Recon General Notes - TheGetch/Penetration-Testing-Methodology GitHub Wiki
Recon General Notes
tcpdump -i eth0tcpdump -c -i eth0tcpdump -A -i eth0tcpdump -w 0001.pcap -i eth0tcpdump -r 0001.pcaptcpdump -n -i eth0tcpdump -i eth0 port 22tcpdump -i eth0 -src 172.21.10.Xtcpdump -i eth0 -dst 172.21.10.X
Other tools:
Tshark (Command Line Wireshark) Wireshark
DNSRecon:
dnsrecon -d www.example.com -adnsrecon -d www.example.com -t axfrdnsrecon -d <startIP-endIP>dnsrecon -d www.example.com -D <namelist> -t brt
Dig:
dig www.example.com + shortdig www.example.com MXdig www.example.com NSdig www.example.com> SOAdig www.example.com ANY +noall +answerdig -x www.example.comdig -4 www.example.com (For IPv4)dig -6 www.example.com (For IPv6)dig www.example.com mx +noall +answer example.com ns +noall +answerdig -t AXFR www.example.com
Sublis3r:
Sublist3r -d www.example.comSublist3r -v -d www.example.com -p 80,443
OWASP AMASS:
amass enum -d www.example.comamass intel -whois -d www.example.comamass intel -active 172.21.0.0-64 -p 80,443,8080,8443amass intel -ipv4 -whois -d www.example.comamass intel -ipv6 -whois -d www.example.com