HTTP/HTTPS:
Reconnaissance
Subdomain brute force, passive recon, cert logs, and dorks
Certificate Transparency Enumeration
Enumerate subdomains and infrastructure by querying Certificate Transparency logs, leveraging publicly recorded TLS certificates to map attack surface during recon.
Google Dork Reconnaissance
Leverage advanced Google search operators to uncover exposed files, misconfigs, login portals, and sensitive data indexed on target web infrastructure.
Passive Web Reconnaissance
Techniques for gathering web infrastructure intel without direct interaction—DNS records, WHOIS, archived content, metadata, and OSINT sources.
Subdomain Bruteforce
Enumerate hidden subdomains via wordlist-based bruteforce using tools like gobuster, ffuf, and amass to expand attack surface during recon.