1. Reconnaissance — Overview
Reconnaissance Pipeline:
Target → Passive Recon → Active Recon → Scan → Report
│ │ │
├── OSINT ├── Port scan ├── Vuln scan
├── DNS enum ├── Service ID ├── Nuclei
├── Subdomain ├── Web crawl └── Custom
├── Cert trans └── Dir brute
└── Shodan/Censys
Tools by Phase:
Passive: Amass, subfinder, theHarvester, Shodan, crt.sh
Active: Nmap, masscan, httpx, ffuf, gobuster
Vuln: Nuclei, nikto, OWASP ZAP, Burp Suite
2. Subdomain Enumeration
# --- Amass — comprehensive subdomain discovery ---
# Passive enumeration (no direct connection to target)
amass enum -passive -d example.com -o amass_passive.txt
# Active enumeration (includes DNS brute-force)
amass enum -active -d example.com -brute -w /usr/share/wordlists/dns.txt \
-o amass_active.txt
# Amass with config file
cat > amass_config.ini << 'EOF'
[scope]
[scope.domains]
domain = example.com
[data_sources]
[data_sources.Shodan]
[data_sources.Shodan.account1]
apikey = YOUR_SHODAN_KEY
[data_sources.SecurityTrails]
[data_sources.SecurityTrails.account1]
apikey = YOUR_ST_KEY
[data_sources.VirusTotal]
[data_sources.VirusTotal.account1]
apikey = YOUR_VT_KEY
EOF
amass enum -active -d example.com -config amass_config.ini -o amass_full.txt
# --- subfinder — fast passive subdomain discovery ---
subfinder -d example.com -all -recursive -o subfinder.txt
# --- Combine and deduplicate ---
cat amass_passive.txt subfinder.txt | sort -u > all_subdomains.txt
echo "[+] Total unique subdomains: $(wc -l < all_subdomains.txt)"
# --- Check which subdomains are alive ---
cat all_subdomains.txt | httpx -silent -status-code -title \
-o alive_subdomains.txt
# --- Certificate Transparency ---
curl -s "https://crt.sh/?q=%.example.com&output=json" | \
jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u > crt_subs.txt
3. Nmap — Advanced Port Scanning
# --- Host Discovery ---
# Ping sweep — find alive hosts
nmap -sn 10.0.0.0/24 -oG ping_sweep.gnmap
grep "Up" ping_sweep.gnmap | awk '{print $2}' > alive_hosts.txt
# ARP scan (local network only)
nmap -sn -PR 10.0.0.0/24
# --- Port Scanning Techniques ---
# SYN scan (default, stealthy, requires root)
sudo nmap -sS -p- --min-rate 5000 -T4 10.0.0.1 -oA syn_scan
# TCP Connect scan (no root required)
nmap -sT -p 80,443,8080,3306,5432,6379,27017 10.0.0.1
# UDP scan (slow but important)
sudo nmap -sU --top-ports 50 10.0.0.1
# Version detection
nmap -sV --version-intensity 5 -p 22,80,443,3306 10.0.0.1
# OS detection
sudo nmap -O --osscan-guess 10.0.0.1
# --- NSE Scripts ---
# Default scripts
nmap -sC -sV -p 80,443 example.com
# Specific vulnerability scripts
nmap --script vuln -p 80,443 example.com
# HTTP enumeration
nmap --script http-enum,http-headers,http-methods -p 80,443 example.com
# SSL/TLS analysis
nmap --script ssl-enum-ciphers,ssl-cert -p 443 example.com
# SMB enumeration (Windows)
nmap --script smb-enum-shares,smb-vuln-ms17-010 -p 445 10.0.0.1
# --- Comprehensive scan command ---
sudo nmap -sS -sV -sC -O -p- \
--min-rate 10000 \
--script "default,vuln,discovery" \
-oA full_scan \
10.0.0.1
Nmap Output Formats:
-oN normal output (human-readable)
-oG grepable output (for scripting)
-oX XML output (for tools like searchsploit)
-oA all formats at once
Port States:
