Perimeter
DNS
$ nslookup example.comSubdomains & AXFR
AS details
$
whois example.com$
whois 127.0.0.1Check for DNS Amplification
CMS, Stack, Vulns
WhatWeb, Wappalyzer
Shodan / Censys / SecurityTrails
Google Dorks
/robots.txt/sitemap.xml
Autonomous Systems
Info via IP
dig:
whois:
Info via ASN
whois:
Search AS
Map IP addresses to AS by origin and netname ignoring potentionally unwanted netname values by keywords:
One-liner providing the input from DivideAndScan:
Using ansmap:
Difference between as-name, aut-num, origin, netname, etc. may be found on RIPE.
Last updated