Skip to main content

Logging and tracking recon data with CrowdRecon

This article explains how to log recon data with CrowdRecon and track the validation status of your recon logs.

Key takeaways:

  • Log domains, subdomains, other recon data and supporting context directly from an eligible program’s details page.

  • Review your logs and their status from the CrowdRecon page.

  • CrowdRecon currently focuses on processing domains and subdomains, while other recon types are captured for future phases.

  • A recon log is separate from a vulnerability submission.

Who this article is for: Researchers using CrowdRecon on the Intigriti platform.


What is recon data?

Recon data is information you discover while mapping and exploring an organisation’s external attack surface. Depending on the use case, this can include:

  • Domains and subdomains

  • Hostnames and IP addresses

  • URLs and endpoints

  • APIs

  • Cloud-hosted resources

  • DNS, certificate and email infrastructure

  • Other externally reachable assets or services

CrowdRecon currently focuses on domains and subdomains, together with contextual information such as how you found them, the methodology you used and why you believe they are relevant to the organisation. You can still log other types of recon data. We will capture this data and start processing additional recon types in future phases.

Logging recon data is not the same as creating a vulnerability submission. Use CrowdRecon to share what you discovered during reconnaissance. If you identify a vulnerability, report it separately through the program’s vulnerability reporting flow.

Log recon data

  1. Open the relevant program.

  2. On the program details page, select Log recon data.
    ​

  3. Paste or enter the recon data you discovered in the first field. CrowdRecon currently focuses on domains and subdomains, but you can also log other recon types.
    ​

  4. In the context field below your recon data, explain how you found it and why it may be relevant. You can include:

    • The methodology or tools you used

    • Why you believe the asset is connected to the organisation

    • How it relates to the organisation’s known attack surface

    • Why it may be security-relevant
      ​

  5. Continue to the review step.

  6. Read the legal notice and check your logs for sensitive information.

  7. Remove credentials, tokens, personal data or other sensitive information that should not be shared.

  8. Select Log recon data to finish.

💡 Note: Useful context makes it easier for the organisation to assess your recon logs.

What should I log?

Log recon data that helps the organisation understand its external attack surface and decide what to review, validate, add to its inventory or scope, investigate or follow up on.

Useful recon logs may include:

  • Live domains, subdomains and IP addresses

  • URLs, endpoints and APIs

  • Exposed services or ports, where permitted by the program rules

  • Staging, test, legacy, regional, partner, sponsor or co-branded environments

  • Technology fingerprints that help classify an asset

  • Relationships between domains, subdomains, IP addresses or services

  • Context explaining why an asset may be relevant, unexpected or worth reviewing

CrowdRecon currently focuses on processing domains and subdomains. Other recon types are still captured and will start being processed in future phases.

Add useful context

Use the context field to help the organisation and Intigriti understand why your recon data may matter. You can explain:

  • What the asset appears to be

  • How it may be related to the organisation, its brand, a subsidiary, partner or program scope

  • Why it seems new, unexpected, interesting or worth reviewing

  • What basic validation you performed, if any

  • How the logged assets relate to each other

  • Any uncertainty or suggested follow-up

You can provide high-level discovery context, but you do not need to reveal private or sensitive methodology. One or two concise sentences can make a recon log much easier to review.

Good logging practices

  • Filter before logging: Log useful results, not everything a tool returns.

  • Check that it is live: Where possible, check whether the asset resolves or responds before logging it.

  • Explain why it matters: Make the connection to the organisation and the potential next step clear.

  • Be transparent about uncertainty: If you are unsure whether an asset belongs to the organisation, explain why you think it may be related.

  • Respect the program rules: CrowdRecon does not extend your permission to test beyond the program’s scope, rate limits or safe-testing requirements.

  • Keep recon and vulnerabilities separate: Use recon logs for exposure and asset context. Use vulnerability reports for exploitable findings.

Avoid logging:

  • Raw, unfiltered scanner output

  • Assets that are clearly unrelated to the organisation

  • Known assets without any new or useful context

  • Non-live assets without an explanation

  • Speculative relationships without supporting context

  • Vulnerabilities disguised as recon logs

  • Credentials, secrets, personal data or other sensitive information

  • Anything obtained through unsafe, disruptive or out-of-scope testing

View your recon logs

  1. Open CrowdRecon from the main navigation. The recon logs view opens by default.

  2. Use the organisation filter to show recon logs for the relevant organisation.

The table shows recon logs associated with your account and the results of CrowdRecon’s basic technical checks.

Understand the table columns

Column

What it shows

Domain

The domain or IP address parsed from your recon log.

Company

The company whose program you used to log the recon data.

Validation status

Whether the company has reviewed the recon log: Not reviewed, Validated or Invalidated.

DNS

The number of IP addresses returned when the domain resolves. An X is shown when it does not resolve.

HTTP

The HTTP response code when the asset is reachable over HTTP. An X is shown when it is not reachable.

