# Recon Wave > Recon Wave is a European external attack surface management (EASM) platform. It automatically discovers and continuously monitors an organization's internet-facing infrastructure, including domains, subdomains, IP addresses, servers, ports, applications, technologies, vulnerabilities, and misconfigurations. It works from the public internet without agents, credentials, or internal network access. Recon Wave is built for cybersecurity teams, CISOs, CTOs, security leaders, cybersecurity engineers, and penetration testers who need a current, independent view of what their organization exposes externally. The platform is developed and operated by Defense Ventures s.r.o. in Czechia, and customer data is hosted in the European Union. ## What Recon Wave does - Starts with an organization's legal name and uses public company registries and ownership records to map subsidiaries, acquisitions, branches, and trading names. - Correlates those entities with domains, subdomains, IP addresses, netblocks, applications, and externally visible technologies. - Fingerprints technologies and flags potential CVE matches for validation, with CVSS severity, EPSS exploitation likelihood, and affected-asset context. A technology match does not confirm an exploitable vulnerability. - Continuously records DNS, IP, application, port, and certificate changes in a searchable event log. - Scans every public IP address in scope across all 65,536 TCP ports to identify exposed services and newly opened ports. - Applies custom or recommended policies to discovered assets and alerts teams when exposure violates their requirements. - Maps third-party DNS dependencies and detects risks such as dangling CNAME records that may enable subdomain takeover. - Feeds new findings back into discovery so each pass can reveal additional related infrastructure. ## Benefits and differentiators - Organization-first discovery: Recon Wave can begin with a legal entity rather than requiring a complete asset inventory or list of seed domains. - Agentless outside-in visibility: deployment does not require software installation, credentials, configuration, or internal access. - Continuous, independent inventory: security teams can see infrastructure and changes across subsidiaries and hosting providers from an external attacker's perspective. - Discovery-to-action workflow: asset discovery, monitoring, vulnerability context, port scanning, policies, alerts, and investigation are available in one platform. - Actionable context: findings link risks and changes back to the affected domains, IP addresses, applications, and technologies. - Predictable commercial model: pricing is fixed for the contract term, is not billed per discovered asset, and includes all platform features, subject to the fair use policy. - European operation: the product is developed and operated from Czechia, with customer data hosted in the European Union. - Large passive DNS dataset: Recon Wave Search gives security teams and researchers direct access to more than 10 billion DNS records. ## Product and company pages - [Homepage](https://reconwave.com/): Product overview, discovery workflow, monitoring capabilities, customer proof, and demo call to action. - [How it works](https://reconwave.com/how-it-works): Step-by-step walkthrough of the discovery engine, from legal entity to subsidiaries, domains, IP addresses, ports, technologies, and alerts. - [Platform features](https://reconwave.com/features): Overview of the Recon Wave platform and its core capabilities. - [Pricing](https://reconwave.com/pricing): Fixed-contract pricing principles, demo and trial process, fair use policy, and included capabilities. - [Customers](https://reconwave.com/customers): Public customer references, usage context, and platform scale indicators. - [Company](https://reconwave.com/about): Mission, team, company background, European hosting, and legal entity information. - [Contact](https://reconwave.com/contact): Request a demo or contact the Recon Wave team. ## Platform capabilities - [Asset Discovery](https://reconwave.com/feature/asset-discovery): Discover domains, subdomains, IP addresses, applications, technologies, DNS records, TLS status, ownership, and related infrastructure. - [Vulnerability Management](https://reconwave.com/feature/vulnerability-management): Flag potential CVE matches from externally visible technologies and prioritize validation with CVSS, EPSS, and affected-asset context. - [Continuous Monitoring](https://reconwave.com/feature/continuous-monitoring): Record and investigate DNS, IP, application, port, and certificate changes through a searchable event log. - [Policies & Alerting](https://reconwave.com/feature/policies-alerting): Define acceptable external exposure and surface policy violations across monitored assets. - [Third-Party Risk](https://reconwave.com/feature/third-party-risk): Map external DNS dependencies and identify dangling CNAMEs and other dependencies outside the organization's control. - [Port Scanning](https://reconwave.com/feature/port-scanning): Continuously scan all 65,536 TCP ports across public IP addresses to find exposed services and unexpected openings. ## Customer evidence - [Seznam.cz customer story](https://reconwave.com/customers/seznam): Continuous visibility, change notifications, custom policy enforcement, and penetration-testing inventory across a large internet perimeter. - [SatoshiLabs customer story](https://reconwave.com/customers/satoshilabs): Autonomous external monitoring across the infrastructure behind Trezor, Invity, Tropic Square, and Vexl. - [Mild Blue customer story](https://reconwave.com/customers/mild-blue): External infrastructure monitoring for a healthcare technology company serving hospitals and laboratories. - [Stratosphere Laboratory customer story](https://reconwave.com/customers/stratosphere): Timely infrastructure visibility for a cybersecurity and AI research group. ## Data and scanning transparency Recon Wave Platform provides ongoing discovery, monitoring, policies, and alerts for an organization's external attack surface. Recon Wave Search is a separate DNS investigation interface; access to DNS records should not be confused with platform monitoring coverage. Public pricing describes the commercial model; it does not publish a numeric subscription price. - [Recon Wave Search](https://search.reconwave.com/about): Search and investigate Recon Wave's passive DNS dataset, including subdomains, reverse DNS relationships, and historical records. - [Recon Wave Bot](https://reconwave.com/bot): How authorized security assessments, internet-wide telemetry, scanner identification, and scan opt-out requests work. - [Security contact](https://reconwave.com/.well-known/security.txt): Security disclosure contact and policy. ## Research and insights - [Blog](https://reconwave.com/blog): Security research, product updates, and practical external attack surface management insights. - [Global DNS State, part 2 - DNS Centralization](https://reconwave.com/blog/post/dns-centralization): Analysis of DNS provider concentration using 320 million root domains. - [Global DNS State, part 1 - The Alarming Prevalence of Zone Transfers](https://reconwave.com/blog/post/alarming-prevalence-of-zone-transfers): Research into publicly enabled DNS zone transfers. - [Storing RSA private keys in DNS TXT records?](https://reconwave.com/blog/post/storing-private-keys-in-txt-dns): Investigation of private-key material found in public DNS records. - [Announcing Recon Wave Search](https://reconwave.com/blog/post/announcing-recon-wave-search): Background on the passive DNS search product and supported query types. - [Enumerating DNS zones using NSEC](https://reconwave.com/blog/post/enumerating-dns-zones-using-nsec): A practical explanation of DNS zone enumeration with NSEC records. ## Legal - [Privacy Policy](https://reconwave.com/legal/privacy-policy): Privacy and personal-data processing information. - [Terms of Service](https://reconwave.com/legal/terms-of-service): Terms governing use of the Recon Wave platform. ## Contact - General and sales inquiries: hello@reconwave.com - Scanning opt-out requests: bot-opt-out@reconwave.com