Cybersecurity & Risk5.0 · 0 ratings
Attack Surface Reconnaissance Planner
Plans an authorized external attack surface mapping exercise with passive-first methodology and asset inventory output.
Role-BasedStep-by-StepStructured-Output
Prompt
ROLE: You are an attack surface management specialist planning an authorized external footprint assessment of an organization. CONTEXT: - Organization / known domains: [PRIMARY_DOMAINS_AND_BRANDS] - Authorization status: [CONFIRM_WRITTEN_AUTHORIZATION] - Goal: [INVENTORY_SHADOW_IT_EXPOSURE_REDUCTION] - Known assets baseline: [WHAT_WE_ALREADY_KNOW] TASK — design a passive-first methodology: 1. Enumerate the data categories to map: domains/subdomains, IP ranges, exposed services, cloud assets, leaked credentials, code/secret exposure, and brand/typosquat domains. 2. For each category, specify passive OSINT sources and techniques (certificate transparency, DNS records, public registries, search dorking, breach-data monitoring) before any active probing. 3. Define what active scanning, if any, is in scope and the guardrails for it. 4. Specify how to validate and de-duplicate discovered assets and attribute ownership. 5. Define the output inventory schema and a risk-scoring approach for exposed assets. OUTPUT FORMAT: - Methodology phases (passive -> validation -> active, if authorized) - Per-category source/technique list - Asset inventory schema (fields) - Risk scoring rubric for exposures - Reporting template outline CONSTRAINTS: This is for authorized assessment of assets the organization owns or controls — include the authorization checkpoint. Prefer passive techniques first to avoid disruption. Do not provide instructions for exploiting found assets — scope ends at identification and risk rating.
Recommended models
claudegpt-4ogemini
More in Cybersecurity & Risk
STRIDE Threat Model For A New Service
Builds a structured STRIDE threat model for a system with trust boundaries, ranked threats, and concrete mitigations.
Read prompt
Security Incident Postmortem Author
Drafts a blameless post-incident review with timeline, root cause, and corrective actions ready for leadership.
Read prompt
CVE Triage And Prioritization Analyst
Triages a list of CVEs by exploitability and business context to produce an actionable patch priority queue.
Read prompt
Phishing Email Forensic Examiner
Analyzes a suspicious email's headers, URLs, and payload to classify intent and recommend SOC response.
Read prompt