asn-infrastructure-mapping
Map organization IP infrastructure via ASN, CIDR, TLD expansion, and reverse DNS.
Install / Use
npx skills add uphiago/recon-skills --skill asn-infrastructure-mappingInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
OperationsSupported Platforms
Tags
Our assessment of asn-infrastructure-mapping
asn-infrastructure-mapping scores 89/100 on our quality scale, 271st of 576 Operations skills we index (top 48%).
Its SKILL.md is 6.3 KB long, well organised into 41 sections with 8 code examples: a thorough specification that gives an agent plenty to work with.
With 1,280 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 29 days ago, so asn-infrastructure-mapping is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
asn-infrastructure-mapping compared with similar skills
All 4 of these similar skills score higher than asn-infrastructure-mapping; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| asn-infrastructure-mapping (this skill)by uphiago | 89 | 1.3k | 29d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 8d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 8d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 9d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 9d ago | SKILL.md |
Frequently asked questions
- How do I install asn-infrastructure-mapping?
- Run
npx skills add uphiago/recon-skills --skill asn-infrastructure-mapping. The install tabs above show the steps for each supported agent. - Which AI agents does asn-infrastructure-mapping work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is asn-infrastructure-mapping safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is asn-infrastructure-mapping still maintained?
- The repository was last updated 29 days ago, so asn-infrastructure-mapping is actively maintained.
Skill content
View source on GitHubname: asn-infrastructure-mapping description: Map organization IP infrastructure via ASN, CIDR, TLD expansion, and reverse DNS. version: 1.1.0 revision_date: 2026-07-25 license: MIT platforms: [linux] compatibility: Requires curl, dnsx, httpx tags: [recon, ASN, CIDR, IP-range, TLD, reverse-DNS, infrastructure] category: recon related_skills:
- subdomain-enumeration
- origin-ip-discovery
- vhost-enumeration
- port-mass-scan
ASN Infrastructure Mapping
Map an organization's entire IP infrastructure by pivoting from domain to ASN (Autonomous System Number), extracting CIDR ranges, and discovering every hostname and service across all owned IP blocks. Includes TLD expansion to find sibling domains on different top-level domains with separate infrastructure.
When to Use
- You have a target domain and want to discover EVERY IP owned by the organization.
- Passive subdomain enumeration found only a few hosts — the rest may be on sibling TLDs or different IP ranges.
- The target has a known ASN that can be expanded to full CIDR blocks.
- Services on non-standard ports are invisible to web-only recon.
- Acquired subsidiaries or international domains may sit on different ASNs with weaker security.
Prerequisites
terminalwhois, dnsx, mapcidr, httpx, and asnmap.- The target domain and/or a known IP belonging to the organization.
- Shodan API key (optional, for deeper OSINT).
Quick Detection
# Start: domain → IP → ASN → CIDR ranges
IP=$(dig target.com +short | head -1)
ASN=$(whois $IP | grep -i "origin\|OriginAS" | awk '{print $NF}' | head -1)
echo "ASN: $ASN"
whois -h whois.radb.net -- "-i origin $ASN" | grep -Eo "([0-9.]+){4}/[0-9]+" | sort -u
Procedure
Phase 1 — Domain to ASN Discovery
# asnmap — automated domain → ASN
asnmap -d target.com
# Manual whois approach
IP=$(dig target.com +short | head -1)
whois $IP | grep -iE "origin|OriginAS|route:|descr:" | head -10
# spk — finds all ASNs for a company by name (including subsidiaries)
spk -json -s "Company Name"
# Webtools
# https://bgp.he.net — search by company name
# https://asnlookup.com — search by org name, ASN, or CIDR
# https://bgp.tools — modern BGP explorer
Phase 2 — ASN to CIDR Ranges
