返回 Skill 列表
extension
分类: 开发与工程无需 API Key

pentest-osint-recon

开源情报收集和攻击面管理,用于外部侦察。

person作者: jakexiaohubgithub

Pentest OSINT Recon

Purpose

Gather publicly available information about a target organization to map its external attack surface, including subdomains, emails, and exposed assets.

Core Workflow

  1. Domain Enumeration: Discover subdomains and related assets using amass and subfinder.
  2. Tech Profiling: Identify technologies used on discovered assets using httpx and whatweb.
  3. Information Gathering: Search for emails, leaks, and social media presence using theharvester and search engines.
  4. Asset Correlation: Correlate IP addresses, domains, and technologies to find weak spots.
  5. Vulnerability Intel: Check discovered software versions against CVE databases.

References

  • references/tools.md
  • references/workflows.md