Domain Discovery
Check the following locations for additional domains:
Certificate Transparency Reports
Goole Cache
Wordlists in DNS
Discovery
Imagine that a DNS CNAME is for a record which is a separate subdomain on the cloud service, can we search for that record as well! This may give us additional information about new assets.
Tools
inetdata - https://github.com/hdm/inetdata
DNSRecon.py - https://github.com/darkoperator/dnsrecon
ShuffleDNS
Uses massdns
to shuffle DNS requests across many different providers, very quick!
gobuster
Last updated