Reference workflow / Pentest consultancies and red teams

External reconnaissance

Move from passive subdomain discovery to approved vulnerability scanning without losing the chain of evidence.

Workflow contract
Audience
Pentest consultancies and red teams
Authorized scope
Authorized domain targets
Expected outcome
A repeatable inventory of discovered subdomains, live hosts and scanner output.
Approval policy
Review the complete scope and active-test policy before the workflow is approved to run.
Expected artifacts
  • Discovered subdomains
  • Live-host inventory
  • Scanner output
  • Approval and execution record
Node sequence

How the workflow is composed

  1. 01
    Input

    Target domain

    Accept and validate the authorized domain scope.

  2. 02
    Tool

    Asset discovery

    Enumerate passive sources through an approved catalog action.

  3. 03
    Tool

    Service validation

    Identify reachable HTTP services and capture basic metadata.

  4. 04
    Tool

    Security checks

    Run the approved template and severity policy.

  5. 05
    Output

    Assessment export

    Retain node outputs with the execution record.

This blueprint describes the intended orchestration pattern. A pilot confirms the exact registered tools, worker dependencies, input schema and output contract before execution.
ChaosEngine early access

Bring your current external reconnaissance process.

We are onboarding a focused group of security teams and helping each one translate an existing process into a governed ChaosEngine workflow.