Service Enumeration
Infrastructure Enumeration
Check Certificate transparency
curl -s https://crt.sh/\?q\=<target-domain>\&output\=json | jq .Scan IP Addresses using Shodan
for i in $(cat ip-addresses.txt);do shodan host $i;doneScan Domain using whois
whois <Domain> Service-Based Enumeration
FTP Enumeration
# Interact with FTP service
ftp <IP>
# Interact with FTP through NC
nc -nv <IP> 21
# Interact with FTP through telnet
telnet <IP> 21
# Interact with FTP through openssl
openssl s_client -connect <IP>:21 -starttls ftp
# Download all files on FTP
wget -m --no-passive ftp://anonymous:anonymous@<target> SSH Enumeration
DNS Enumeration
SMB Enumeration
NFS Enumeration
IMAPS/POP3 Enumeration
SMTP Enumeration
SNMP Enumeration
MySQL Enumeration
MSSQL Enumeration
IPMI Enumeration
WnRM Enumeration
Last updated