Agent skill

Origin Ip Discovery

by uphiago in uphiago/recon-skills

Discover origin IPs behind CDN/WAF via favicon hash, DNS history, and SSL certs.

MITAuto-check passedSecurity

Install Origin Ip Discovery

skills CLI
$ npx skills add uphiago/recon-skills --skill origin-ip-discovery -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install uphiago/recon-skills origin-ip-discovery --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/recon/origin-ip-discovery .claude/skills/origin-ip-discovery && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
origin-ip-discovery
GitHub stars
1.3k
Token cost
~1.7k tokens
SKILL.md length
326 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

Discover origin IPs behind CDN/WAF via favicon hash, DNS history, and SSL certs.

  • Works in 6 steps: Favicon Hash Fingerprinting → Historical DNS Records → SSL Certificate Search → …
  • Tasks that involve Cloud networking
  • SKILL.md covers When to Use, Prerequisites, Quick Detection and Procedure, plus 3 more sections
  • Calls curl, python3 and jq; reaches securitytrails.com and otx.alienvault.com; needs SECURITYTRAILS_KEY

What it does

Origin Ip Discovery is an agent skill from uphiago/recon-skills. Discover origin IPs behind CDN/WAF via favicon hash, DNS history, and SSL certs.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires curl, dnsx, python3, subfinder

It sits in Security, covering Cloud networking. It works with Google Analytics and Cloudflare. The repository describes itself as: Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh. The licence is MIT.

When your agent uses it

  • Tasks that involve Cloud networking

Example prompts

  • “/origin-ip-discovery”

Requirements

  • Python 3
  • A credential in SECURITYTRAILS_KEY
  • Compatibility (from SKILL.md): Requires curl, dnsx, python3, subfinder

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Favicon Hash Fingerprinting
  2. Historical DNS Records
  3. SSL Certificate Search
  4. Google Analytics ID Cross-Referencing
  5. Common Origin Leak Vectors
  6. Validate Origin

What it can do on your machine

Read from SKILL.md and the folder at commit 1260244. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • python3
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • securitytrails.com
    • otx.alienvault.com
    • crt.sh
    • search.censys.io
    • netlas.io
    • api.hackertarget.com
    • builtwith.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SECURITYTRAILS_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires curl, dnsx, python3, subfinder

    From compatibility in the SKILL.md frontmatter.

Context cost

Origin Ip Discovery loads about 1.7k tokens when it runs. Until then it costs about 25 tokens; SKILL.md has 326 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~25
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from uphiago/recon-skills at commit 1260244, republished under its MIT licence (© uphiago). 326 words, ~1,683 tokens.

Download SKILL.mdSave it as .claude/skills/origin-ip-discovery/SKILL.md (or your agent's skills folder).
name
origin-ip-discovery
description
Discover origin IPs behind CDN/WAF via favicon hash, DNS history, and SSL certs.
compatibility
Requires curl, dnsx, python3, subfinder
version
1.1.0
revision_date
2026-07-25
license
MIT
platforms
linux
tags
recon, origin-ip, CDN, WAF, bypass, Cloudflare, favicon, DNS
category
recon
related_skills
subdomain-enumeration, vhost-enumeration, port-mass-scan

Origin IP Discovery

Discover the real server IP behind CDN/WAF protections (Cloudflare, Akamai, Fastly). When the origin IP is found, the raw server is exposed without firewall rules, rate limiting, or application-layer filtering. Techniques include favicon hash fingerprinting across Shodan, historical DNS records from passive sources, SSL certificate SAN field matching, and Google Analytics ID cross-referencing.

When to Use

  • Target is behind Cloudflare/Akamai and returns 403 or CAPTCHA challenges on all requests.
  • You need direct access to the origin to bypass WAF rules.
  • Subdomain enumeration reveals internal/staging hosts on non-CDN IPs.
  • The target uses a single favicon across all infrastructure.
  • SSL certificates share the same organization name across IPs.

