because it builds its map entirely from third-party archival and scan sources — Certificate Transparency, passive DNS, scan platforms, web archives, and indexes — without sending any packets to the target, so the operator is not alerted.
Yes. Step 1 requires writing down the subject, objective, out-of-bounds list, jurisdiction, and passive boundary, and references a repository ETHICS.md; it is also marked disable-model-invocation so it is not auto-triggered.
A deduplicated, timestamped asset inventory covering registration, DNS, subdomains, resolved IPs and ASNs, infrastructure and services, tech stack, and owner attribution, each finding tied to the artifact it rests on.
When a saturation-based stopping rule is met: two consecutive new sources yield no new assets, every name is resolved or classified with an owner and attribution grade, and naming-convention gaps are accounted for.
Reconnaissance is inherently dual-use, but the workflow is explicitly passive, scope-gated, and defensive (vendor risk, attack-surface review, diligence, phishing investigation), and it forbids any active probing of the target.
Quick Setup:
.claude/skills/Repository
useosint/osint-skills