The Modern Web Recon Workflow: From Seed to Shell

The Modern Web Recon Workflow: From Seed to Shell
Most junior bug bounty hunters start their careers entirely backwards. They grab a massive wildcard scope on HackerOne, immediately fire off a noisy vulnerability scanner against the main www subdomain, get blocked by Cloudflare within four minutes, and then complain on X (formerly Twitter) about finding duplicates.
If you want to actually find P1s and P2s consistently, you have to build a systematic, repeatable reconnaissance pipeline. The goal is simple: find the hidden, forgotten infrastructure that other researchers missed.
A modern reconnaissance pipeline flows sequentially: Subdomain Discovery -> DNS Resolution -> Active Probing -> Targeted Scanning.
The Rules of Engagement
Before we touch a terminal, we define the scope. Your methodology means nothing if it gets you banned from a platform for throwing untargeted payloads at out-of-scope assets. We always limit our scans to explicitly authorized domains. If the brief says *.example.com, you do not touch example-staging.com unless the rules allow root domain discovery.
Everything discussed here assumes you are operating strictly within an authorized bug bounty program or a contracted penetration test.
Stage 1: Passive Subdomain Discovery
We start completely passive. We do not want to interact with the target's servers yet. We want to ask third-party services what they know about the target. We use subfinder to scrape public data sources like Censys and Shodan. For a deep dive into subfinder configuration, check out our Subfinder Masterclass.
Cybersecurity enthusiast focused on ethical hacking, penetration testing, bug bounty hunting, and security education. Founder of CyberBlockz, sharing practical cybersecurity knowledge, CTF challenges, and hands-on training to help learners develop real-world security skills and stay updated with the latest threats and vulnerabilities.



Piping live hosts from httpx directly into a targeted vulnerability scanner.
An automated EASM pipeline triggers notifications in Slack or Discord the second a new subdomain comes online.