Perimeter
DNS
$ nslookup example.com
Subdomains & AXFR
AS details
$
whois example.com
$
whois 127.0.0.1
Check for DNS Amplification
CMS, Stack, Vulns
WhatWeb, Wappalyzer
Shodan / Censys / SecurityTrails
Google Dorks
/robots.txt
/sitemap.xml
Autonomous Systems
Info via IP
dig:
whois:
Info via ASN
whois:
Search AS
Map IP addresses to AS by origin
and netname
ignoring potentionally unwanted netname
values by keywords:
whois.sh
One-liner providing the input from DivideAndScan:
Using ansmap:
Difference between as-name, aut-num, origin, netname, etc. may be found on RIPE.
Last updated