Recon — Subdomain and Shadow IT Discovery // MODULES

Recon — Subdomain and Shadow IT Discovery

Continuous surface discovery: subdomain enumeration, port and service scanning, technology and certificate fingerprinting.

Overview

Findings are indexed and feed the EASM and Investigate modules automatically, keeping the exposure inventory up to date.

Capabilities

  • Multi-source subdomain enumeration
  • Port and service scanning
  • Technology and CMS fingerprinting
  • Certificate collection (crt.sh/CT logs)
  • Scheduled re-scan with diff

Use Cases

  • Inventory the organization’s exposed assets
  • Discover shadow IT and forgotten subdomains
  • Map a target’s technology stack
  • Feed assets into EASM and investigations

Integrations

  • OODA EASM / Investigate
  • Shodan, crt.sh, Subfinder

SLA & Guarantees

Scheduled re-scan · asset diff

Next Steps