ALL_AGENTSBUILD.01 · ATTACK SURFACE

    What you ship is
    what they see.
    Map it first.

    The Recon agent walks the public internet the way an offensive team would, pivoting from a single domain to every subdomain, forgotten staging environment, exposed bucket, leaked credential and shadow integration that belongs to you. Continuously, not on a quarterly cadence.

    10 min
    to first map
    24/7
    drift monitoring
    1,400+
    data sources
    Passive
    no auth required
    RECON_AGENT // PERIMETER_MAP
    T+0.0s
    01.SEED
    02.ENUMERATE
    03.FINGERPRINT
    04.ATTRIBUTE
    05.RANK
    06.MONITOR
    ROOT
    DOMAIN
    CT_LOGS
    PASSIVE_DNS
    ASN
    api.staging
    old-portal
    internal-vpn
    shadow-app
    FIG.01 · NODE_GRAPHN=8 · E=9
    EMITTED · 0/4
    • AWAITING SIGNAL...
    FIELD_CONDITIONS

    Every breach starts with an asset the defender forgot existed.

    Marketing spins up a microsite. An ex-engineer leaves an S3 bucket public. A vendor exposes your API key in a sample repo. Your asset inventory was stale before you finished writing it. Recon assumes that, and rebuilds the picture every hour from sources attackers actually use.

    // CAPABILITY

    What a real reconnaissance pass looks like.

    MODULE_01 · DISCOVERY
    01/03

    From one seed to the entire perimeter

    Feed it a domain. The agent pivots through certificate transparency logs, ASN mappings, passive DNS, archived crawls, code-search and paste sites, surfacing subdomains, dev environments and shadow IT no asset register has.

    • Discovery depthITERATIVE
    • Sources1,400+
    • AttributionAUTOMATIC
    MODULE_02 · FINGERPRINT
    02/03

    Identify the stack, then the weakness

    Every discovered asset is fingerprinted, stack, version, framework, exposed services, secrets in JS bundles, default credentials. The Hive Mind correlates that against known exploits and your code paths to rank what is reachable now.

    • FingerprintsDEEP
    • Secret scanJS · HTML · API
    • Exploit matchREAL-TIME
    MODULE_03 · MONITOR
    03/03

    Drift is the breach. Watch for it.

    Every change to your perimeter, a new subdomain, an opened port, a rotated certificate, an exposed API, is captured, diffed and triaged. You are notified the moment the surface changes, not the next time someone runs a scan.

    • CadenceCONTINUOUS
    • Diff resolutionPER-ASSET
    • AlertingRISK-WEIGHTED

    From seed domain to triaged inventory.

    SEQ_LEN · 04
    01 · Seed

    Provide a root domain or org name. No agents, no auth, no scope sheet.

    02 · Pivot

    The agent expands across CT logs, DNS, ASN, code search and archives until it stops finding new assets.

    03 · Triage

    Each asset is fingerprinted, ranked by exposure, and routed into the Hive Mind for active testing.

    04 · Watch

    Drift in DNS, certificates, ports or secrets opens an incident before the next deploy.

    Where Recon pays for itself in week one.

    Find the assets your CMDB never knew about

    Most teams discover 30–60% more public assets than their inventory shows on the first scan. The agent finds them, attributes them and tells you who owns them.

    Catch the leaked credential before the attacker does

    Recon scans paste sites, code search and exposed JS bundles for keys, tokens and credentials tied to your domain, and rotates them through the Hive Mind for impact analysis.

    Make M&A diligence a one-day exercise

    Point Recon at the target's domain and get a full attack-surface report, assets, exposure, leaked secrets, deprecated stacks, in hours, not weeks.

    Be the first to know when something changes

    When marketing ships a new subdomain or an engineer reopens a staging port, the Hive Mind tests it before attackers find it on Shodan.

    FIELD_METRIC · OBSERVED
    47% UNKNOWN

    // FIELD_NOTE

    On the first pass, Recon typically surfaces 30–60% more public assets than the customer's own inventory shows. The unknowns are where the breach lives.

    Stop reading alerts.
    Start shipping fixes.

    Free for 14 days. Easy onboarding. Live in under five minutes.

    See it in action

    EU data residency. Cancel anytime.

    Red Team Recon & EASM Agent