Information Gathering
The more you know about the target, the more successful you will be in the next stages of penetration test
What information are we looking for?
Pasive Information Gathering
Get an IP address
host $IPCheck for hidden files
robots.txt
sitemap.xml
/crossdomain.xml
/clientaccesspolicy.xml
/.well-known/Extensions
Builtwith
Wappalyzer
Version/Tech
Analyze the source code

Domain enumeration without engage the target
enumeration
subdomains
Active Information Gathering
Host Discovery
netdiscover
fping
nmap
No man's land
DNS Zone Transfer
dig
host
nslookup
DNS Records
Port Scanning
TCP Scan
UDP Scan
VULN Scan
Firewall/IDS Evasion
rustscan

Banner Grabbing
Last updated