// Pillar topic

Reconnaissance AI

Reconnaissance is the first phase of any authorized security assessment: building an accurate picture of the target's attack surface before you test anything. For a web target that usually means enumerating subdomains, identifying live hosts and services, and noting the technologies in use — always within the scope you are permitted to test.

MAKEIY assists the reconnaissance phase without removing you from the loop. It can help you plan an enumeration approach, explain what a given tool's output is telling you, and organize scattered findings into a structured attack-surface map you can prioritize. The tools still run against targets you are authorized to assess; MAKEIY helps you plan and make sense of the results.

How MAKEIY helps

Guides

Subdomain enumeration, explainedHow subdomain enumeration works and why it matters for authorized recon — passive vs active discovery, resolving live hosts, and turning a domain list into a testable surface.Mapping an attack surfaceTurn raw recon output into a structured attack-surface map — grouping hosts and services, noting technologies, and prioritizing where authorized testing effort belongs.

Key terms

ReconnaissanceThe information-gathering phase of a security assessment, in which a tester builds a picture of an authorized target — its domains, hosts, services, and technologies — before testing anything. Often shortened to recon.Attack surfaceThe full set of points where an attacker could attempt to interact with a system — every exposed domain, endpoint, service, and input. Mapping the attack surface is a core goal of reconnaissance because you can only assess what you know exists.Bug bountyA program through which an organization invites security researchers to find and report vulnerabilities in its systems, usually in exchange for recognition or a monetary reward. Testing is authorized only within the program's published scope and rules.

Related topics

Bug Bounty AIHow an AI assistant supports bug bounty hunting — planning reconnaissance, understanding vulnerability classes, and writing clear, responsible disclosure reports for authorized programs.Penetration Testing AIHow an AI assistant supports authorized penetration testing — planning a methodology, understanding findings, and documenting results. An assistant for testers, not an autonomous scanner.