Recon
Recon Tools & Frameworks
Last updated
Recon Tools & Frameworks
Last updated
Tools:
ASNLookup
bgp.he.net
amass
docker build -t amass
(docker run amass intel -asn ASN_NUM,1,2,3)
Reverse WHOIS: whoxy.com (lets you search).
Good for API
Free Credits
DOMLink: recursively go through all whoxy output
Ad/Analytics Relationships: Builtwith.com
Google-Fu "<some search string>" inurl:<domain>
Shodan: Infrastructure spider. domain scanning. Free API.
Linked Discovery
gospider
hakrawler
Subdomain Enumeration:
subdomainizer
subscraper
exclusion example: site:<rootdomain> -www.<rootdomain>
(e.g: minus out subdomains; i.e pull out of some sub-domain)
Tools
subfinder:
github-subdomains.py
shosubgo (golang)
Subdomain Bruting
amass enum -brute -d <domain> -src
amas enum brute -d <domain> -rf resolvers.txt -w bruteforce.list