
# cert transparency curl -s "https://crt.sh/?q=%25.target.com&output=json" | jq -r '.[].name_value' | anew crtsh.txt subfinder -d target.com -all -silent > subs_sf.txt assetfinder --subs-only target.com > subs_af.txt cat subs_*.txt | sort -u > all_subs.txt
# puredns puredns bruteforce $DNS_WORDLIST target.com -r resolvers.txt -o subs_pd.txt # gungnir gungnir -d target.com
cat all_subs.txt | httpx -silent -status-code -title -tech-detect -web-server -follow-redirects -o alive.txt # screenshot para ver visualmente gowitness file -f alive.txt -P ./shots/
naabu -list alive.txt -p - -rate 1000 -c 50 -nmap-cli 'nmap -sV -sC' -o ports.txt
nuclei -l alive.txt -t nuclei-templates/http/ -severity critical,high,medium -rl 30 -o nuclei.txt nuclei -l alive.txt -t nuclei-templates/http/exposures/
cat alive.txt | gau --threads 200 > urls_gau.txt cat alive.txt | waybackurls > urls_wb.txt # katana: JS crawler katana -u alive.txt -jc -kf all -d 5 -headless -silent > urls_kat.txt cat urls_*.txt | anew all_urls.txt
grep -iE '.js(?|$)' all_urls.txt > js_urls.txt
grep -Ei "login|signin|auth|oauth|reset" all_urls.txt > auth.txt
grep -Ei '[0-9]{2,}' all_urls.txt > idor_candidates.txt
grep -Ei "redirect|callback|goto|return|url=" all_urls.txt > openredir.txt
# linkfinder: endpoints dentro del JS python3 linkfinder.py -i https://target.com/app.js -o cli # arjun: parámetros GET/POST no documentados arjun -u "https://target.com/api" -m GET --stable
# mantra: scanner de secretos en JS cat js_urls.txt | mantra # trufflehog: solo secretos verificados trufflehog github --org=target --token=$GITHUB_TOKEN --only-verified
ffuf -u https://api.target.com/FUZZ -w apiroutes.txt -mc 200,201,204,301,302,401,403 -ac -t 40
# directorios ffuf -w /opt/useful/seclists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u https://target.com/FUZZ # por extensión ffuf -w /opt/useful/seclists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u https://target.com/FUZZ.js
# subdominios por Host header ffuf -u https://target.com -H "Host: FUZZ.target.com" -w /usr/share/wordlists/subdomains.txt -t 100 -fc 403 | tee ffuf_subs.txt
nuclei -u https://target.com -t nuclei-templates/http/misconfiguration/ -t nuclei-templates/http/exposures/ curl -sk -i -X OPTIONS https://target.com | grep -i "allow|^x-|content-security"
# aleatoriedad de tokens curl -sk -I https://target.com | grep -i set-cookie