> For the complete documentation index, see [llms.txt](https://bugrecon.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://bugrecon.gitbook.io/docs/introduction.md).

# Introduction

## What is BugRecon?

**BugRecon** is a web-based security reconnaissance platform designed for bug bounty hunters, penetration testers security researchers and any other security professionals. It helps you discover all the subdomains of your target, probe services, collect publicly available URLs, run vulnerability scans, take screenshots, and receive notifications - all from a single web interface.

The application is built around **projects** and **scopes**: you organize your targets in projects, then create one or more scopes per project. Each scope starts from a list of domains (entered manually, imported from a file or from your preferred bug bounty platform). From a scope you run scan types (subdomain discovery, port scanning, HTTP probing, vulnerability scanning, and other modules) to enrich it.

![Login page](https://1075470145-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FV2n4UTcrS4SHhY2NTi0v%2Fuploads%2Fgit-blob-d605f436b2312fcf41ff6c24c58e57707b0c6d1e%2Flogin.png?alt=media)

## Key features

* **All bug bounty scopes in one place** - Import or sync domains from multiple programs; manage projects and scopes from a single interface.
* **Real-time recon** - Certificate Transparency monitoring (CertStream) and live scan results so you see discoveries as they happen.
* **Free tier** - Get started with port, HTTP, vulnerability, basic auth, takeover, and screenshot scans at no cost.
* **Search across all scope domains in seconds** - Global search by subdomain, IP, port, technology, status code, or URL; advanced filters and statistics.
* **Spray testing across all scopes in seconds** - Run HTTPX or Nuclei across multiple scopes in one run, with real-time results and export.

## Main concepts

* **Project** - A container for a bug bounty program or your company scope. It has a name, optional description, and can hold multiple scopes and notes.
* **Scope** - A reconnaissance target you create from a project: a list of domains (and later subdomains). From the scope detail page you run scan types (subdomain, port, HTTP, vulnerability, etc.) to enrich it with results.
* **Quota** - Your subscription plan defines how many scans you can run per period (e.g. per month) and, for Basic/Premium/Enterprise, how many domains you can monitor via CertStream.
* **API Keys** - Optional credentials for external services (e.g. subdomain enumeration sources, Discord notifications). Stored securely and used by the backend when running scans or sending alerts to fit your needs.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://bugrecon.gitbook.io/docs/introduction.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
