-
Directory Enumeration
- Dirsearch
- FFUF
- Wordlists
-
Technology Fingerprinting
- Wappalyzer Plugin
- Whatweb
-
Port Scanning
- NMap
- Naabu
-
Broken Link Hijacking
- BurpSuite Plugin
- Tool
-
JavaScript Files for Hardcoded APIs & Secrets
- Automated tools for finding hardcoded information
- Automated tools for finding params, endpoints, etc.
- Compare JS files (current and old)
-
Tools
- JFScan
- LinkFInder
- DetectDynamicJS
- Retire.js (Burp Plugin/Browser Extension/Standalone)
- JSLink Finder (Burp Plugin)
- SecretFinder
-
Parameter Discovery
- ParamSpider
- Arjun
-
Wayback History
- Wayback Machine
- Waybackurls
- gau
-
Domain-Specific GitHub & Google Dorking
- Google Hacking DB
- GitDocker
- GitRob
- GirHound
- Interesting GitHub Dorks List
-
Data Breach Analysis
- Intelx
- Hacking Forums
- Darkweb/Darknet Analysis
-
Misconfigured Cloud Storage
- S3 Misconfig Article
- If any outdated software is found , then check for CVEs
- by : Software Odyssey
- Reference : Harsh Bothra Mind Map