1. Help centre
  2. Your services
  3. Recon Scan
  • Welcome to HackRisk
  • Getting started
  • Reading your dashboard
  • Sophia, your AI assistant
  • Dark Web Scan
  • Vulnerability Scan
  • Recon Scan
  • Supply Chain Risk
  • Security Awareness & Phishing
  • Managing your account

Recon Scan

The full picture of your external footprint: subdomains, certificates, services and what they reveal.

Loading documentation…

Vulnerability Scan< PreviousSupply Chain RiskNext >

Powered by heyo

On this page

OverviewDomain InformationSSL CertificatesSubdomainsRecon Data ChangesURLsVulnerabilitiesVisualisation

Recon Scan maps your external footprint: the domains, subdomains and endpoints that anyone on the internet can find. It shows you what an attacker would see before they start.

Overview

Recon Scan is an attack surface monitoring tool. It scans your domain and its subdomains and endpoints to find what is reachable.

This is different from Vulnerability Scan, which checks only the specific targets you have added. Recon Scan explores the wider structure of your domain.

The results are spread over several tabs, in addition to the main dashboard. Where a tab contains an issue that affects your HackRisk Score, a bell icon points you to it.

Domain Information

For each domain scanned, Recon Scan looks up its registration details. This shows what is held at the domain registration and DNS level, which can include:

  • Name servers.
  • Associated domains.
  • Details of the organisation or person who registered the domain.

SSL Certificates

HackRisk tries to retrieve the SSL certificate for every reachable subdomain it finds. Each certificate includes the issuer, the issue and expiry dates, the encryption standard and other usage details.

The most useful details are usually the issuer, the encryption standard and the dates, as these help you keep your domains secure.

On this page, you can also set notifications for when a certificate is close to expiring. This is available to subscribers only. If you are on a free trial, you will still receive an email if any certificates had already expired at the time of your free scan.

Some endpoints return no certificate data. That is common and does not necessarily mean there is a problem. It matters only when no certificate is present at all, which the results show separately.

Subdomains

The Subdomains tab lists every subdomain found. For each one it can show:

  • Vulnerabilities found.
  • Technologies detected.
  • Associated IP addresses.
  • Other information that could be retrieved.

Recon Data Changes

This tab shows what has changed since the previous Recon Scan: which subdomains and endpoints have been added, and which have been removed.

It is useful for spotting something new that you did not expect to be public. On a free trial there is no earlier scan to compare against, so the tab stays empty.

URLs

The URLs tab lists the URLs HackRisk has been able to find, along with the technologies they use and how they responded.

Vulnerabilities

Recon Scan also checks for vulnerabilities across the subdomains it discovers. This check is less in-depth than Vulnerability Scan, but it covers a wider area.

As in Vulnerability Scan, each issue is listed by CVSS level. Here the results can also include Info and Unknown severities.

  • Select Fetch details on an issue for guidance on how to fix it.
  • If you believe an issue is a false positive, or you do not consider it a real risk, you can acknowledge it. It stays visible but no longer counts towards your HackRisk Score.

Visualisation

The Visualisation tab presents the data from the other tabs as a graphic. It adds no new information, but it makes the relationships between your domains, subdomains and other findings easier to see.