Definition · Subdomain Enumeration
What is Reconnaissance?
Reconnaissance — often shortened to recon — is the work an attacker does before touching anything sensitive. The goal is a map: which domains and subdomains exist, which hosts resolve, which ports answer, what software is running, who works there, and which of all that is weakest.
Passive and active reconnaissance
Passive reconnaissance draws only on third-party sources and never sends traffic to the target: WHOIS and registration data, passive DNS history, certificate transparency logs, search engines, code repositories, and job adverts. It is effectively undetectable by the target.
Active reconnaissance interacts with the target directly: DNS resolution and brute-forcing, port scanning, banner grabbing, service fingerprinting, and crawling web applications. It is faster and more accurate, but it appears in logs.
Why defenders should do the same work
Reconnaissance is not an attacker-only activity. The same techniques, run against your own domains, produce the inventory you are supposed to already have — and the gap between that inventory and the one in your asset register is usually where incidents come from: a forgotten staging environment, a supplier’s hostname under your domain, an admin panel someone exposed temporarily two years ago.
Reducing what recon yields
You cannot stop passive reconnaissance; certificate logs and DNS are public by design. What you can do is reduce what it finds — decommission unused names, avoid descriptive hostnames for sensitive systems, keep wildcard certificates and internal naming out of public records, and close services that need not be public.
Related concepts
Reconnaissance combines OSINT sources with active asset discovery, feeds a threat actor’s choice of attack vector, and is the first phase of any penetration test or subdomain enumeration exercise.