Prerequisites

  • terminal with curl, python3, and shodan CLI.
  • Shodan API key: shodan init <KEY>.
  • Target favicon file or URL.

Quick Detection

bash
# Check Cloudflare presence
curl --max-time 30 --connect-timeout 10 -sI "https://target.com" | grep -i "cf-ray\|server: cloudflare"

# If Cloudflare detected, check for common origin leaks
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/cdn-cgi/trace" | grep -E "ip=|colo="

Procedure

Phase 1 — Favicon Hash Fingerprinting
bash
# Get favicon hash
FAVICON_URL="https://target.com/favicon.ico"
curl --max-time 30 --connect-timeout 10 -sk "$FAVICON_URL" -o favicon_target.ico

# Calculate hash
python3 -c "
import hashlib, base64
with open('favicon_target.ico', 'rb') as f:
    hash_bytes = base64.b64encode(hashlib.md5(f.read()).digest())
    print(f'favicon hash: {hash_bytes.decode()}')
"

# Search Shodan for IPs serving this favicon
HASH=$(python3 -c "
import hashlib, base64
with open('favicon_target.ico','rb') as f:
    print(base64.b64encode(hashlib.md5(f.read()).digest()).decode())
")
shodan search "http.favicon.hash:$HASH" --fields ip_str,port,org,hostnames

# Automatedtools
python3 favUp.py -ff favicon_target.ico --shodan-cli
python3 favUp.py --web target.com -sc
Phase 2 — Historical DNS Records
bash
# SecurityTrails — DNS history
curl --max-time 30 --connect-timeout 10 -s "https://securitytrails.com/domain/target.com/history/a" \
  -H "APIKEY: $SECURITYTRAILS_KEY" \
  | jq '.records[].values[].ip' | sort -u

# AlienVault OTX — passive DNS
curl --max-time 30 --connect-timeout 10 -s "https://otx.alienvault.com/api/v1/indicators/domain/target.com/passive_dns" \
  | jq '.passive_dns[].address' | sort -u

# Automatedtools
echo "target.com" | originiphunter
cat domains.txt | originiphunter
bash
# crt.sh — find all certs for the domain, extract unique IPs from SAN fields
curl --max-time 30 --connect-timeout 10 -s "https://crt.sh/?q=%25.target.com&output=json" \
  | jq -r '.[].name_value' | tr ',' '\n' | sort -u > cert_domains.txt

# Censys — search by parsed names
# Web: https://search.censys.io — query: parsed.names: target.com

# Shodan — search by SSL subject CN
shodan search "ssl.cert.subject.cn:target.com" --fields ip_str,port,org

# Netlas — deep infrastructure search
# Web: https://netlas.io — query: domain:*.target.com
Phase 4 — Google Analytics ID Cross-Referencing
bash
# Extract Analytics ID from target pages
curl --max-time 30 --connect-timeout 10 -s "https://target.com" | grep -Eo '(?:UA-|G-|GTM-)[A-Z0-9]+'

# Find all domains sharing the same GA ID
curl --max-time 30 --connect-timeout 10 -s "https://api.hackertarget.com/analyticslookup/?q=UA-XXXXXXXX-X"
curl --max-time 30 --connect-timeout 10 -s "https://builtwith.com/relationships/target.com"

# Automated
cat subdomains.txt | analyticsrelationships
Phase 5 — Common Origin Leak Vectors
bash
# Direct IP in page source
curl --max-time 30 --connect-timeout 10 -sk "https://target.com" | grep -Eo '\b(?:\d{1,3}\.){3}\d{1,3}\b' | sort -u

