> For the complete documentation index, see [llms.txt](https://h3ckt0r.gitbook.io/0xsec/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://h3ckt0r.gitbook.io/0xsec/elite/web_appsec/reconnaissance/scope.md).

# Scope

### **Small Scope**

Only Specific URLs are part of Scope. This usually includes staging/dev/testing or single URLs.

* [ ] &#x20;Directory Enumeration
* [ ] &#x20;Technology Fingerprinting
* [ ] &#x20;Port Scanning
* [ ] &#x20;Parameter Fuzzing
* [ ] &#x20;Wayback History
* [ ] &#x20;Known Vulnerabilities
* [ ] &#x20;Hardcoded Information in JavaScript
* [ ] &#x20;Domain Specific GitHub & Google Dorking
* [ ] &#x20;Broken Link Hijacking
* [ ] &#x20;Data Breach Analysis
* [ ] &#x20;Misconfigured Cloud Storage

### **Medium Scope**

Usually the scope is wild card scope where all the subdomains are part of scope

* [ ] &#x20;Subdomain Enumeration
* [ ] &#x20;Subdomain Takeover
* [ ] &#x20;Probing & Technology Fingerprinting
* [ ] &#x20;Port Scanning
* [ ] &#x20;Known Vulnerabilities
* [ ] &#x20;Template Based Scanning (Nuclei/Jeales)
* [ ] &#x20;Misconfigured Cloud Storage
* [ ] &#x20;Broken Link Hijacking
* [ ] &#x20;Directory Enumeration
* [ ] &#x20;Hardcoded Information in JavaScript
* [ ] &#x20;GitHub Reconnaissance
* [ ] &#x20;Google Dorking
* [ ] &#x20;Data Breach Analysis
* [ ] &#x20;Parameter Fuzzing
* [ ] &#x20;Internet Search Engine Discovery (Shodan, Censys, Spyse, etc.)
* [ ] &#x20;IP Range Enumeration (If in Scope)
* [ ] &#x20;Wayback History
* [ ] &#x20;Potential Pattern Extraction with GF and automating further for XSS, SSRF, etc.
* [ ] &#x20;Heartbleed Scanning
* [ ] &#x20;General Security Misconfiguration Scanning

### **Large Scope**

Everything related to the Organization is a part of Scope. This includes child companies, subdomains or any labelled asset owned by organization.

* [ ] &#x20;Tracking & Tracing every possible signatures of the Target Application (Often there might not be any history on Google related to a scope target, but you can still crawl it.) ​
* [ ] &#x20;Subsidiary & Acquisition Enumeration (Depth – Max)​
* [ ] &#x20;Reverse Lookup
* [ ] &#x20;ASN & IP Space Enumeration and Service Identification​
* [ ] &#x20;Subdomain Enumeration
* [ ] &#x20;Subdomain Takeover
* [ ] &#x20;Probing & Technology Fingerprinting
* [ ] &#x20;Port Scanning
* [ ] &#x20;Known Vulnerabilities
* [ ] &#x20;Template Based Scanning (Nuclei/Jeales)
* [ ] &#x20;Misconfigured Cloud Storage
* [ ] &#x20;Broken Link Hijacking
* [ ] &#x20;Directory Enumeration
* [ ] &#x20;Hardcoded Information in JavaScript
* [ ] &#x20;GitHub Reconnaissance
* [ ] &#x20;Google Dorking
* [ ] &#x20;Data Breach Analysis
* [ ] &#x20;Parameter Fuzzing
* [ ] &#x20;Internet Search Engine Discovery (Shodan, Censys, Spyse, etc.)
* [ ] &#x20;IP Range Enumeration (If in Scope)
* [ ] &#x20;Wayback History
* [ ] &#x20;Potential Pattern Extraction with GF and automating further for XSS, SSRF, etc.
* [ ] &#x20;Heartbleed Scanning
* [ ] &#x20;General Security Misconfiguration Scanning
* [ ] &#x20;And any possible Recon Vector (Network/Web) can be applied.​
