Recon and Methodology Router
This is the starting router for new targets and unknown attack surfaces.
When to Use
- You just received a new target and do not yet know what to test first
- You need to begin by drawing the surface from the application, then asset discovery, fingerprinting, and test-route planning
- You want to build follow-up testing on structured methodology instead of random payload enumeration
Skill Map
- Attack Surface Mapping — from one URL / one app, draw hosts, APIs, keys, and the object graph
- Recon and Methodology
- Insecure Source Code Management — .git/.svn/.hg exposure detection
- Dependency Confusion — Supply chain reconnaissance for internal package names
Recommended Flow
- Confirm in-scope assets and target type
- Draw the surface from the application: attack-surface-mapping
- Route the inventory to api-sec, auth-sec, injection-checking, or business-logic-vuln