Skip to content

🌍 DNS & Web Recon ​

πŸ› οΈ Tools ​

  • amass (GitHub) - OSINT + subdomain brute-force.
  • DNSRecon Github - Enum based on DNS records, bruteforce based on wilcard and much more.
  • dnsx - Fast and multi-purpose DNS toolkit.
  • MassDNS - High-performance DNS stub resolver targeting (350,000~ names per second).
  • subfinder - Subdomain enum based on several sources (censys, fofa, github).
  • Findomain - Subdomain enum based on APIs & Certificated.

🌐 Web App ​

  • httpx - Give your domain list, and get informations on target (technologies used, DNS, TLS, HTTP, Location and much more)
  • FinalRecon - Headers, TLS, (sub)DNS, wayback, port scan, fuzzing.
  • Raccoon - DNS Records, WHOIS, TLS, WAF, Bucket, Open Port, Fuzzing.
  • Gixy-Next - NGINX configuration security scanner.
  • Nuclei - Vulnerabilities scanner, customizable.
  • Wapiti - Web vulnerability scanner.
  • CRLFsuite Scanner
  • Corsfix - Check CORS configuration.