October 30, 2019 · Basic Pen-Testing

3.1 : Passive information gathering techniques

Basics

Passive information gathering is reconing targets info from the internet, without direct touchpoint, including the following assets:

The key, is to identify possible attack surface.

public info & creds tree-passing

Google


sub-domain enum

Sublist3r

amass

rapid-7

Whois cli


Email enum

theharvester


features update

Web archive