A practical, repeatable reconnaissance workflow for authorized bug bounty targets — from confirming scope to mapping the attack surface and deciding where to look first.
Good reconnaissance is less about running more tools and more about building an accurate, organized picture of what you are allowed to test. A repeatable workflow keeps you thorough without wandering out of scope. The steps below are the shape most hunters converge on.
Before anything else, read the program's policy and write down what is in scope, what is explicitly out, and any constraints (rate limits, required headers, test-account rules). Everything you do afterward is checked against this list.
For a web target, enumeration usually starts with discovering subdomains and then identifying which of them are live and what services they run. The goal is coverage: you can only test what you have found.
See the dedicated guide on subdomain enumeration for the details of this step.
Raw tool output is not a plan. Collapse it into a structured attack-surface map: hosts, the services on them, and the technologies in use. This is where an assistant like MAKEIY is genuinely useful — turning scattered output into an organized picture and helping you spot the interesting outliers.
You will never have time to test everything. Prioritize surfaces that are unusual, recently changed, or handle sensitive functionality. Depth on a promising target usually beats a shallow sweep across everything.
Record what you did as you go — the URLs, the requests, the responses. When you find something, that trail becomes the reproduction steps in your report, and a clear report is what actually gets a bug fixed.