Skip to content

Expert-led service

Reconnaissance and external attack surface assessments.

Before an attacker touches your application, they map your perimeter. We conduct comprehensive open-source intelligence (OSINT) and external asset discovery to find every forgotten asset, leaked secret, and exposure path before adversaries do.

What we test

Scope, agreed in writing.

  • Subdomain & perimeter enumeration

    Passive DNS, certificate transparency logs, ASN mapping, and dormant infrastructure.

  • Credential & breach intelligence

    Dark web forum auditing, paste site monitoring, and corporate email exposure in historical breaches.

  • Public code & secret leaks

    Unintended repository commits, public S3 buckets, exposed Jira instances, and leaked API tokens.

  • Cloud & shadow IT discovery

    Unregistered staging environments, forgotten test domains, and dangling DNS pointers vulnerable to subdomain takeover.

How we work

Methodical, and never destructive without agreement.

  1. 01Define scope and organizational boundaries in writing.
  2. 02Execute non-intrusive passive reconnaissance across open intelligence sources and certificate logs.
  3. 03Analyze employee exposure, credential leaks, and corporate metadata footprints.
  4. 04Validate active service banners, DNS records, and potential takeover candidates safely.
  5. 05Deliver an actionable attack surface catalog prioritized by exploitability.

What you receive

  • Complete external attack-surface inventory with live status
  • Leaked credential and dark-web exposure intelligence report
  • Subdomain takeover and dangling record remediation guide
  • Executive risk briefing on corporate digital footprint

Manual testing or MyPentest?

MyRecon runs automated OSINT lookups, username tracking, and breach intelligence. MyPentest scans discovered web assets for live vulnerabilities.

Our expert-led reconnaissance service performs in-depth human investigation into corporate supply-chain leakage, executive threat profiling, and multi-cloud perimeter sprawl.

Automated vs manual penetration testing

FAQ

Questions, answered straight.

How long does an engagement take?

Most engagements run 5-12 testing days depending on scope, with the report delivered within 5 business days of testing finishing. Exact dates are agreed in the scoping document before you commit.

Will testing affect production?

Rules of engagement are agreed in writing before anything starts. We recommend a staging environment; when production testing is required we use non-destructive techniques, throttle traffic and agree testing windows. Denial-of-service testing is never performed without explicit written agreement.

Is retesting included?

Yes. When you've fixed the issues, we retest them and confirm in writing which are closed.

Is reconnaissance safe for our live systems?

Yes. Reconnaissance is conducted predominantly through passive OSINT intelligence sources, public DNS registries, and certificate transparency archives without intrusive probing against your production hosts.

How does reconnaissance connect to penetration testing?

Reconnaissance provides the complete target inventory. Once your perimeter assets are mapped, high-risk web applications and APIs can be immediately fed into automated or manual penetration testing.

Talk to a tester, not a sales team.

A free 30-minute scoping call, then a fixed quote in writing. Or start with a free automated pentest today.