Recon/Mapping Phase

Auto Recon

https://github.com/six2dez/reconftw

Search Engine Discovery Recon

Fingerprint Web Server

Metafiles

Application Enumeration & Mapping

sublist3r -d example.com         # Subdomain enumeration, passive
subfinder -d example.com -silent # Subdomain enumeration, passive, part of ProjectDiscovery ecosystem
subfinder -d example.com -silent | httpx -silent -title -tech-detect

# Full port sweep, SYN scan
sudo nmap -sS -p- -T3 example.com 

# Can also use dnsdumpster.com
dnsrecon -d example.com          # DNS recon
dnsenum example.com              # Passive + Active DNS recon, perform DNS zone transfer

# Virtual host brute force
gobuster vhost -u "example.com" --domain example.com -w /path/to/wordlist --append-domain --exclude-length 250-320 

# Crawler, maps out every URL, endpoint, JS file, form, and parameter
katana -u -silent example.com
katana -u -silent example.com -jc -kf all -o output.txt   # Parse JS to find hidden endpoints
katana -u -silent example.com -jc -kf -hl                 # Find dynamic routings

# Fuzz for hidden endpoints, different from Katana
ffuf -w /path/to/wordlist -u example.com/FUZZ -mc 200,301 # Filter status code
## While using ffuf, can add .old extension at end, example.com/FUZZ.old

## Virtual host fuzzing
ffuf -u <https://target.com/> -H "Host: FUZZ.target.com" -w /path/to/wordlist -fs 0