Exposition Audit - Plan
Reconnaissance
Have your target organization name
Search through RIPE.net :
domain.example > person > e-mail -> GOGet these IP blocs that belongs to the company
Subdomains find
Google Dorks
site:domain.example -wwwTools
shodan
# install
pip install shodan
# usage
shodan domain domain.exampleOneForAll
subfinder
Scans
IP2FQDN
nmap
Visualize hosts
gowitness
Get a capture of each web service
Last updated