Run scope-bounded reconnaissance for a penetration test: enumerate the authorized attack surface (hosts, domains, services, technologies, exposure) and organize it for testing. Use at the start of an engagement, strictly within the agreed scope.