Passive Reconnaissance
May 18, 2025Steps
First we start by simple
whoiscommand to know more data about the registrant or the registrar so we could tailor a potential social engineering attack on the targetWe will need to get more information from the registrar DNS to know more about the registrant we here can use
nslookupordig(provides more information)This tools are limited in subdomain discovery here we could use
DNSDumpsterwebsite to get more information about the subdomains and a graph that gives us a better visualization