- 92
- Messages
- 6
- Threads
-
0
- Rep
4 Years of Service
A great thread and very well written. I personally use Maltego I will open a "Case FIle" from there I will map out the different pieces of information I have gathered. I can't tell you how many times google dorking has helped me find say a pdf or a doc file which helped me identify software used by say a target, generally this works well when the target has a large surface exposed. There are also many dual purpose tools, for example we might see VirusTotal for scanning files, but no it can also be used to scan urls/domains which in this case we can get some subdomains as well as possible IP addresses. The real basics of dig, nslookup and whois often are the bread and butter of recon.