October 10, 2026
How to Map an Organization’s IP Ranges Using ASNMap and MapCIDR | by Samadhan Shimple
When I start a bug bounty program or an authorized penetration test, one of the first things I want to understand is the target’s…

By Samadhan shimple
7 min read
When I start a bug bounty program or an authorized penetration test, one of the first things I want to understand is the target's internet-facing infrastructure.
A domain name is only one small part of the picture. An organization may operate multiple IP ranges, use different Autonomous System Numbers (ASNs), and host services across several networks. Understanding this infrastructure can help security researchers build a better picture of the target's potential attack surface.
This is where two useful ProjectDiscovery tools come in: ASNMap and MapCIDR.
ASNMap helps identify IP ranges associated with an organization, while MapCIDR can expand those ranges into individual IP addresses and perform other CIDR-related operations.
In this guide, I'll walk through how both tools work, how to install them, and how to combine them into a practical reconnaissance workflow.
Note: These tools help identify and process network ranges, but they cannot guarantee a complete list of every IP address an organization owns or uses.
What Are ASNMap and MapCIDR?
Before getting into the commands, let's understand what each tool does.
1. ASNMap: Finding an Organization's IP Ranges
ASNMap is a command-line tool developed by ProjectDiscovery. It helps researchers find network ranges associated with domains, IP addresses, ASNs, and organization names.
An Autonomous System Number (ASN) identifies a network or group of networks managed under a common routing policy.
For example, a large technology company may announce multiple IP prefixes through one or more ASNs. By looking up this information, we can discover network ranges associated with that company.
ASNMap supports several types of lookups:
- Domain-based lookups
- ASN-to-CIDR lookups
- IP-to-network lookups
- Organization-name lookups
- Text, JSON, and CSV output options
- File input and command-line pipeline integration
The goal is simple: instead of manually searching different network databases, we can use ASNMap to collect relevant network information more efficiently.
2. MapCIDR: Converting Network Ranges into IP Addresses
Once we have a list of CIDR ranges, the next question is how to work with them.
That is where MapCIDR becomes useful.
CIDR stands for Classless Inter-Domain Routing. It is a notation used to represent an IP network.
For example:
192.168.1.0/24
This represents 256 IPv4 addresses, from 192.168.1.0 to 192.168.1.255.
MapCIDR can expand a CIDR range into individual IP addresses. It can also split ranges into smaller subnets, aggregate ranges, filter addresses, and perform other network-related operations.
In short:
- ASNMap finds the network ranges.
- MapCIDR processes those ranges into a format you can use.
Let's put them to work.
Step 1: Install ASNMap
ASNMap is written in Go, so you will need a compatible Go installation.
You can install it using:
go install github.com/projectdiscovery/asnmap/cmd/asnmap@latestgo install github.com/projectdiscovery/asnmap/cmd/asnmap@latestMake sure your Go binary directory is included in your system's PATH. You can then check whether the tool is available:
asnmap -hasnmap -hDepending on your installed version and configuration, ASNMap may require an API key from the ProjectDiscovery Cloud Platform.
export PDCP_API_KEY="YOUR_API_KEY"export PDCP_API_KEY="YOUR_API_KEY"Replace the placeholder with your own key. Avoid publishing API keys in screenshots, blog posts, or public repositories.
Step 2: Find CIDR Ranges from a Domain
Let's start with a simple example.
asnmap -d example.comasnmap -d example.comThis asks ASNMap to look up network information associated with the domain.
You can also use a real organization domain, provided your research is consistent with your authorized testing scope.
For cleaner output, which is especially useful when chaining commands, use:
asnmap -d example.com -silentasnmap -d example.com -silentThe result may contain network prefixes associated with the domain's ASN information.
One important detail: a domain lookup does not necessarily reveal every network an organization owns. A domain may point to a CDN, a cloud provider, or third-party infrastructure. Some corporate networks may also be associated with different ASNs or organization names.
For a more complete picture, it is worth comparing domain-based results with other available network records.
Step 3: Look Up an ASN Directly
If you already know the organization's ASN, you can query it directly.
For example:
asnmap -a AS15169asnmap -a AS15169This requests network information associated with AS15169, Google's well-known ASN.
