> ## Documentation Index
> Fetch the complete documentation index at: https://docs.jsmon.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# Reconnaissance

> Explore discovered assets across 20+ categories

The Reconnaissance section provides a comprehensive view of all assets and data discovered during your scans. Jsmon automatically categorizes findings into over 20 distinct categories, making it easy to explore and analyze your target's attack surface.

## Layout

The Reconnaissance page uses a two-panel layout:

* **Left Panel** — A list of all categories with item counts for each
* **Right Panel** — The data for the currently selected category, with search, filtering, and export options

## Categories

Jsmon organizes reconnaissance data into the following categories:

| Category | Description |
| - | - |
| **API Paths** | Discovered API endpoints and routes |
| **Headers** | HTTP response headers collected during scanning |
| **URLs** | All URLs discovered during the crawl |
| **Domains** | Subdomains and related domains found |
| **AWS Assets** | Amazon Web Services resources (S3 buckets, CloudFront distributions, etc.) |
| **IP Addresses** | IP addresses associated with the target |
| **Emails** | Email addresses found in the target's assets |
| **S3 Bucket Takeovers** | S3 buckets vulnerable to subdomain takeover |
| **GQL Queries** | GraphQL query operations discovered |
| **GQL Mutations** | GraphQL mutation operations discovered |
| **GQL Fragments** | GraphQL fragment definitions found |
| **Parameters** | URL and form parameters identified |
| **Node Modules** | JavaScript packages and dependencies detected |
| **NPM Confusion** | Packages potentially vulnerable to dependency confusion attacks |
| **GUIDs** | Globally Unique Identifiers found in assets |
| **Vulnerabilities** | Security vulnerabilities identified during scanning |
| **Localhost** | References to localhost or internal addresses |
| **Expired Domains** | Domains with expired registrations (potential takeover targets) |
| **Social Media URLs** | Links to social media profiles and pages |
| **Filtered Port URLs** | URLs with non-standard ports |
| **File Extension URLs** | URLs organized by file extension type |

## Working with Reconnaissance Data

For each category, you can:

* **Search** — Use the search bar to filter results within the selected category
* **Filter by File Type** — Narrow results by specific file types
* **Export** — Download the data for offline analysis or reporting

Reconnaissance data is collected automatically during domain scans and is retained within the workspace for future reference. Each scan adds to the existing reconnaissance data, building a comprehensive picture of your target over time.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.