Network Information

MITRE ATT&CK, Reconnaissance, Technique T1590

DNS Information

Subdomain enumeration is the process of finding valid resolvable subdomains for a companies domain(s). The more you can find, the more you can hack.

Google Dork

site:*.$domain -www)

Dome

# Passive subdomain enumeration
dome.py -m passive -d $domain

# Active enumeration
dome.py -m active -d $domain

Sublist3r

DNSRecon

Amass

Gobuster

IP Addresses

Hurricane Electric Internet Services

Hurricane Electric Internet Services is a fast way to identify what company owns what IP

SecurityTrails

SecurityTrails Another good site for verifying IP addresses and netblocks belonging to an organization

NetBlockTool

NetblockTool can be used to gather IP ranges, points of contact, and even netblocks belonging to your target’s subsidiaries

Basic usage

Extract ranges owned by the target company’s subsidiaries

References

References

DNS Information

IP Addresses

Last updated