Skip to content

Instantly share code, notes, and snippets.

@ruevaughn
Forked from rohan-cce/Recon Check List
Created August 10, 2023 18:29
Show Gist options
  • Select an option

  • Save ruevaughn/976680647c81d1e34ba3cb6425caefe8 to your computer and use it in GitHub Desktop.

Select an option

Save ruevaughn/976680647c81d1e34ba3cb6425caefe8 to your computer and use it in GitHub Desktop.
❌❌ :RECON CHECKLIST:❌❌
1. Subdomain Enumeration: subfinder-amass-altdns-sublister-assetfinder-findomain
2.Resolving Subdomains: HTTPX/HTTPROBE
3. Screenshotting: HTTPX/AQUATONE/EYEWITNESS/GOWITNESS
4. Port Scan: Nmap/Zenmap/Aquatone/Amass
5. Directory Bruteforce: FFUF/Dirsearch/Dirbuster
6. Crawling: waybackurls/gau
7. Finding endpoints from JS: relative-url-extracter
8. Manual Recon: Burp Suite
9. Subdomain Takeovers: subzy/SubOver/subjack
10.Finding endpoints: Waybackmachine
11. Finding Exposed files: Google Dorking
12. To find exposed api keys/secrets/tokens: Github Recon
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment