My Recon
my recon methodology.
whois:
whois target.comBanner Grabbing:
whatweb --no-errors target.comcurl -IL https://www.target.comSubdomains Enumeration:
Listing:
subfinder -d domain.com -o output1.txtassetfinder -subs-only domain.com > output2.txtadd all together:
list live subs:
get URLs:
shortcut:
use gau tool:
Resources recon:
Is there a WAF?
Last updated