Use only the Academy Lab on 127.0.0.1:5177. Do not copy these tests to a public system without explicit written authorization.
Write the scope first
List approved roots, excluded domains, IP ranges, ports, rate limits, and time window. Do not infer that a parent company domain authorizes every subsidiary or provider.
Run DNS and WHOIS
Query only the authorized domain. Record source, timestamp, resolver, registration data, and uncertainty. WHOIS privacy or missing fields are normal, not findings.
Find subdomains
Separate passive-source names from active DNS validation. Deduplicate, resolve, and keep wildcard-DNS controls. Never claim a localhost route is a public subdomain.
Scan approved ports
Use a narrow port list, low concurrency, and explicit IP scope. Confirm service banners before reporting exposure and stop when a provider or host falls outside authorization.
Document the Academy limitation
The downloadable lab teaches HTTP service mapping on loopback. DNS, WHOIS, passive subdomain, and external-port results require your own authorized test domain.
Prove it before moving on.
You can produce a source-attributed asset inventory without scanning any unapproved host.
