vulns.co
/
GKData.io MCP

Back to Playbooks

Full Recon Methodology

End-to-end attack-surface mapping: from a root domain to a prioritized list of live, interesting hosts.

Tags: recon, asset-discovery, methodology

Level: beginner

Method

  1. Enumerate subdomains (passive)

    Aggregate multiple passive sources and dedup. Passive first - it's fast and stealthy.

    subfinder -d target.com -all -silent | anew subs.txt; assetfinder --subs-only target.com | anew subs.txt

    Tools: subfinder, amass, assetfinder, anew

  2. Bruteforce subdomains (active)

    Add coverage with a DNS wordlist and fresh resolvers, filtering wildcards.

    puredns bruteforce best-dns-wordlist.txt target.com -r resolvers.txt -w brute.txt

    Tools: puredns

  3. Resolve & find live HTTP

    Resolve everything, then probe which hosts actually serve HTTP and enrich with title/tech.

    cat subs.txt brute.txt | dnsx -silent | httpx -sc -title -tech-detect -o live.txt

    Tools: dnsx, httpx

  4. Triage visually

    Screenshot everything and skim for admin panels, dev/staging, default installs, and odd tech.

    gowitness scan file -f live.txt

    Tools: gowitness

  5. Scan for known issues

    Run nuclei across live hosts, starting at critical/high to keep noise down.

    nuclei -l live.txt -severity critical,high -o nuclei.txt

    Tools: nuclei

Field notes

  • Refresh your resolvers.txt regularly - stale resolvers cause false positives.
  • Keep a per-target folder and use anew so re-runs only surface new assets.
  • Staging/dev subdomains are gold - they're often less hardened.

References