Information Gathering

The more you know about the target, the more successful you will be in the next stages of penetration test

What information are we looking for?

Passive Information Gathering
Active Information Gathering

Pasive Information Gathering

Get an IP address

host $IP

Check for hidden files

robots.txt
sitemap.xml
/crossdomain.xml
/clientaccesspolicy.xml
/.well-known/

Extensions

  • Builtwith

  • Wappalyzer

Version/Tech

Analyze the source code

Domain enumeration without engage the target

  • enumeration

  • subdomains

Active Information Gathering

Host Discovery

  • netdiscover

  • fping

  • nmap

  • No man's land

DNS Zone Transfer

  • dig

  • host

  • nslookup

  • DNS Records

Port Scanning

It is recomanded to save the scans in a file. I usualy save this files in recon directory

  • TCP Scan

  • UDP Scan

  • VULN Scan

  • Firewall/IDS Evasion

  • rustscan

Last updated