Manual Network Exploration

Vinny Troia · 2020

This chapter provides an overview of performing general network reconnaissance on an organization, as well as scanning and identifying network hosts. It focuses on the process than the specific tools being used because when it comes to Open Source Intelligence, or probably any facet of information security, there will always be newer, better, and shinier tools to use. To illustrate the differences between the different tools and services, all tests are considered against two different servers, pepsi.com and cyper.org. The chapter looks at tools like Sublist3r, fierce, and Enumall, which are all essential to any digital investigator or penetration tester because of their ability to sniff out subdomains within a target domain. It also provides information on services like Shodan and Censys.io, which are big repositories of discoverable server information, and can also be used to identify servers or devices for target organization.

Read the paper · More papers on PaperTik