# asnmap — direct CIDR extraction
asnmap -a AS33905 -silent > cidr_ranges.txt
# RADB whois — full route objects
whois -h whois.radb.net -- "-i origin AS33905" \
| grep -Eo "([0-9.]+){4}/[0-9]+" \
| sort -u >> cidr_ranges.txt
# metabigor — multi-source IP intelligence
echo "Company Name" | metabigor net --org -o cidr_ranges.txt
echo "ASN33905" | metabigor net --asn -o cidr_ranges.txt
Phase 3 — CIDR to Individual IPs
# mapcidr — split CIDR into flat IP list
cat cidr_ranges.txt | mapcidr -silent > all_ips.txt
wc -l all_ips.txt
# prips — alternative IP generator
while read cidr; do prips "$cidr"; done < cidr_ranges.txt >> all_ips.txt
# Scan discovered IPs for live web services
cat all_ips.txt | httpx \
-ports 80,443,8080,8443,3000,5000,8000,8888,9090,9443 \
-status-code -title -web-server -silent \
-o live_ip_services.txt
Phase 4 — Reverse DNS on IP Ranges
# dnsx PTR — resolve hostnames from IP blocks
cat cidr_ranges.txt | dnsx -silent -resp-only -ptr > ptr_domains.txt
# Filter for target-related hosts
grep -i "target" ptr_domains.txt > ptr_target.txt
# hakrevdns — reverse DNS at scale
hakrevdns -d target.com -R resolvers.txt
# resolveDomains — check which IPs serve target content
resolveDomains -d all_subs.txt > resolved.txt
awk '{print $3}' resolved.txt | sort -u > unique_ips.txt
Phase 5 — TLD Expansion
# tldbrute — discover all registered TLD variants
tldbrute -d target.com
# Manual IANA TLD list approach
wget -q https://data.iana.org/TLD/tlds-alpha-by-domain.txt
ROOT=$(echo "target.com" | cut -d. -f1)
cat tlds-alpha-by-domain.txt | tr '[:upper:]' '[:lower:]' \
| while read tld; do echo "$ROOT.$tld"; done \
| httpx -silent -mc 200 > tlds_alive.txt
# Apply to all known subdomains
cat all_subs.txt | while read sub; do
cat tlds-alpha-by-domain.txt | tr '[:upper:]' '[:lower:]' \
| sed "s/^/$sub./"
done | dnsx -silent > subs_tld_expanded.txt
Phase 6 — Architecture Visualization
# Map which domains belong to which IP
cat unique_ips.txt | while read ip; do
echo -n "$ip: "
grep -l "$ip" resolved.txt 2>/dev/null | tr '\n' ' '
echo
done > ip_to_domain_map.txt
# Identify shared infrastructure (one IP serving multiple domains — CDN or reverse proxy)
awk '{if (NF > 2) print}' ip_to_domain_map.txt > shared_infra.txt
# Scan non-web ports on ALL discovered IPs
naabu -l all_ips.txt -p - -rate 1000 -c 50 -exclude-ports 80,443 -o all_services.txt
Phase 7 — Sub-organization Discovery
# Extract all company/organization names from whois
cat all_ips.txt | while read ip; do
whois $ip 2>/dev/null | grep -iE "OrgName|org-name|descr:" | head -1
done | sort -u > subsidiary_names.txt
# For each subsidiary, repeat the ASN → CIDR pipeline
cat subsidiary_names.txt | while read org; do
metabigor net --org "$org" >> expanded_cidr.txt
done
Pitfalls
- CIDR ranges can be massive (e.g., AWS). Only scan IP ranges confirmed to belong to the target, not the entire hosting provider.
- RADB whois data may be stale. Cross-reference with multiple sources (bgp.he.net, Censys, Shodan).
- TLD expansion is noisy. Only .com/.org/.net/.io/.dev usually produce useful results.
- Reverse DNS may reveal internal hostnames. Handle with care in external recon — these leaks are findings themselves.
- Sub-organization discovery can lead to out-of-scope targets. Always verify the relationship before scanning.
Verification
- CIDR ranges were confirmed via at least two sources (whois + bgp.he.net or asnmap).
- Reverse DNS on discovered IPs returned target-related hostnames.
- TLD expansion found live domains on sibling TLDs.
- Web service scan identified unique applications on non-standard ports.
- Map the full infrastructure: domains → IPs → services → vulnerabilities.
Related Skills
subdomain-enumeration— Generate the initial subdomain list before expanding to IP infrastructure.origin-ip-discovery— Once CIDR ranges are known, identify which IPs are origins behind CDN.vhost-enumeration— Scan discovered IPs for hidden virtual hosts.port-mass-scan— Scan all discovered IPs for exposed services.
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
