-
Asset Discovery
-
Dns Brute Forcing and Resolving
- str-replace
- puredns
- massdns
-
Subdomain Discovery
- Amass
- subfinder
- findomain
-
Fingerprint
-
HTTP Discovery
- httprpobe
- httpx
-
Technology fingerprint
- httpx
-
Screenshot
- aquatone
- goverview
-
Spider Links
- gospider
- katana
-
OSINT
-
Finding more links
- gau
-
IP Discovery
- metabigor
- cdnstrip
-
Vulnerability Scan
-
Nuclei
- Subdomain takeover
- Scanning with all templates
-
Jaeles
- Scanning with all signatures
- Looking for interesting endpoints
-
Content Discovery
- Filtering and Beautify the output format
-
FFUF
- Looping for each domain and run ffuf on it
-
Port Scan
-
Full port scan
- rustscan
-
Service Fingerprint
- metabigor
- Vulnerability Scan
- Content Discovery
- Scanning based on open ports