BOOK THIS SPACE FOR AD
ARTICLE ADBy Tahir Mujawar, Certified Ethical Hacker & Cyber Security Researcher
Hey 👋 cyber adventurers! Tahir Mujawar here, introducing the Recon Mind map — a strategic guide for navigating cyber security’s complexities. Crafted meticulously, it’s our blueprint for reconnaissance, leading us through subdomains, tech identification, and content discovery. Let’s uncover cyberspace’s secrets and forge a safer digital frontier together with the Recon Mind map.
Recon isn’t just about gathering information — it’s about gaining insight, foresight, and the upper hand against unseen threats.
The purpose of creating the Recon Mind map is to streamline learning. With an abundance of resources available online, enthusiasts like myself often find it challenging to discern what to focus on. The Recon Mind map encompasses nearly all the essential topics for web application reconnaissance, providing clarity and direction in our learning journey.
Recon mind map encompasses the following elements:
Network Infrastructure Mapping
1. Topology Mapping
NetBrainNetCrunchSolarWinds2. Firewall Identification
WafW00fNmap NSE3. Load Balancers
lbd4. ASN
bgp.he.netHacker TargetAmass5. CIDR Range
Asn LookupMapcidrAmass Intelipaddressguide.com6. IP Blocks / Subnets
viewdnsMxToolswhois.arin.netwhoxywho.islopsegshodan.io7. IP Addresses
Open Ports, Services, Versions
MasscanNaabuRustscanNmapSandmapScan Cannon8. Cloud
Home Lister DirectorySubdomain Enumeration
* Horizontal / Acquisitions Enumeration
WhoisXMLAPICrunchBaseWikipediaChatGpt* vertical Enumeration
Passive Enumeration :
Passive SourcesChaosAmassSubfinderSublist3rAssetfinderOneForAllFindomainCrobatKnockpyGithub-Subdomains2. Certificate Logs
crt.shtls.bufferover.run3. Recursive Enumeration
Passive Sources* Active Enumeration
DNS Brute forcingPurednsCewlFFUF2. Permutations
Gotator3. JS / Source Code Scraping
LinkfinderGetJSGospider4. Google Analytics
Analytics Relationships5. TLS, CNAME probing
Cerohttpxdnsx6. VHOST probing
Virtual Host ScannerHost Hunter7. Web probing
UnimaphttpxTechnology Identification
WhatwebWappalyzerNetcraftBuiltwithFingerprintxRetire.JSDiscovery
1. URLs
GAULinxWaybackurlhakrawlerGospiderURLgrab2. Parameters
Param-Minerx8ParamethArjunGithub-Endpoints3. JS Enumeration
Secret FinderJS ReconLink FinderWayback URLsJS Scan4. Directory & file Enumeration
FFUFDirbGobusterDirSearchWFuzz5. Google FU
Github
TrufflehogGitDorkergithoundGitGrabberGitLeakesRepo-SupervisorBuckets
S3 ScannerS3 Bucket FinderGrayHatWarfareLazy S3AWS Bucket DumpCloudBruteCMS
WpscanCMSmapJoomscanOSINT & Social Engineering
OSINT FrameworktheHarvesterRecon-ngMaltegoMOSINTSpiderFootScreenshot
EyeWitnessLazyShotAquatoneWeb shotEyeballerHere’s the Mind map i was talking about, Use medium app or open it in your computer/laptop for better visibility. Ping me on LinkedIn to get PNG.
Connect me on LinkedIn
Researching takes considerable time. If you found this helpful, a Like, share, or follow would be greatly appreciated. Your support fuels our cyber journey!
Happy Hacking ! Bye Bye Hackers 👋