Randori recon

randori → recon target

Launches reconnaissance of a target with Randori (CrowdStrike's attack engine), discovering the external surface and validating SOC visibility.

Use it when you want validation from the external attacker's perspective: Randori (CrowdStrike's attack surface management platform) performs continuous reconnaissance of the target — exposed assets, services, applications — and measures the surface an attacker would see. In purple teaming, Randori's reconnaissance validates SOC visibility: what Randori discovers (an exposed service, a legacy app) is what the attacker would see — and what the SOC should be monitoring. The gap between the discovered and monitored surface is the finding.

Do not use it as an attack: Randori is reconnaissance and surface management — exploitation is validated with exercise tools. The platform is commercial (CrowdStrike): cost is the requirement; open source alternatives (surface scanners, Shodan) cover part of the terrain. And note: Randori's reconnaissance discovers what's exposed — interpretation (what is a real risk) is the team's; a discovered service is not necessarily a vulnerability. Visibility validation: what Randori discovers is searched in the SIEM (does the SOC monitor it?).