recon
ACTIVE
External networks
Aquatone -- excellent tool for multiple stages of bounty hunting/recon
TODO: FILL IN THESE EXAMPLES with the other aquatone tools
aquatone- ???
aquatone ???
aquatone-discover --threads 15 --nameservers 1.1.1.1 <domain>For local networks (ex: during CTFs)
netdiscover - very fast, uses arp; output = IP, MAC, HW Manuf based on MAC
nbtscan - find SMB shares/chatty windoze boxes
smbmap - SMB share enumerator
smbclient - connect to SMB shares to pull/put files
Passive
SSL Transparency Report - search by host/domain -- check the hostnames that a company has registered certs for (even expired certs!), and include subdomains in search
Last updated