Recon · by toolbox chromos

See your outside view
before attackers do.

A fixed-price external assessment that shows exactly what's publicly visible about your business — domains, email posture, exposed services, and Microsoft 365 identity signals — then turns it into an executive-ready report with a clear list of what to fix first.

$2,500
Fixed-price snapshot
72h
Scope to report
0
Credentials required
15–20
Page PDF report
How Recon works

Four steps. No access required.

01 / SCOPE

Scope your domain

You hand us one thing: your domain. No accounts, no installs, no internal access. We confirm scope in a one-page agreement and get to work.

02 / RECON

Run external recon

We map your public footprint from the outside — subdomains, services, email and DNS posture, Microsoft 365 identity signals, and your historical web footprint.

03 / RANK

Rank what actually matters

Findings are rated by real business impact, not scanner severity — so the list reflects your actual risk.

04 / DELIVER

Get the report and fix first

You get the PDF, the readout call, and a prioritized list your team or MSP can start on immediately.

Packages

Fixed scope. Fixed price.

No hourly billing, no open-ended engagement. Pick the depth that fits.

Deep Dive
$5,000
Everything in Snapshot, extended across subsidiaries, acquisitions, and historical infrastructure.
  • Everything in Snapshot
  • Multiple domains & subsidiaries
  • Historical infrastructure review
  • Certificate transparency analysis
  • Expanded OSINT artifacts
  • Extended readout & Q&A
Request Deep Dive
Monitoring
$1,500/mo
Continuous external monitoring so new exposure is caught when it appears, not a year later.
  • Continuous surface monitoring
  • Change alerts as exposure appears
  • Monthly delta report
  • Quarterly review call
  • Priority response window
Request Monitoring
The deliverable

What's in the report.

The output is a clean PDF and a readout call — written so a managing partner, owner, or administrator can understand the risk and the plan without a security background.

01

Executive summary

The whole picture in one page — risk posture and priorities, plain English.

02

External attack surface

Every host, service, and port we could reach from the outside, with exposure ratings.

03

Email & DNS hygiene

SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI, DNS records, and certificate transparency.

04

Microsoft 365 posture

Tenant identification, federation, and the identity signals visible without credentials.

05

Ranked findings

Each finding with severity, evidence, business impact, and a specific fix.

06

Domain intelligence & history

Registration details, public footprint, and the historical record still indexed today — plus methodology and scope.

Straight answers

What buyers ask before they email.

What do you need from us?

One thing: your domain. No credentials, no agents, no installs. Scope is confirmed in a one-page agreement before any work starts.

Will this disrupt anything?

No. Recon is passive — built on publicly visible infrastructure and open-source evidence. We never touch your internal systems, so there's nothing to install and nothing to explain to your compliance team.

Is this a penetration test?

No. Recon maps what's publicly visible and ranks it by business impact — it doesn't attempt exploitation. It's the baseline that tells you whether deeper testing is even the right next spend.

How long does it take?

Most Snapshots are delivered within about 72 hours of scoping.

Who reads the report?

It's written for a managing partner, owner, or administrator — no security background required. Your team or MSP gets a prioritized fix list they can act on immediately.

Who is Recon built for?

50–500 person organizations on Microsoft 365 without an internal security team — the firms enterprise ASM platforms price out and ignore.

Ready to see your outside view?

Send your domain and we'll scope a Recon review. Most snapshots are delivered within 72 hours — no logins, no agents, no long contract.