# DNS CNAME chain — may expose origin
dig target.com ANY +noall +answer
dig www.target.com CNAME +short

# MX records — mail server often shares infrastructure
dig target.com MX +short

# SPF records — may contain non-CDN IPs
dig target.com TXT +short | grep -Eo '\b(?:\d{1,3}\.){3}\d{1,3}\b'

# Subdomain with different IP pattern
subfinder -d target.com -silent | dnsx -silent -a -resp-only | sort -u > all_ips.txt
# Filter out Cloudflare IPs (104.x, 172.64-71.x)
grep -vE '^104\.(1[6-9]|2[0-9]|3[0-1])\.|^172\.(6[4-9]|7[0-1])\.' all_ips.txt > non_cf_ips.txt
# Probe each for the target's content
for ip in $(cat non_cf_ips.txt); do
  curl --max-time 30 -sk --connect-timeout 5 "https://$ip" -H "Host: target.com" -o /dev/null -w "%{http_code} $ip\n"
done | grep -v "^403\|^000"
Phase 6 — Validate Origin
bash
# Check if IP serves the target's content
curl --max-time 30 --connect-timeout 10 -sk "https://ORIGIN_IP" -H "Host: target.com" | grep -o '<title>[^<]*</title>'

# Verify favicon matches
curl --max-time 30 --connect-timeout 10 -sk "https://ORIGIN_IP/favicon.ico" -H "Host: target.com" -o favicon_origin.ico
md5sum favicon_target.ico favicon_origin.ico  # should match

# Probe ports directly on origin
naabu -host ORIGIN_IP -p - -rate 2000

Pitfalls

  • Cloudflare may block your IP on repeated scans. Rotate user-agents and proxies.
  • Shodan queries require an API key. Free tier is rate-limited.
  • The origin may also be behind firewall rules. Even if you find the IP, it may only accept traffic from Cloudflare's IP ranges.
  • Google Analytics IDs are shared across unrelated sites. Verify by favicon or content match before claiming a finding.
  • Non-CDN IPs from subdomains may be load balancers, not the actual web server origin. Probe with Host header to confirm.

Verification

  1. Favicon hash matches between CDN-cached site and direct origin IP.
  2. HTTPS request to origin IP with Host: target.com returns the same page content.
  3. Open ports on origin differ from CDN-proxied ports (origin exposes SSH, MySQL, etc.).
  4. SSL certificate on the origin IP lists the target domain in SAN.
  • subdomain-enumeration — Generate the subdomain list needed for IP deduplication.
  • vhost-enumeration — Once origin IP is found, enumerate virtual hosts.
  • port-mass-scan — Scan origin IP for exposed services.

© uphiago, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in recon/origin-ip-discovery of uphiago/recon-skills.

Open the folder on GitHubat commit 1260244

Compare with similar skills

Origin Ip Discovery next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Origin Ip Discovery compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Origin Ip Discovery this skilluphiago/recon-skills1.3k—~1.7kAutomated safety check: PassMIT
External Enumerationforefy/.context152—~3.1kAutomated safety check: PassMIT
OmniRoute Tunnel CLIdiegosouzapw/OmniRoute74k1 repos~339Automated safety check: PassMIT
OmniRoute Tunnelsdiegosouzapw/OmniRoute74k—~209Automated safety check: PassMIT
Cdn Setupsickn33/agentic-awesome-skills47k2 repos~2.9kAutomated safety check: PassMIT
DNS Managementsickn33/agentic-awesome-skills47k2 repos~2.7kAutomated safety check: PassMIT

Similar skills

  • External Enumeration

    forefy/.context

    Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs.

    152 GitHub stars~3.1k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • OmniRoute Tunnel CLI

    diegosouzapw/OmniRoute

    Starts, stops, and inspects ngrok, Cloudflare, or custom tunnel connections from the command line, including auth and reachability.

    74k GitHub starsUsed in 1 repo~339 tokens
    DevOps & CloudAuto-check passed
  • OmniRoute Tunnels

    diegosouzapw/OmniRoute

    Create and manage secure tunnels (ngrok, Cloudflare Tunnel, custom) to expose OmniRoute to the internet or share access with remote agents and CI pipelines.

