Passive Information Gathering
WHOIS
Linux
Windows
Nslookup & DIG
Querying: A Records for a Subdomain
Querying: PTR Records for an IP Address
Querying: ANY Existing Records
The more recent RFC8482 specified that ANY
DNS requests be abolished. Therefore, we may not receive a response to our ANY
request from the DNS server or get a reference to the said RFC8482.
Querying: TXT Records
Querying: MX Records
Nslookup
WHOIS
VirusTotal
Certificates
Certificate Transparency
| Issue the request with minimal output. |
| Ask for the json output. |
| Process the json output and print certificate's name value and common name one per line. |
| Sort alphabetically the output provided and removes duplicates. |
We also can manually perform this operation against a target using OpenSSL via:
TheHarvester
Read More.
Passive Infrastructure Identification
Read More.
Last updated