Uncovering assets:
crt.sh, merklemap.com, censys, Shodan, Gau, Whoxy, LinkedIn scraping, Google Dorks, Crunchbase, Zoominfo (zoomeye?)
Awesome censys queries: https://github.com/thehappydinoa/awesome-censys-queries
Viewing websites:
gowitness scan cidr --write-db --cidr {IP_range} --write-db
gowitness scan file --write-db -f {file_with_ips}
gowitness scan cidr --write-db --cidr-file {file_with_cidrs}
gowitness report server
in the same directory (with gowitness.sqlite3
)Finding user information and passwords:
sudo python3 dehashed.py -q {domain_name} -p
Search documentation/internal resources for:
net use
psexec
.pfx
AsPlainText
Authorization: Basic
Authorization: Bearer
NetworkCredential
password
root
passwd
credential
putty
logins
connectionstring
securestring
samaccountname
ldap
sudo
scp
ssh
.vmd
clientdomain\
@clientdomain.com
id_dsa
id_rsa
ghp_
AWS_SECRET_ACCESS_KEY + AKIA/ASIA
ssh_password
net user