Full Recon Methodology
End-to-end attack-surface mapping: from a root domain to a prioritized list of live, interesting hosts.
Tags: recon, asset-discovery, methodology
Level: beginner
Method
Enumerate subdomains (passive)
Aggregate multiple passive sources and dedup. Passive first - it's fast and stealthy.
subfinder -d target.com -all -silent | anew subs.txt; assetfinder --subs-only target.com | anew subs.txtTools: subfinder, amass, assetfinder, anew
Bruteforce subdomains (active)
Add coverage with a DNS wordlist and fresh resolvers, filtering wildcards.
puredns bruteforce best-dns-wordlist.txt target.com -r resolvers.txt -w brute.txtTools: puredns
Resolve & find live HTTP
Resolve everything, then probe which hosts actually serve HTTP and enrich with title/tech.
cat subs.txt brute.txt | dnsx -silent | httpx -sc -title -tech-detect -o live.txtTriage visually
Screenshot everything and skim for admin panels, dev/staging, default installs, and odd tech.
gowitness scan file -f live.txtTools: gowitness
Scan for known issues
Run nuclei across live hosts, starting at critical/high to keep noise down.
nuclei -l live.txt -severity critical,high -o nuclei.txtTools: nuclei
Field notes
- Refresh your resolvers.txt regularly - stale resolvers cause false positives.
- Keep a per-target folder and use anew so re-runs only surface new assets.
- Staging/dev subdomains are gold - they're often less hardened.