Definition · Subdomain Enumeration

What is Reconnaissance?

Reconnaissance — often shortened to recon — is the work an attacker does before touching anything sensitive. The goal is a map: which domains and subdomains exist, which hosts resolve, which ports answer, what software is running, who works there, and which of all that is weakest.

Passive and active reconnaissance

Passive reconnaissance draws only on third-party sources and never sends traffic to the target: WHOIS and registration data, passive DNS history, certificate transparency logs, search engines, code repositories, and job adverts. It is effectively undetectable by the target.

Active reconnaissance interacts with the target directly: DNS resolution and brute-forcing, port scanning, banner grabbing, service fingerprinting, and crawling web applications. It is faster and more accurate, but it appears in logs.

Why defenders should do the same work

Reconnaissance is not an attacker-only activity. The same techniques, run against your own domains, produce the inventory you are supposed to already have — and the gap between that inventory and the one in your asset register is usually where incidents come from: a forgotten staging environment, a supplier’s hostname under your domain, an admin panel someone exposed temporarily two years ago.

Reducing what recon yields

You cannot stop passive reconnaissance; certificate logs and DNS are public by design. What you can do is reduce what it finds — decommission unused names, avoid descriptive hostnames for sensitive systems, keep wildcard certificates and internal naming out of public records, and close services that need not be public.

Reconnaissance combines OSINT sources with active asset discovery, feeds a threat actor’s choice of attack vector, and is the first phase of any penetration test or subdomain enumeration exercise.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.