Expert-led service
Reconnaissance and external attack surface assessments.
Before an attacker touches your application, they map your perimeter. We conduct comprehensive open-source intelligence (OSINT) and external asset discovery to find every forgotten asset, leaked secret, and exposure path before adversaries do.
What we test
Scope, agreed in writing.
Subdomain & perimeter enumeration
Passive DNS, certificate transparency logs, ASN mapping, and dormant infrastructure.
Credential & breach intelligence
Dark web forum auditing, paste site monitoring, and corporate email exposure in historical breaches.
Public code & secret leaks
Unintended repository commits, public S3 buckets, exposed Jira instances, and leaked API tokens.
Cloud & shadow IT discovery
Unregistered staging environments, forgotten test domains, and dangling DNS pointers vulnerable to subdomain takeover.
How we work
Methodical, and never destructive without agreement.
- 01Define scope and organizational boundaries in writing.
- 02Execute non-intrusive passive reconnaissance across open intelligence sources and certificate logs.
- 03Analyze employee exposure, credential leaks, and corporate metadata footprints.
- 04Validate active service banners, DNS records, and potential takeover candidates safely.
- 05Deliver an actionable attack surface catalog prioritized by exploitability.
What you receive
- Complete external attack-surface inventory with live status
- Leaked credential and dark-web exposure intelligence report
- Subdomain takeover and dangling record remediation guide
- Executive risk briefing on corporate digital footprint
Manual testing or MyPentest?
MyRecon runs automated OSINT lookups, username tracking, and breach intelligence. MyPentest scans discovered web assets for live vulnerabilities.
Our expert-led reconnaissance service performs in-depth human investigation into corporate supply-chain leakage, executive threat profiling, and multi-cloud perimeter sprawl.
Automated vs manual penetration testingFAQ
Questions, answered straight.
How long does an engagement take?
Most engagements run 5-12 testing days depending on scope, with the report delivered within 5 business days of testing finishing. Exact dates are agreed in the scoping document before you commit.
Will testing affect production?
Rules of engagement are agreed in writing before anything starts. We recommend a staging environment; when production testing is required we use non-destructive techniques, throttle traffic and agree testing windows. Denial-of-service testing is never performed without explicit written agreement.
Is retesting included?
Yes. When you've fixed the issues, we retest them and confirm in writing which are closed.
Is reconnaissance safe for our live systems?
Yes. Reconnaissance is conducted predominantly through passive OSINT intelligence sources, public DNS registries, and certificate transparency archives without intrusive probing against your production hosts.
How does reconnaissance connect to penetration testing?
Reconnaissance provides the complete target inventory. Once your perimeter assets are mapped, high-risk web applications and APIs can be immediately fed into automated or manual penetration testing.
Talk to a tester, not a sales team.
A free 30-minute scoping call, then a fixed quote in writing. Or start with a free automated pentest today.