Intro
Active Recon - Interacting with the target
- Port Scanning -
nmap, masscan, unicornscan
- Vulnerability Scanning -
nessus, nikto, openvas
- Network Mapping -
nmap, traceroute
- Banner Grabbing -
netcat, curl
- OS Fingerprinting -
-O
- Service Enum -
-sV
- Web Spidering - crawling
Passive Recon - Without interacting with the target
- Search Engine Queries -
google, shodan
- WHOIS lookup -
whois cmdline
- DNS -
dig, nslookup
- Web Archive Analysis -
wayback machine
- Social Media analysis
- Code repos -
github, gitlab