What problem does it solve?
Reconnaissance and testing planning often waste time with ad-hoc enumeration and inconsistent coverage, causing teams to miss high-impact bugs on new targets.
Core Features & Use Cases
- Structured recon workflow: builds a repeatable hierarchy from scope definition through asset discovery, tech fingerprinting, and endpoint mapping.
- Target discovery and validation: supports passive/active subdomain enumeration, port/service discovery, and HTTP probing to identify what is actually reachable.
- Methodical bug hunting mindset: emphasizes systematic coverage (what to test, in what order, and why), plus program triage to focus on features most likely to yield findings.
- Quick testing accelerators: guides use of common tooling for directory/parameter discovery and nuclei-based triage for misconfigurations and exposures.
Quick Start
Use recon-and-methodology to systematically enumerate subdomains, fingerprint technologies, discover endpoints and parameters, then prioritize testing based on likely bug paths for your chosen bug bounty program.