    74k GitHub stars~209 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Cdn Setup

    sickn33/agentic-awesome-skills

    Configure CDNs for content delivery. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~2.9k tokens
    DevOps & CloudAuto-check passed
  • DNS Management

    sickn33/agentic-awesome-skills

    Configure DNS zones and records. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~2.7k tokens
    DevOps & CloudAuto-check passed
  • Implementing Cloud Waf Rules

    mukul975/Anthropic-Cybersecurity-Skills

    Deploys and tunes Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare, covering managed rule sets, custom business-logic rules, rate limiting, bot management, and false-positive…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from uphiago/recon-skills

All 23 skills in this repo
  • Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.

    1.3k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Error Log Mining

    uphiago/recon-skills

    Mine errorlog for creds, paths, SQL when leak hunt finds. An agent skill from uphiago/recon-skills.

    1.3k GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • JS Secrets Extraction

    uphiago/recon-skills

    Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

    1.3k GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Recon Playbook

    uphiago/recon-skills

    A skill your agent uses when starting or restructuring an authorized external web and API assessment.

    1.3k GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Web Enumeration

    uphiago/recon-skills

    Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect

    1.3k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check: notes
  • 401 403 Bypass Techniques

    uphiago/recon-skills

    A skill your agent uses when protected HTTP routes return 401 or 403.

    1.3k GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Origin Ip Discovery

What does Origin Ip Discovery do?

Discover origin IPs behind CDN/WAF via favicon hash, DNS history, and SSL certs. Origin Ip Discovery is an agent skill from uphiago/recon-skills. Discover origin IPs behind CDN/WAF via favicon hash, DNS history, and SSL certs.

When should I use Origin Ip Discovery?

Origin Ip Discovery fits situations like: tasks that involve Cloud networking.

How do I install Origin Ip Discovery in Claude Code?

Run `npx skills add uphiago/recon-skills --skill origin-ip-discovery -a claude-code`. Or copy the skill folder (recon/origin-ip-discovery in uphiago/recon-skills) into .claude/skills/origin-ip-discovery in your project. Claude Code loads it when a task matches its description.

How do I install Origin Ip Discovery in Codex?

Run `npx skills add uphiago/recon-skills --skill origin-ip-discovery -a codex`. Or copy the skill folder (recon/origin-ip-discovery in uphiago/recon-skills) into .agents/skills/origin-ip-discovery in your project. Codex loads it when a task matches its description.

Can I use Origin Ip Discovery in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add uphiago/recon-skills --skill origin-ip-discovery -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/origin-ip-discovery, .gemini/skills/origin-ip-discovery, .github/skills/origin-ip-discovery and .opencode/skills/origin-ip-discovery in your project.

What does Origin Ip Discovery need to run?

Going by SKILL.md and its folder, Origin Ip Discovery needs the command-line tools its instructions call (curl, python3 and jq) and credentials named SECURITYTRAILS_KEY. Our summary lists: Python 3; A credential in SECURITYTRAILS_KEY. Compatibility (from SKILL.md): Requires curl, dnsx, python3, subfinder.

Does Origin Ip Discovery access the network?

SKILL.md names 7 domains. In commands or code: securitytrails.com, otx.alienvault.com, crt.sh, search.censys.io, netlas.io, api.hackertarget.com and builtwith.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Origin Ip Discovery safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Origin Ip Discovery use?

Origin Ip Discovery is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Origin Ip Discovery use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Origin Ip Discovery?

Skills that share tags, products or a category with Origin Ip Discovery: External Enumeration (forefy/.context, 152 stars), OmniRoute Tunnel CLI (diegosouzapw/OmniRoute, 74k stars), OmniRoute Tunnels (diegosouzapw/OmniRoute, 74k stars) and Cdn Setup (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Origin Ip Discovery?

uphiago (a GitHub user) maintains it in uphiago/recon-skills, which has 1,294 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 1, 2026.

Source: uphiago/recon-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.