// Bug Bounty AI guide

A bug bounty reconnaissance workflow

A practical, repeatable reconnaissance workflow for authorized bug bounty targets — from confirming scope to mapping the attack surface and deciding where to look first.

Good reconnaissance is less about running more tools and more about building an accurate, organized picture of what you are allowed to test. A repeatable workflow keeps you thorough without wandering out of scope. The steps below are the shape most hunters converge on.

1. Confirm and record the scope

Before anything else, read the program's policy and write down what is in scope, what is explicitly out, and any constraints (rate limits, required headers, test-account rules). Everything you do afterward is checked against this list.

2. Enumerate the attack surface

For a web target, enumeration usually starts with discovering subdomains and then identifying which of them are live and what services they run. The goal is coverage: you can only test what you have found.

  • Passive discovery first (certificate transparency, public datasets) — it is quiet and low-risk.
  • Then active resolution to see which hosts actually respond.
  • Note technologies and services so you can group similar targets.

See the dedicated guide on subdomain enumeration for the details of this step.

3. Organize what you found

Raw tool output is not a plan. Collapse it into a structured attack-surface map: hosts, the services on them, and the technologies in use. This is where an assistant like MAKEIY is genuinely useful — turning scattered output into an organized picture and helping you spot the interesting outliers.

4. Prioritize where to look

You will never have time to test everything. Prioritize surfaces that are unusual, recently changed, or handle sensitive functionality. Depth on a promising target usually beats a shallow sweep across everything.

5. Keep notes for the report

Record what you did as you go — the URLs, the requests, the responses. When you find something, that trail becomes the reproduction steps in your report, and a clear report is what actually gets a bug fixed.

Related guides

Writing a clear vulnerability reportWhat makes a vulnerability report easy to triage and act on — a precise title, real impact, reproducible steps, and concrete remediation, written for the person who has to fix it.

Terms used here

ReconnaissanceThe information-gathering phase of a security assessment, in which a tester builds a picture of an authorized target — its domains, hosts, services, and technologies — before testing anything. Often shortened to recon.Attack surfaceThe full set of points where an attacker could attempt to interact with a system — every exposed domain, endpoint, service, and input. Mapping the attack surface is a core goal of reconnaissance because you can only assess what you know exists.Bug bountyA program through which an organization invites security researchers to find and report vulnerabilities in its systems, usually in exchange for recognition or a monetary reward. Testing is authorized only within the program's published scope and rules.