Back to glossary

Reconnaissance

2 min read

In offensive security, reconnaissance is the first phase of an attack: gathering information about a target to plan the intrusion. It is the first tactic in MITRE ATT&CK and the opening stage of the cyber kill chain, which both begin by describing exactly this, and it splits into a passive form and an active one.

July 29, 2026
Compartir:

How it works

Reconnaissance is the work of learning the target before acting on it, and it divides cleanly. Passive reconnaissance gathers information without touching the target’s systems: OSINT from public sources, registration records, and anything observable from outside, which leaves no trace on the target. Active reconnaissance interacts with the target directly (resolving and probing its DNS, scanning its exposed hosts and ports, enumerating its web applications and services) which is more revealing but detectable. It is the first tactic in MITRE ATT&CK and the opening stage of the cyber kill chain; both frameworks start here because every intrusion does. The output is a map of the target’s external footprint and the candidate ways in.

What goes wrong

The failure on the defender’s side is not knowing their own external footprint as well as an attacker will. Organisations lose track of what they expose: a forgotten subdomain, a staging server left public, a service stood up for a project and never removed, a DNS record pointing at a decommissioned host that invites subdomain takeover. From the attacker’s seat, reconnaissance is where the whole operation is shaped, and the reliable wins are the assets the organisation forgot it had, because those are the ones nobody is patching or watching. The attack surface an organisation manages is often smaller than the one it actually presents, and the gap between them is what reconnaissance finds first.

Where this shows up in an audit

Reconnaissance is the first phase of an external assessment, and its output is a map of the target’s exposure: the domains, subdomains, hosts, services and technologies reachable from outside, including the ones the organisation had forgotten. We report the surface itself as a finding where it is larger or more exposed than expected, since an unmanaged asset is a risk before any vulnerability is even tested. Keeping that surface known and small over time is the discipline of attack surface management. This is part of how we map an attack surface.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.