You can also look up network information associated with an IP address:
asnmap -i 8.8.8.8asnmap -i 8.8.8.8Or search by an organization name:
asnmap -org "Google LLC"asnmap -org "Google LLC"The organization-name lookup can be useful when a company operates multiple networks or uses different ASNs.
However, organization names in network registration data are not always consistent. It is a good idea to verify results instead of assuming every matching record belongs to the same company.
Step 4: Save and Organize the Results
When performing reconnaissance, saving results makes it easier to review and reuse them later.
To save CIDR output to a file:
asnmap -d example.com -o cidr_ranges.txtasnmap -d example.com -o cidr_ranges.txtFor structured output, you can use the JSON option supported by your installed version:
asnmap -d example.com -jsonasnmap -d example.com -jsonCSV output may also be available:
asnmap -d example.com -csvasnmap -d example.com -csvCheck asnmap -h if a flag behaves differently in your installed release.
Structured output is especially helpful when building automation scripts because network prefixes and their associated metadata can be processed programmatically.
At this point, we have a list of candidate network ranges. The next step is to process them with MapCIDR.
Step 5: Install MapCIDR
Install MapCIDR with Go:
go install -v github.com/projectdiscovery/mapcidr/cmd/mapcidr@latestgo install -v github.com/projectdiscovery/mapcidr/cmd/mapcidr@latestCheck that the installation worked:
mapcidr -hmapcidr -hMapCIDR supports CIDR expansion, subnet slicing, aggregation, filtering, sorting, and other operations. The exact options may vary by release, so consult the help output for your installed version.
Step 6: Expand CIDR Ranges into Individual IP Addresses
Imagine that your CIDR file contains this entry:
192.168.1.0/24192.168.1.0/24You can expand the range using:
mapcidr -cidr 192.168.1.0/24mapcidr -cidr 192.168.1.0/24The output lists the IP addresses represented by that range.
For a file containing multiple CIDR ranges, use:
mapcidr -cl cidr_ranges.txt -o ip_addresses.txtmapcidr -cl cidr_ranges.txt -o ip_addresses.txtThe -cl option accepts a list of CIDRs in supported versions of MapCIDR. Check mapcidr -h to confirm the input flags available in your release.
Another option is to provide a CIDR file through the tool's supported file-input option:
mapcidr -cidr cidr_ranges.txt -o ip_addresses.txtmapcidr -cidr cidr_ranges.txt -o ip_addresses.txtUse the form supported by your installed version.
A practical warning: expanding a large network can generate millions of IP addresses and consume substantial disk space. Before expanding a range, calculate its size and make sure you actually need every address.
For example, an IPv4 /16 contains 65,536 addresses, while a /8 contains 16,777,216. Start with smaller, authorized ranges while learning the workflow.
Step 7: Useful MapCIDR Operations
MapCIDR can do more than expand ranges. Here are a few useful examples.
Count the addresses
To calculate how many addresses are represented by a CIDR:
mapcidr -cidr 192.168.1.0/24 -countmapcidr -cidr 192.168.1.0/24 -countThis helps estimate the size of the input before generating a large output file.
Split a CIDR into smaller subnets
You can split a network into a specified number of smaller CIDRs using the subnet-count option:
mapcidr -cidr 192.168.0.0/24 -sbc 10mapcidr -cidr 192.168.0.0/24 -sbc 10The exact behavior and resulting subnet sizes depend on the tool's implementation and options.
Aggregate network ranges
If you have multiple CIDRs that can be represented by a smaller set of covering ranges, aggregation can help simplify the list.
For example:
mapcidr -cl cidr_ranges.txt -aggregatemapcidr -cl cidr_ranges.txt -aggregateUse aggregation carefully. A summarized range may include addresses outside the exact set of original networks if the ranges are not perfectly aligned. For security testing, do not treat an aggregated range as authorized merely because it covers authorized addresses.
Filter IPv4 or IPv6 addresses
MapCIDR also provides address-family filtering options in supported versions:
mapcidr -cidr cidr_ranges.txt -f4mapcidr -cidr cidr_ranges.txt -f4For IPv6:
mapcidr -cidr cidr_ranges.txt -f6mapcidr -cidr cidr_ranges.txt -f6Refer to the installed tool's help output if the available flags differ.
Step 8: Combine ASNMap and MapCIDR
Now we can combine both tools into one workflow.
