> For the complete documentation index, see [llms.txt](https://bugrecon.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://bugrecon.gitbook.io/docs/step-by-step-guides.md).

# Step-by-step guides

This section walks you through the main user actions: creating a project, creating a scope, and running your first port scan (and related scans). All steps assume you are logged in.

***

## Create a project

1. In the navbar, click **Projects**.
2. Click **New Project**.
3. Fill in:
   * **Project Name** (required): e.g. "Acme Corp Bug Bounty".
   * **Description** (optional): e.g. scope URL or short note.
4. Click **New Project**.
5. You are redirected to the project detail page.

***

## Create a scope

1. Open the **Project** you want to add a scope to (from **Projects** or **Dashboard**).
2. On the project detail page, find the **Create scope** / **Import domains** section.
3. Choose how to provide domains:
   * **Manual:** Type or paste domains in the text area (one per line).
   * **File:** Upload a file; its contents are read as one domain per line.
4. Enter or paste your domains (e.g. `example.com`, `api.example.com`). Empty lines are ignored.
5. Click the button to **create** or **import** the scope.
6. After creation, you are redirected to the **Scope detail** page for the new scope. The scope starts in a state like "not-started" until you run a scan type (e.g. subdomain or port).

***

## Run your first port scan

1. **Create a project and a scope** (see above) so you have at least one scope with domains.
2. Open the **Scope detail** page for that scope.
3. Ensure the scope has **subdomains** to scan. If you only imported root domains (e.g. `example.com`), you can:
   * Run a **Subdomain scan** first (Premium and above) to discover subdomains, or
   * Use the imported list as-is; some scan types (e.g. port scan) can run on the current list.
4. In the **Port scan** section:
   * Optionally set the port list (e.g. `80,443,8080,8443`) or use the default from Settings.
   * Choose **Simple** or **Version** scan type.
5. Select the subdomains (or all) you want to run the port scan on. You may have a "Select all" or per-subdomain checkbox.
6. Click **Run Port Scan**.
7. You can stay on the page to see status and results in real time.
8. When the port scan completes, results appear in the **Port scan** section of the scope.

***

## Run a subdomain scan (Basic/Premium)

1. Open the **Scope detail** page for a scope that has at least one root domain (e.g. `example.com`).
2. In the **Subdomain scan** section, choose options (e.g. passive, active, AI-powered).
3. Click **Run Subdomain Scan**.
4. After the job runs, the scope's subdomain list is updated. You can then run other scan types (port, HTTP, etc.) on the discovered subdomains.

*Subdomain enumeration can use API keys you configured under **API Keys** (e.g. Shodan, VirusTotal) for better coverage.*

***

## Run an HTTP scan

1. On **Scope detail**, ensure you have subdomains (from import or subdomain scan).
2. In the **HTTP scan** section, set HTTP ports if needed (default often includes 80, 443, 8080, 8443).
3. Select subdomains (or all).
4. Click **Run HTTP Scan**.
5. When finished, HTTP results (status, title, tech, etc.) appear per subdomain.

***

## Run a vulnerability scan

1. On **Scope detail**, open the **Vulnerability scan** (or Nuclei) section.
2. Select template categories or "ALL" (or the options provided).
3. Select the subdomains to scan.
4. Click **Run Vulns Scan** (or equivalent).
5. Results appear in the vulns section; you can filter and open findings.

***

## Add and use API keys

1. Click your **profile** in the navbar → **API Keys**.
2. Expand a category (e.g. **Notification Services** for Discord, or **Subdomain enumeration keys** for Shodan, VirusTotal, etc.).
3. For a service, enter the required fields (e.g. Webhook URL for Discord, API Key for Shodan).
4. Click **Save** (or **Update** if already set).

Details: [API Keys](/docs/features-list/api-keys.md).

***

## Use Spraying (multi-scope HTTPX/Nuclei)

1. Go to **Modules** → **Spraying**.
2. Search or filter and **select one or more scopes**.
3. Choose **HTTPX** or **Nuclei**.
4. For HTTPX: pick a template or set options. For Nuclei: write or paste a YAML template.
5. Click **Run**.
6. Monitor progress and results.

***

## Create a scheduled task

1. Go to **Modules** → **Tasks**.
2. Click **New Task**.
3. Set **Name** and optional description.
4. Choose **Type** (e.g. Port scan, HTTP scan, Subdomain scan - subject to plan).
5. Choose **Trigger:** Interval, Cron, or Date.
6. Set **Target:** project, scope, and subdomains (or all).
7. Configure any type-specific options (ports, templates, etc.).
8. Save. The task appears in the list with next run time; you can delete it later if needed.

*Free users cannot create tasks of type subdomain, JavaScript, leaks, or URL; integration sync (YesWeHack, HackerOne, Bugcrowd, Intigriti) is Premium only.*

***

## Add a domain to CertStream (Basic/Premium)

1. Go to **Modules** → **CertStream**.
2. Click **Add Domain** (or equivalent).
3. Enter the domain to monitor (e.g. `*.example.com` or `example.com`).
4. Save. The domain appears in the monitored list and detections will show when new certificates are seen.
5. Optionally use **Add All Domains** to add wildcard domains from your scopes in bulk.

*Respects CertStream quota (e.g. 15 for Basic, unlimited for Premium).*


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://bugrecon.gitbook.io/docs/step-by-step-guides.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
