Reconnaissance
Subdomain enumeration
Subfinder
# List
subfinder -dL domains.txt -o subs.com
# domain
subfinder -d test.com -o subs.com Amass
# passive
└─$ amass enum --passive -norecursive -noalts -d example.com -o example.com.subs
# Lsit
└─$ amass enum --passive -norecursive -noalts -df domains.txt-o example.com.subs
# active
└─$ amass enum -src -ip -brute -min-for-recursive 2 -d example.com -o example.com.subsAssetfinder
SubEnum
TheHarvester
CRT
google dorking
unique subdomain
Subdomain Takeover
Subzy
dig
nslookup
Live subdomain
Httpx all thing about targets
Httpx 200 status code
httpx all ips and ports on host
Port Scanning
using Shodan
Endpoints
waybackurl
Katana
gospider
unique
Auto scan
Information about target
Shodan
Dig
Extract IPs
Search in shodan using IPs
Censys
Directory
dirsearch
dirsearch files
JS files
waybackurls
API leak
mantra
nuclei
NMAP
Http request smuggling
Parameters
extract PHP file
Arjun
paramspider
unique
OSINT Framework
Shodan
Crunch base
Whois
403/unauthorized
Last updated