Information Gathering

The more you know about the target, the more successful you will be in the next stages of penetration test

What information are we looking for?

chevron-rightPassive Information Gatheringhashtag
chevron-rightActive Information Gatheringhashtag

Pasive Information Gathering

Get an IP address

host $IP

Check for hidden files

robots.txt
sitemap.xml
/crossdomain.xml
/clientaccesspolicy.xml
/.well-known/

Extensions

  • Builtwith

  • Wappalyzer

Version/Tech

Analyze the source code

Domain enumeration without engage the target

  • enumeration

  • subdomains

Active Information Gathering

Host Discovery

  • netdiscover

  • fping

  • nmap

  • No man's land

DNS Zone Transfer

  • dig

  • host

  • nslookup

  • DNS Records

Port Scanning

circle-info

It is recomanded to save the scans in a file. I usualy save this files in recon directory

  • TCP Scan

  • UDP Scan

  • VULN Scan

  • Firewall/IDS Evasion

  • rustscan

Last updated