External Assessments

Uncovering Assets

Project Discovery Tools

Project Discovery’s Tool Manager can install all of the above go tools in one shot

Misc tools

Search tools

Viewing websites:

GoWitness

EyeBaller

Finding user information and passwords:

Shodan

Burp

Email & Domain security

Email security

Subdomain takeovers

Cloud

AADInternals

Secrets

LinkedIn

O365

Password spraying

OneDrive

Github

Rotating IPs

Documentation/Wikis Search documentation/internal wikis for:

net use
psexec
.pfx
AsPlainText
Authorization: Basic
Authorization: Bearer
NetworkCredential
password
root
passwd
credential
putty
logins
connectionstring
securestring
samaccountname
ldap
sudo
scp
ssh
.vmd
clientdomain\
@clientdomain.com
id_dsa
id_rsa
ghp_
AWS_SECRET_ACCESS_KEY + AKIA/ASIA
ssh_password
net user