External reconnaissance
Move from passive subdomain discovery to approved vulnerability scanning without losing the chain of evidence.
Workflow contract
- Audience
- Pentest consultancies and red teams
- Authorized scope
- Authorized domain targets
- Expected outcome
- A repeatable inventory of discovered subdomains, live hosts and scanner output.
- Approval policy
- Review the complete scope and active-test policy before the workflow is approved to run.
Expected artifacts
- Discovered subdomains
- Live-host inventory
- Scanner output
- Approval and execution record
Node sequence
How the workflow is composed
- 01Input
Target domain
Accept and validate the authorized domain scope.
- 02Tool
Asset discovery
Enumerate passive sources through an approved catalog action.
- 03Tool
Service validation
Identify reachable HTTP services and capture basic metadata.
- 04Tool
Security checks
Run the approved template and severity policy.
- 05Output
Assessment export
Retain node outputs with the execution record.
This blueprint describes the intended orchestration pattern. A pilot confirms the exact registered tools, worker dependencies, input schema and output contract before execution.
ChaosEngine early access
Bring your current external reconnaissance process.
We are onboarding a focused group of security teams and helping each one translate an existing process into a governed ChaosEngine workflow.