First, collect candidate CIDR ranges:
asnmap -d example.com -silent > cidr_ranges.txtasnmap -d example.com -silent > cidr_ranges.txtNext, expand those ranges into individual IP addresses:
mapcidr -cidr cidr_ranges.txt -o ip_addresses.txtmapcidr -cidr cidr_ranges.txt -o ip_addresses.txtYou now have two files:
cidr_ranges.txt— the network ranges returned by ASNMap.ip_addresses.txt— the individual addresses generated from those ranges.
This separation is useful because you can review the original network data before processing it.
The one-line version
If you want to combine the operations in a single command, you can use a pipeline:
asnmap -d example.com -silent | mapcidr -silentasnmap -d example.com -silent | mapcidr -silentTo save the results:
asnmap -d example.com -silent | mapcidr -silent > ip_addresses.txtasnmap -d example.com -silent | mapcidr -silent > ip_addresses.txtThe first tool supplies the network ranges, and the second processes them into individual addresses.
Before running this against a large organization, review the number and size of the returned CIDRs. A short command can still produce a very large output.
Step 9: Use the Results in an Authorized Reconnaissance Workflow
Once you have a candidate IP list, you may want to identify which systems respond to network or HTTP probes.
ProjectDiscovery provides additional tools for these tasks, including Naabu and httpx.
For example, to perform a limited port check against an explicitly authorized set of IP addresses, you can use a small, approved target list:
naabu -list authorized_ips.txt -p 443naabu -list authorized_ips.txt -p 443To check HTTP services on approved targets:
httpx -list authorized_ips.txthttpx -list authorized_ips.txtThe appropriate options depend on the installed versions and your testing requirements.
I recommend starting with a small, confirmed scope rather than immediately scanning every address associated with a large company. A network range may belong to a cloud provider, CDN, hosting company, or another shared infrastructure operator.
The presence of an IP address in an ASN lookup is not, by itself, proof that you are authorized to test the service hosted there.
Best Practices I Follow
Here are a few things worth keeping in mind when using these tools.
1. Verify the results.
Treat ASNMap output as a starting point. Cross-check network ownership and routing information, especially when the organization has a complex infrastructure.
2. Understand the difference between ownership and usage.
A company can use cloud-hosted infrastructure without owning the underlying IP range. Likewise, a network registered to a large provider may host services for many unrelated customers.
3. Keep the original CIDR list.
Store the original ranges separately from expanded IP lists. This makes it easier to review the source data, identify mistakes, and repeat your workflow.
4. Be careful with large ranges.
Expanding every address in a large CIDR can create enormous files. Count addresses first and process only the ranges needed for your authorized research.
5. Use structured output when appropriate.
JSON or CSV can make it easier to organize results, compare network records, and integrate them into other scripts.
6. Respect the testing scope.
For bug bounty work, check the program's scope and rules before probing IP addresses. A domain listed as in scope does not automatically mean every IP address associated with the organization is in scope.
7. Keep credentials private.
Never expose API tokens in terminal screenshots, public repositories, or published tutorials.
Conclusion
Mapping an organization's network infrastructure can be an important part of security reconnaissance, but it helps to understand what each tool actually tells you.
ASNMap makes it easier to discover candidate network ranges using ASN, IP, domain, and organization information. MapCIDR then helps you expand and manipulate those ranges for further analysis.
The basic workflow is straightforward:
- Use ASNMap to collect network prefixes.
- Review and save the CIDR results.
- Use MapCIDR to expand or process the ranges.
- Verify ownership and scope before testing individual hosts.
- Use additional tools only against authorized targets.
The biggest lesson is that a list of IP addresses is not the same as a complete or verified attack surface.
For bug bounty hunters and penetration testers, ASNMap and MapCIDR are useful tools to add to a reconnaissance workflow as long as the results are interpreted carefully and testing remains within the agreed scope.
Disclaimer: This article is intended for educational purposes and authorized security research. Always obtain permission before scanning or testing systems, and follow the applicable bug bounty program rules and laws.
AI assistance:_ I used an AI-powered grammar and spelling checker to review this article. The ideas, research, technical analysis, and final content are my own._
Have questions or want to share your own workflow? Drop a comment below or connect with me on :
🔗Linkdin: https://www.linkedin.com/company/sam-shield/
🔗Youtube: https://www.youtube.com/@sam_shield-w7l
🔗Medium: https://medium.com/@samadhanshimple