Link to this headingDNS Recon
Link to this headingAmass
Get Whois Information from domain:
>>> amass
Get Whois Information from Organization:
>>> amass
Look for Subdomains on other sites:
>>> amass
Try Zone Transfer to get information:
>>> amass
Active DNS Brute forcing:
>>> amass
>>> amass
Link to this headingDIG commands
DNS Lookup
Perform DNS IP Lookup
Perform MX Record Lookup
Perform Zone Transfer with DIG
Windows DNS zone transfer
Link to this headingBrute Force DNS addresses
Link to this headingSublist3r
This runs Sublist3r on a list of domains and outputs the results in separate files.
Link to this headingAquatone
Aquatone One-liner
&&
Link to this headingDNSRecon
Link to this headingSearch for other domains using certificates.
Link to this headingCertspotter
| | | |
| | | | | | |
Link to this headingScans.io
Command to parse & extract sub-domains for a given domain:
| | |
Link to this headingCert.sh database
Link to this headingResolve domains
Use Certificate Transparency logs to find DNS addresses. Then use them to resolve to IP addresses and add them to the list.
|
Link to this headingSearch for other domains using IPv4 scans.
| | |
Resolution
- http://dnsbin.zhack.ca (DNS)
- http://pingb.in (DNS)
- http://requestb.in (HTTP)
- https://www.mockbin.org/ (HTTP)
Reconnaissance
domain research tool
Older Tools:
- https://dnslytics.com/bgp/us
- Reverse IP Lookup (Domainmonitor)
- Security headers (Security Report, missing headers)
- http://threatcrowd.org (WHOIS, DNS, email, and subdomain recon)
- https://mxtoolbox.com (wide range of DNS-related recon tools)
- https://publicwww.com/ (Source Code Search Engine)
- http://ipv4info.com/ (Find domains in the IP block owned by a Company/Organization)
- HackerTarget Tools (DNS recon, site lookup, and scanning tools)
- VirusTotal (WHOIS, DNS, and subdomain recon)
- crt.sh (SSL certificate search)
- Google CT (SSL certificate transparency search)
- PenTest Tools (Google dorks)
- Wayback Machine (Find stuff which was hosted on the domain in past)
- FindSubdomains (Find subdomains using domain or keywords)
- https://scans.io/
Link to this headingInternal DNS
Do a DNS lookup for terms such as intranet, sharepoint, wiki, nessus, cyberark and many others to start intel on your target.