In-scope asset list
Domains, subdomains, IP ranges and applications, each with ownership evidence and the date it was confirmed.
OSINT penetration testing reconnaissance gives your tester the attacker's starting map before the first scan: assets you forgot you had, which ones are really yours, which sit with cloud and hosting providers, and what your staff and code reveal. We do it as a separate, authorized phase and hand over a pack your tester can use on day one.
OSINT penetration testing reconnaissance is the information-gathering phase of a pentest, done from public and commercially available sources before any active testing. OSINT-S finds your internet-facing assets, confirms which are yours and which belong to providers, records exposed technology, people and leaked credentials, and delivers a scoped target list and an out-of-scope list. The active testing stays with your authorized tester.
The less your tester is told, the more the test depends on reconnaissance. A separate recon phase is most useful for black-box and threat-led tests.
| Test type | What the tester is given | Role of OSINT recon |
|---|---|---|
| Black-box | Only the company name or a main domain | Builds the target list from scratch, as an attacker would |
| Grey-box | Asset list, some accounts or documentation | Finds what the list missed: shadow IT, old subdomains, acquired brands |
| White-box | Full architecture and source access | Shows what outsiders can see, so findings can be ranked by real exposure |
| Threat-led or red team | Objectives and threat scenarios | Supplies the intelligence that scenarios are built on |
Buying recon as its own phase, from a team that does not run the exploitation, also gives you a second view of your estate that you can compare with the tester's results.
Recon routinely finds hosts that look like yours but belong to a supplier, a former subsidiary or a shared cloud service. Testing them without permission is the commonest scope mistake.
Each asset we find is put in one of three groups, with the evidence for the decision: owned and in scope, owned but excluded by your rules of engagement, or not yours. Typical "not yours" cases are a marketing agency's hosting, a SaaS login page on your subdomain, a former subsidiary sold years ago and shared content delivery addresses.
Cloud assets need a further check because providers set their own rules. AWS, for example, lets customers test listed services on their own accounts without prior approval, but prohibits activities such as DNS zone walking through Route 53 hosted zones, denial-of-service testing, request flooding and S3 bucket or subdomain takeover (AWS penetration testing policy). We flag where each asset is hosted so your tester can check the right policy before touching it. A possible subdomain takeover is reported to you as a finding to fix, never claimed to prove it.
Web application methodologies start with search-engine reconnaissance, and regulated threat-led tests require a formal threat intelligence phase.
Web application tests. The OWASP Web Security Testing Guide v4.2 opens its information gathering section with search engine discovery reconnaissance for information leakage, followed by tests such as reviewing webpage content for leakage and mapping application architecture (OWASP WSTG). We cover the public-source part: indexed admin pages, exposed documents, old API documentation and archived versions of the application.
Threat-led penetration testing in EU finance. Under the DORA standard on threat-led penetration testing, a threat intelligence provider analyzes generic and sector-specific threat intelligence for the financial entity, proposes scenarios that target each critical or important function in scope, and delivers a targeted threat intelligence report; the control team selects at least three scenarios. The recitals note that gathering typically takes about four weeks (Delegated Regulation (EU) 2025/1190, Article 10). Formal provider requirements apply to those tests, so we confirm with your test manager what role our reconnaissance can play before scoping.
Six components in machine-readable and written form, so the tester spends day one testing, not searching.
Domains, subdomains, IP ranges and applications, each with ownership evidence and the date it was confirmed.
Assets that look like yours but are not, with the reason, so nobody tests a supplier by accident.
Software, versions and services visible in public scan data, job ads and documentation.
Accounts in breach and stealer data, matched to current staff. We never test them; your rules decide whether the tester may.
Email formats and public roles, included only when social engineering is in scope.
Social engineering assessment →What was searched, when and with which tools, so results can be repeated after fixes.
Recon for a focused test from 10 business days, larger estates up to about a month, always under a signed authorization.
Recon for a focused external or web application test takes from 10 business days after the authorization is signed; a group with many brands, acquisitions or regions takes up to about a month. Urgent delivery costs 50% more, the price is fixed after written scoping, a senior analyst reviews the pack and the fee goes down if we miss the agreed date. We plan backwards from your tester's start date.
Our work stays passive: no scanning, exploitation, credential testing or takeover attempts. Employee data is minimized and deleted at the end as agreed under the GDPR and similar laws. If you are choosing tools to run recon in-house, see our reviews of theHarvester and Recon-ng. For the full method, including ATT&CK mapping and the exposure map, see red team OSINT reconnaissance; for other OSINT services for security teams, see the overview.
Send the test type, the domains or brands in scope, the tester's start date and who will sign the authorization. We reply with scope and a fixed price.
Usually, yes. In a black-box test the result depends on what reconnaissance finds, and a separate OSINT penetration testing phase gives you a validated target list, an out-of-scope list and a second view of your estate to compare with the tester's. If your vendor's own recon is strong, you can share our pack after the test instead to see what each side missed.
Not without the provider's permission. Your authorization covers what you own or control; a SaaS application on your subdomain belongs to the provider, whose own testing policy applies. We list it in the out-of-scope pack with the reason. Report any concern to the provider, or ask them whether they allow customer testing and under what conditions.
Possibly, but check with your test manager first. The DORA standard requires a threat intelligence provider to deliver a targeted threat intelligence report with scenarios for each critical or important function, and formal provider requirements apply. Our reconnaissance can support that work, for example on your external exposure, but the role has to be agreed with your control team and the provider before scoping.
Only if your rules of engagement allow it and through the channel they specify. We match leaked credentials to current staff and report them, but we never try them ourselves. Many organizations prefer to reset affected accounts immediately and let the tester simulate the access instead. The decision belongs to whoever signed the authorization, and we follow it in writing.
Book at least three weeks ahead for a focused test, more for a large group. We need the signed authorization, the domains, brands and business units in scope, known exclusions, the tester's start date and a contact for urgent findings. Recon itself takes from 10 business days; urgent delivery is available for an extra 50%.
Sources checked 10 October 2026. Figures about third-party firms and tools are as published by them or by the cited source on that date.