open Service accepting connections
closed Accessible but no service listening
filtered Firewall blocking — can't determine
unfiltered Accessible but open/closed unknown
open|filtered Can't determine if open or filtered
4. Masscan — High-speed Port Scanner
# Masscan — scan entire internet in 6 minutes (don't do this!)
# Fast scan of large networks
sudo masscan 10.0.0.0/16 -p 80,443,8080,8443 \
--rate 10000 \
--output-format json \
--output-filename masscan_results.json
# Combine with Nmap for accuracy
# Step 1: Fast port discovery with masscan
sudo masscan 10.0.0.0/24 -p 1-65535 --rate 10000 \
-oG masscan_ports.gnmap
# Step 2: Extract open ports
grep "open" masscan_ports.gnmap | \
awk '{print $4}' | cut -d/ -f1 | sort -un | \
tr '\n' ',' > open_ports.txt
# Step 3: Detailed scan with Nmap on discovered ports
nmap -sV -sC -p $(cat open_ports.txt) 10.0.0.0/24 -oA detailed_scan
5. Nuclei — Template-based Vulnerability Scanner
# --- Installation ---
go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
# Update templates
nuclei -update-templates
# --- Basic scanning ---
# Scan single target
nuclei -u https://example.com -o nuclei_results.txt
# Scan with severity filter
nuclei -u https://example.com \
-severity critical,high \
-stats \
-o nuclei_critical.txt
# Scan multiple targets
nuclei -l alive_subdomains.txt \
-severity critical,high,medium \
-c 50 \
-rate-limit 150 \
-o nuclei_all.txt
# --- Template categories ---
# CVE scanning
nuclei -u https://example.com -t cves/ -severity critical
# Exposure scanning (sensitive files, misconfigs)
nuclei -u https://example.com -t exposures/
# Technology detection
nuclei -u https://example.com -t technologies/
# Misconfiguration scanning
nuclei -u https://example.com -t misconfiguration/
# Default credentials
nuclei -u https://example.com -t default-logins/
# Specific tags
nuclei -u https://example.com -tags sqli,xss,ssrf,lfi
# --- Custom Nuclei Template ---
# custom-templates/api-key-exposure.yaml
id: api-key-in-js
info:
name: API Key Exposure in JavaScript Files
author: xdev-pentester
severity: high
description: Detects API keys exposed in JavaScript files
tags: exposure,apikey,javascript
http:
- method: GET
path:
- "{{BaseURL}}/js/app.js"
- "{{BaseURL}}/static/js/main.js"
- "{{BaseURL}}/assets/js/config.js"
matchers-condition: or
matchers:
- type: regex
regex:
- "(?i)(api[_-]?key|apikey|api_secret)['\"]?\\s*[:=]\\s*['\"][a-zA-Z0-9]{20,}"
- "(?i)(aws_access_key_id)['\"]?\\s*[:=]\\s*['\"]AKIA[A-Z0-9]{16}"
- "(?i)(firebase|supabase).*['\"][a-zA-Z0-9]{30,}['\"]"
part: body
extractors:
- type: regex
regex:
- "(?i)(api[_-]?key|apikey)['\"]?\\s*[:=]\\s*['\"][^'\"]{20,}['\"]"
part: body
# custom-templates/auth-bypass.yaml
id: auth-bypass-path-traversal
info:
name: Authentication Bypass via Path Traversal
author: xdev-pentester
severity: critical
tags: auth-bypass,critical
http:
- method: GET
path:
- "{{BaseURL}}/admin"
- "{{BaseURL}}//admin"
- "{{BaseURL}}/./admin"
- "{{BaseURL}}/admin;/"
- "{{BaseURL}}/admin/..;/"
- "{{BaseURL}}/%2f/admin"
- "{{BaseURL}}/admin%20/"
- "{{BaseURL}}/admin%09/"
matchers-condition: and
matchers:
- type: status
status:
- 200
- type: word
words:
- "dashboard"
- "admin panel"
- "management"
condition: or
part: body
6. Recon Automation Pipeline
#!/bin/bash
# recon-pipeline.sh — Automated reconnaissance
TARGET=$1
OUTPUT_DIR="./recon/$TARGET"
mkdir -p "$OUTPUT_DIR"/{subdomains,ports,vulns}
echo "[*] Starting recon for $TARGET"
# Phase 1: Subdomain Enumeration
echo "[+] Phase 1: Subdomain enumeration..."
subfinder -d "$TARGET" -all -silent > "$OUTPUT_DIR/subdomains/subfinder.txt"
amass enum -passive -d "$TARGET" -o "$OUTPUT_DIR/subdomains/amass.txt" 2>/dev/null
# Combine and deduplicate
cat "$OUTPUT_DIR"/subdomains/*.txt | sort -u > "$OUTPUT_DIR/subdomains/all.txt"
echo " Found $(wc -l < "$OUTPUT_DIR/subdomains/all.txt") unique subdomains"
# Phase 2: Alive check
echo "[+] Phase 2: Checking alive hosts..."
cat "$OUTPUT_DIR/subdomains/all.txt" | \
httpx -silent -status-code -title -tech-detect \
-o "$OUTPUT_DIR/subdomains/alive.txt"
# Phase 3: Port scanning
echo "[+] Phase 3: Port scanning..."
cat "$OUTPUT_DIR/subdomains/alive.txt" | awk '{print $1}' | \
while read -r url; do
host=$(echo "$url" | sed 's|https\?://||' | cut -d/ -f1)
nmap -sV --top-ports 1000 -T4 "$host" \
-oN "$OUTPUT_DIR/ports/${host}.txt" 2>/dev/null
done
# Phase 4: Vulnerability scanning
echo "[+] Phase 4: Nuclei vulnerability scan..."
cat "$OUTPUT_DIR/subdomains/alive.txt" | awk '{print $1}' | \
nuclei -severity critical,high,medium \
-c 30 -rate-limit 100 \
-o "$OUTPUT_DIR/vulns/nuclei.txt"
# Summary
echo ""
echo "========== RECON SUMMARY =========="
echo "Subdomains found: $(wc -l < "$OUTPUT_DIR/subdomains/all.txt")"
echo "Alive hosts: $(wc -l < "$OUTPUT_DIR/subdomains/alive.txt")"
echo "Vulnerabilities: $(wc -l < "$OUTPUT_DIR/vulns/nuclei.txt")"
echo "Results saved to: $OUTPUT_DIR"
7. Summary
- Amass + subfinder: Subdomain enumeration (passive + active)
- Nmap: Port scanning, service detection, NSE scripts
- Masscan: High-speed scanning for large networks, combining Nmap
- Nuclei: Template-based vulnerability scanning, custom templates
- Automation: Pipeline combines all tools for effective recon
The next lesson will practice Web Application Testing with Burp Suite and OWASP ZAP.