top of page

Scope Discovery for Web Pentests: WHOIS, ASN, and Certificates

4 hours ago
2 min read

Scope discovery is where web pentests start before Burp opens. WHOIS and ASN data tell you who owns what; certificates tell you what exists even when DNS is quiet.


It's not glamorous—it's how you avoid testing your client's neighbor by typo.

Scope Discovery for Web Pentests: WHOIS, ASN, and Certificates

Passive scope discovery saves political capital: you walk into kickoff with educated questions instead of spraying traffic at neighbor netblocks. Clients remember the tester who asked before scanning.



WHOIS and registrant intel


Registrant orgs, name servers, and historical changes hint at acquisitions and shadow IT. Treat WHOIS privacy as a signal to dig elsewhere.



ASN mapping


Which netblocks belong to the org vs CDN vs cloud shared space. Helps separate in-scope IPs from provider infrastructure.


  • Cross-reference with client documentation

  • Note geolocation and any regulatory constraints



Certificate transparency


CT logs surface hostnames before you brute force. Watch for dev domains leaking production naming schemes.


Discovery output feeds scope conversations—confirm before testing new ranges.


Passive intel gathering still needs contractual permission on some engagements.


Send a short passive intel summary to the client before active testing; surprises during scanning erode trust faster than findings themselves.


Small habits compound—what feels like overhead early becomes speed when deadlines hit.


When WHOIS is private, lean on client intros instead of guessing ownership.



Acquisition drift


Recent M&A shows up in CT logs before org charts update—flag new names to the client early.


Document assumptions when WHOIS privacy hides ownership—you may need confirmation.



Client validation loop


Send preliminary asset lists for client sign-off before active probing—political safety matters.


Highlight cloud shared IP ranges that confuse ownership—ask which tenant is theirs.


Certificate org fields sometimes lag rebrands; don't argue without confirmation.




Worth reading next


Recon Series: Subdomain Enumeration


Web App Reconnaissance: The Advantage Layer


OSINT and Google Dorking for Authorized Web Testing

Comments


© 2022 by SapiensHack.com (Security)

bottom of page