External Assessments

Uncovering Assets

Finding Alternate Domains

Project Discovery Tools

Project Discovery’s Tool Manager can install all of the above go tools in one shot

Misc tools

Search tools

DNS Querying

Viewing websites:

EyeWitness

EyeBaller

Finding user information and passwords:

Shodan

Burp

Email & Domain security

Email security

Subdomain takeovers

Cloud

AADInternals

Secrets

LinkedIn

O365

Password spraying

OneDrive

Github

Rotating IPs

Documentation/Wikis Search documentation/internal wikis for:

net use
psexec
.pfx
AsPlainText
Authorization: Basic
Authorization: Bearer
admin:
admin/
NetworkCredential
password
root
passwd
credential
putty
logins
connectionstring
securestring
samaccountname
ldap
sudo
scp
ssh
.vmd
clientdomain\
@clientdomain.com
id_dsa
id_rsa
ghp_
AWS_SECRET_ACCESS_KEY + AKIA/ASIA
ssh_password
net user