Recon is the foundation of every engagement. The quality of your enumeration directly determines the quality of your attack surface: missed open ports, forgotten vhosts, and unscanned directories are where flags and footholds hide.
Port Scanning
nmap techniques: full TCP, UDP, service detection, NSE scripts, and rate tuning
Web Enumeration
Directory and file brute force with ffuf/gobuster, extension sweeps, and API path discovery
Subdomain & DNS
Subdomain enumeration, DNS zone transfer, vhost fuzzing, and reverse DNS