Recon automation pipeline

SkillMonitoring & ops

Chain recon tools into a repeatable, resumable pipeline for continuous bug-bounty coverage. Load on "automate recon", "recon pipeline", monitoring many programs, or scaling subdomain→ live→scan. Signals: wildcard scope at scale, wanting scheduled/continuous discovery.

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the Recon automation pipeline skill

What this skill tells your AI

The instructions your AI receives, as published by noorqureshi/sploitagent in skills/automation/automation-recon-pipeline/SKILL.md and read by ahel’s review.

When it applies

You track one or more wildcard programs and want discovery to run repeatably (and on a schedule), surfacing only new assets/findings instead of re-reviewing everything.

Why it works

Recon is a directed flow: roots → subdomains → resolve → live → ports → nuclei. Wiring the ProjectDiscovery tools together (each reads/writes lines) makes it composable, and diffing against last run (anew) turns it into continuous monitoring that alerts on change.

Method

  1. Pipeline (each stage feeds the next):
    subfinder -dL roots.txt -all -silent \
      | dnsx -silent -a -resp-only \
      | httpx -silent -sc -title -tech-detect \
      | tee live.txt \
      | nuclei -silent -severity low,medium,high,critical
    
  2. Diff for "only new": pipe each stage through anew subs.txt / anew live.txt so reruns emit only newly-seen lines — the basis of continuous monitoring.
  3. Notify: pipe results to notify (Slack/Discord/Telegram) so new hosts/findings alert you.
  4. Schedule with cron/systemd-timer/GitHub Actions; persist state files per program so runs resume.
  5. Keep templates current: nuclei -update-templates before each run.

Gotchas

  • Stay in scope: feed only in-scope roots, filter out-of-scope hosts before scanning.
  • Respect rate limits (-rl, -c) and program automation rules — don't hammer.
  • De-dupe wildcard DNS (dnsx wildcard filtering) or you'll alert on noise forever.

Verify success

A rerun surfaces only newly-appeared assets/findings and notifies you — hands-off continuous coverage.

References

ProjectDiscovery pipeline docs; TomNomNom anew; nuclei templates.

Signals

GitHub stars
20
Forks
7
Last commit
Sep 2026
Advanced
Item type
skill
Key
automation-recon-pipeline
Source
github.com/noorqureshi/sploitagent