// Reconnaissance AI guide

Mapping an attack surface

Turn raw recon output into a structured attack-surface map — grouping hosts and services, noting technologies, and prioritizing where authorized testing effort belongs.

Once enumeration has told you what exists, attack-surface mapping organizes it into something you can reason about. A pile of hostnames is data; a map is a plan. The aim is to see the target the way a defender's inventory should — and to notice what the defender may have missed.

Group by service and technology

Cluster the live hosts by what they run: web applications, APIs, admin panels, mail, and so on. Note the technology fingerprint of each — server software, frameworks, and versions — because that shapes which weaknesses are plausible.

Look for the outliers

  • Staging, dev, and test hosts that were never meant to be public.
  • Old technology versions that lag behind the main application.
  • Endpoints that behave differently from their siblings.

Outliers are where authorized testing is most often productive, because they are where security attention was thinnest.

Record impact potential, not just existence

For each cluster, note what it appears to handle — authentication, payments, user data. Surfaces that touch sensitive functionality deserve priority over surfaces that do not, regardless of how many hosts each has.

Related guides

Subdomain enumeration, explainedHow subdomain enumeration works and why it matters for authorized recon — passive vs active discovery, resolving live hosts, and turning a domain list into a testable surface.

Terms used here

Attack surfaceThe full set of points where an attacker could attempt to interact with a system — every exposed domain, endpoint, service, and input. Mapping the attack surface is a core goal of reconnaissance because you can only assess what you know exists.ReconnaissanceThe information-gathering phase of a security assessment, in which a tester builds a picture of an authorized target — its domains, hosts, services, and technologies — before testing anything. Often shortened to recon.