Grunt's personal blog

this is my personal blog for my hacking stuff, my degree stuff, etc

View on GitHub

General Enumeration stuff

Overview

Overview

OSINT

Resource Examples
ASN / IP registrars IANA, ARIN for searching the Americas, RIPE for searching in Europe, BGP Toolkit
Domain Registrars & DNS Domaintools, PTRArchive, ICANN, manual DNS record requests against the domain in question or against well-known DNS servers, such as 8.8.8.8
Social Media Searching LinkedIn, Twitter, Facebook, your region’s major social media sites, news articles, and any relevant info you can find about the organization
Public-Facing Company Websites Often, the public website for a corporation will have relevant info embedded. News articles, embedded documents, and the “About Us” and “Contact Us” pages can also be gold mines
Cloud & Dev Storage Spaces GitHub, AWS S3 buckets & Azure Blob storage containers, Google searches using “Dorks”
Breach Data Sources HaveIBeenPwned to determine if any corporate email accounts appear in public breach data, Dehashed to search for corporate emails with cleartext passwords or hashes we can try to crack offline. We can then try these passwords against any exposed login portals (Citrix, RDS, OWA, 0365, VPN, VMware Horizon, custom applications, etc.) that may use AD authentication

AD Enumeration

Detailed User Enumeration

Cloud services

DNS

vhost enum

http POST fuzzing