External Reconnaissance

Root Domains

#Acquisition
https://crunchbase.com

#Reverse Whois
https://www.whoxy.com
amass intel -src -whois -d example.com

#Ad Relationships
https://builtwith.com/relationships/etisalat.eg

ASN Enumeration

# Find ASN for org
http://bgp.he.net
amass intel -org example.com

# Find root domains through Reverse DNS (ASN -> CIDR -> Reverse DNS)
amass intel -ipv4 -src -asn 26808

# Find root domains through Reverse DNS + SSL Cert Dump
amass intel -active -ipv4 -src -asn 26808

Sub Domains Enumeration

Public Data Sources

Rapid7 Project Sonar

Amass

SubFinder

Brute Force

Alternations

Zone Transfer

Reverse DNS & Cert Dump

Sub-Domains Takeover

Live Sub-Domains

IP Addresses

Censys

Shodan

Service Scanning

Nmap

Github Recon

Cloud Recon

People OSINT

Hunter

Google Dorks

LinkedIn

Leaked Databases

Last updated