crosshairs-simpleService Enumeration

Infrastructure Enumeration

Check Certificate transparency

curl -s https://crt.sh/\?q\=<target-domain>\&output\=json | jq .

Scan IP Addresses using Shodan

for i in $(cat ip-addresses.txt);do shodan host $i;done

Scan Domain using whois

whois <Domain> 

Service-Based Enumeration

FTP Enumeration

# Interact with FTP service
ftp <IP>                                                 
# Interact with FTP through NC
nc -nv <IP> 21                                           
# Interact with FTP through telnet
telnet <IP> 21                                           
# Interact with FTP through openssl
openssl s_client -connect <IP>:21 -starttls ftp          
# Download all files on FTP
wget -m --no-passive ftp://anonymous:anonymous@<target>  

SSH Enumeration

DNS Enumeration

SMB Enumeration

NFS Enumeration

IMAPS/POP3 Enumeration

SMTP Enumeration

SNMP Enumeration

MySQL Enumeration

MSSQL Enumeration

IPMI Enumeration

WnRM Enumeration

Last updated