githubEdit

Exposition Audit - Plan

circle-info

The objective is to define the attack surface of a company, mainly made up of all the elements of its information system exposed on the Internet.

Reconnaissance

  • Have your target organization name

  • Search through RIPE.netarrow-up-right :

    • domain.example > person > e-mail -> GO

    • Get these IP blocs that belongs to the company

Subdomains find

Google Dorks

site:domain.example -www

Tools

shodan

# install
pip install shodan
# usage
shodan domain domain.example

OneForAll

subfinder

Scans

IP2FQDN

nmap

Visualize hosts

gowitness

  • Get a capture of each web service

Last updated