
Automated OSINT for Security Assessments
If you are a red teamer or a penetration tester you got to love automated OSINT tools which will help your security assessments. Here is one of the best ones.
Articles
9 articles, newest first.

If you are a red teamer or a penetration tester you got to love automated OSINT tools which will help your security assessments. Here is one of the best ones.

DNS zone transfers use the AXFR protocol to replicate DNS records across DNS servers. If you do not protect your name servers, attackers can get information about all your hosts with AXFR.

Social media platforms can betray a considerable amount of information on a person or organization which can be useful during a pentest information gathering.

You can build a pentest lab on a raspberry pi with DVWA to test your skills and also learn new tricks on how to attack and/or secure web applications.

WebMap is a web dashboard for your nmap scans. This tool, which is free, can provide you with more management capabilities of your scan results.

Nikto is an open source scanner capable of scanning for over 6700 items to detect any misconfigurations on web servers like Apache, Nginx, Litespeed etc. as well as discovery of exposed files, user enumeration and outdated components.

A list of not so commonly used but powerful Nmap commands to help you bring your enumeration skills to the next level.

Google Dorking is great for penetration testing activities and security researching but can also be used to aid in the protection of sensitive information.

A list of docker security practices for securely configuring your Docker containers and images.