Skip to content
Back to skills

Attack Surface Mapper

ASecurity

Mapear la superficie de ataque de un dominio: subdominios, OSINT, typosquatting.

  • 50 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 27, 2026
ai-agentsgobashdockertestingsecurity

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 28, 2026

npx -y skills add gonzalezpazmonica/savia --skill attack-surface-mapper --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Attack Surface Mapper?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Attack Surface Mapper
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/gonzalezpazmonica-attack-surface-mapper/badge)](https://www.skillsdirectory.com/skills/gonzalezpazmonica-attack-surface-mapper)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
layer: peripheral
name: attack-surface-mapper
description: "Mapear la superficie de ataque de un dominio: subdominios, OSINT, typosquatting."
metadata:
  # --- metadata.savia.* (SE-333) ---
  savia.authorization_required: true
  savia.maturity: beta
  savia.category: security
  savia.context: fork
  savia.context_cost: medium
  savia.priority: high
  savia.summary: "OSINT y enumeracion de subdominios con subfinder, httpx, theHarvester y dnstwist. REQUIERE autorizacion explicita del propietario del dominio antes de ejecutar. Output: subdomains.txt + typosquatting.json + surface-map-{target}-YYYYMMDD.json"
  savia.tags: "attack-surface, subdominios, osint, dnstwist, subfinder"
---

# Attack Surface Mapper — SE-243

## AVISO: AUTORIZACIÓN OBLIGATORIA

Este skill ejecuta herramientas activas contra infraestructura real.
Escanear dominios sin autorización escrita puede ser ilegal.

**Antes de usar:**
```bash
bash scripts/surface-map-authorize.sh --target <domain>
```

## Triggers

- "mapea la superficie de ataque de..."
- "subdominios de..."
- "attack surface mapping"
- "dnstwist typosquatting"
- "theHarvester OSINT"

## Flujo

```
1. Verificar autorización → output/security/authorization-{domain}.txt
2. subfinder  — enumeración pasiva de subdominios
3. httpx      — HTTP probing de subdominios encontrados
4. theHarvester — OSINT: emails, IPs, tecnologías
5. dnstwist   — typosquatting: dominios similares registrados
6. Report     → output/security/surface-map-{domain}-YYYYMMDD.json
```

## Uso

```bash
# Paso 1: autorizar
bash scripts/surface-map-authorize.sh --target ejemplo.com

# Paso 2: mapear
bash scripts/attack-surface-map.sh \
  --target ejemplo.com \
  --tools subfinder,httpx,theharvester,dnstwist
```

## Herramientas (Docker fallback automático)

| Herramienta | Imagen Docker | Función |
|---|---|---|
| subfinder | projectdiscovery/subfinder | Enumeración pasiva subdominios |
| httpx | projectdiscovery/httpx | HTTP probing |
| theHarvester | secsi/theharvester | OSINT emails/IPs |
| dnstwist | elceef/dnstwist | Typosquatting detection |

## Output

```
output/security/
  authorization-{domain}.txt          ← gate de autorización
  surface-map-{domain}-YYYYMMDD.json  ← report consolidado
  attack-surface-{domain}-YYYYMMDD/
    subdomains.txt     ← input para pentesting skill Fase 2
    raw/httpx.json
    raw/dnstwist.json
    raw/harvest.txt
```

## Integración

- Salida `subdomains.txt` es input para `pentesting` skill Fase 2
- Complementa SE-246 (network-recon) y SE-245 (dynamic-web-testing)
- Reports marcados N3 — no incluir en repos públicos

## Gate de autorización

Sin `output/security/authorization-{domain}.txt` con contenido "AUTHORIZED"
y antigüedad < 30 días, el script aborta con exit 1.

El fichero se crea con `surface-map-authorize.sh` que pide confirmación interactiva.

Files in this skill

  • DOMAIN.md3.4 KB
  • SKILL.md2.8 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…