// Reconnaissance AI guide

Subdomain enumeration, explained

How subdomain enumeration works and why it matters for authorized recon — passive vs active discovery, resolving live hosts, and turning a domain list into a testable surface.

Subdomain enumeration is the process of discovering the hostnames that belong to a target domain — app.example.com, api.example.com, staging.example.com, and so on. It matters because each subdomain is a potential entry point, and the ones nobody remembered to secure are often the interesting ones.

Passive discovery

Passive techniques find subdomains from data that already exists, without touching the target directly. Certificate transparency logs, public DNS datasets, and search indexes reveal a large share of a domain's public footprint quietly.

Active discovery

Active techniques probe the target's DNS to confirm which names resolve and to brute-force likely names from a wordlist. This finds hosts that never appear in public data, at the cost of being noisier and generating traffic to the target.

Resolving and validating

A raw list of candidate names is not yet useful. Resolve them to see which are live, then check which respond on common web ports and what they return. A name that does not resolve, or resolves to a parked page, is not a target.

From list to surface

The output of enumeration feeds directly into attack-surface mapping: group the live hosts, note their technologies, and decide where to focus. Enumeration answers "what exists"; mapping answers "what matters."

Related guides

Mapping an attack surfaceTurn raw recon output into a structured attack-surface map — grouping hosts and services, noting technologies, and prioritizing where authorized testing effort belongs.

Terms used here

ReconnaissanceThe information-gathering phase of a security assessment, in which a tester builds a picture of an authorized target — its domains, hosts, services, and technologies — before testing anything. Often shortened to recon.Attack surfaceThe full set of points where an attacker could attempt to interact with a system — every exposed domain, endpoint, service, and input. Mapping the attack surface is a core goal of reconnaissance because you can only assess what you know exists.