Recon

assetfinder CrtSh Findomain Subfinder Github-Subdomains

httprobe

Terminal window
cat subs.txt | httprobe | tee -a alivesubs.txt

aquatone

cat subs.txt | aquatone

find low hanging fruit nuclei nmap nikto

  • scope domains
    • Find all the root domains
  • acquisitions
    • understand the company
    • crunchbase.com
  • asn enumeration
    • Autonomous System Number
    • bgp.he.net
    • asnlookup
    • metabigor
    • asn enumeration amass amass intel -asn 46489
  • reverse whois
    • api.whoxy.com -> search a domain and show the pasts been own
  • subdomain enumeration
  • port analysis
  • others
    • subdomain takeover
    • buckets
    • github leaks
    • interlace
    • screenshotting
    • frameworks