Recon Scan
The full picture of your external footprint: subdomains, certificates, services and what they reveal.
Loading documentation…
Recon Scan maps your external footprint: the domains, subdomains and endpoints that anyone on the internet can find. It shows you what an attacker would see before they start.
Recon Scan is an attack surface monitoring tool. It scans your domain and its subdomains and endpoints to find what is reachable.
This is different from Vulnerability Scan, which checks only the specific targets you have added. Recon Scan explores the wider structure of your domain.
The results are spread over several tabs, in addition to the main dashboard. Where a tab contains an issue that affects your HackRisk Score, a bell icon points you to it.
For each domain scanned, Recon Scan looks up its registration details. This shows what is held at the domain registration and DNS level, which can include:
HackRisk tries to retrieve the SSL certificate for every reachable subdomain it finds. Each certificate includes the issuer, the issue and expiry dates, the encryption standard and other usage details.
The most useful details are usually the issuer, the encryption standard and the dates, as these help you keep your domains secure.
On this page, you can also set notifications for when a certificate is close to expiring. This is available to subscribers only. If you are on a free trial, you will still receive an email if any certificates had already expired at the time of your free scan.
Some endpoints return no certificate data. That is common and does not necessarily mean there is a problem. It matters only when no certificate is present at all, which the results show separately.
The Subdomains tab lists every subdomain found. For each one it can show:
This tab shows what has changed since the previous Recon Scan: which subdomains and endpoints have been added, and which have been removed.
It is useful for spotting something new that you did not expect to be public. On a free trial there is no earlier scan to compare against, so the tab stays empty.
The URLs tab lists the URLs HackRisk has been able to find, along with the technologies they use and how they responded.
Recon Scan also checks for vulnerabilities across the subdomains it discovers. This check is less in-depth than Vulnerability Scan, but it covers a wider area.
As in Vulnerability Scan, each issue is listed by CVSS level. Here the results can also include Info and Unknown severities.
The Visualisation tab presents the data from the other tabs as a graphic. It adds no new information, but it makes the relationships between your domains, subdomains and other findings easier to see.