HTTPS

The HTTPS response code when the asset is reachable over HTTPS. An X is shown when it is not reachable.

💡 Note: DNS, HTTP and HTTPS results reflect automated technical checks. They help you understand whether an asset resolves or responds, but they do not determine whether the company will validate the recon log.

View more information about a recon log

Select a recon log in the table to open its side panel. The panel provides additional information about the selected log and lets you review its available contextual and technical details without leaving the table.

View the leaderboard

Open the Leaderboard view from the CrowdRecon page to see how your recon activity compares with that of other researchers.

The leaderboard shows researchers’ ranking and points based on eligible recon contributions. Points are intended to recognise useful and technically verifiable recon, not raw logging volume. Being the first researcher to log an asset and having that recon validated can contribute to your position.

Use the available filters to switch between the global leaderboard and rankings for a specific organisation. Reward and scoring rules may differ between CrowdRecon engagements, so always check the relevant program details.

💡 Note: Your leaderboard position and points can change as organisations review recon logs and as other researchers log recon data.

Recon log statuses

An organisation can review and validate your recon logs. You may see the following statuses:

Status

Meaning

Not reviewed

The organisation has not yet recorded a decision for the recon log.

Validated

The organisation reviewed and recognised the recon log as valid recon work.

Invalidated

The organisation reviewed the recon log but did not validate it as relevant recon work.

⚠️ Beware: A validated recon log is not automatically added to the program’s scope. Recon validation, asset inventory management and program scope are separate decisions.

Frequently asked questions

Is CrowdRecon replacing vulnerability reports?

No. Vulnerability reports remain the correct way to report security vulnerabilities. CrowdRecon is for useful reconnaissance data and context that can help an organisation understand its external attack surface before or between vulnerability reports.

Should I log a vulnerability as recon data?

No. If you identify a vulnerability, report it through the program’s normal vulnerability reporting flow. A recon log may provide useful asset or exposure context, but it does not replace a vulnerability report.

Can I log recon data other than domains and subdomains?

Yes. Although CrowdRecon currently focuses on processing domains and subdomains, you can log other recon types and add supporting context. This data will be captured and will start being processed in future phases.

What makes a useful recon log?

A useful recon log is relevant, technically verifiable and clear enough for the organisation to review or act on. It can help the organisation identify an unknown or unexpected asset, understand a relationship between assets, refine its inventory or scope, investigate an exposure or decide what to review next.

The goal is not to log as much raw data as possible. Filter your results and include concise context explaining why the recon may matter.

What does technically verifiable mean?

It means that the logged asset, endpoint, service or relationship can be checked. For example, a domain may resolve in DNS, an asset may respond over HTTP or HTTPS, or available evidence may show why the recon is meaningful.

CrowdRecon performs basic technical checks automatically. You do not need to reproduce those checks in detail, but performing a basic sanity check before logging helps keep your recon useful.

Can I log an asset that may already be known?

Yes. Known assets can still provide value when you add useful context. For example, you might identify an unexpected service, environment, relationship or reason the organisation may want to review it. Repeating an existing asset without adding useful information is less likely to be validated or rewarded.

Can I log output from automated tools?

Yes, but filter and review it first. Avoid logging raw scanner output. Check that the results are relevant, remove noise and add context that helps the organisation understand why they may matter.

Do I need to reveal my private methodology?

No. You can provide high-level discovery context where useful, but you do not need to disclose private or sensitive methodology. The priority is to give the organisation enough information to understand and review the recon data.

Can I test beyond the program scope?

No. CrowdRecon does not grant permission to test beyond the program rules. Always respect the defined scope, rate limits and safe-testing requirements.

What happens if another researcher logs the same asset first?

When an asset is not already declared by the organisation, the first researcher to log it may receive the related credit. A later log of the same asset is treated as a duplicate unless it adds meaningful new context. Exact credit and reward rules depend on the relevant CrowdRecon engagement.

Will every recon log be rewarded?

Not necessarily. Rewards depend on the model and validation rules described in the relevant program details. Factors may include technical validity, relevance, novelty, usefulness, duplicates and compliance with the program rules.

Who validates recon logs?

Validation is handled by the organisation and/or Intigriti, depending on the CrowdRecon engagement. Check the relevant program details for engagement-specific information.

Will CrowdRecon affect my vulnerability-report rewards?

No. CrowdRecon rewards are separate from normal vulnerability-report rewards unless the program details explicitly state otherwise.

How are leaderboard points calculated?

Points recognise useful recon contributions rather than raw logging volume. Depending on the engagement, scoring may consider whether you were the first researcher to log an asset, whether it passed technical checks and whether the organisation validated it. Refer to the relevant program details for the applicable scoring and reward rules.

Can I edit or delete a recon log?

Review your data carefully before logging it, especially for sensitive information. If you logged sensitive or incorrect information, contact Intigriti Support.

When will my recon log be reviewed?

Review times depend on the organisation. A Not reviewed status means that no validation decision has been recorded yet.

Did this answer your question?