Passive Reconnaissance
18 May 2025
• 1 min read
Steps
-
First we start by simple
whoiscommand to know more data about the registrant or the registrar so we could tailor a potential social engineering attack on the target -
We will need to get more information from the registrar DNS to know more about the registrant we here can use
nslookupordig(provides more information) -
This tools are limited in subdomain discovery here we could use
DNSDumpsterwebsite to get more information about the subdomains and a graph that gives us a better visualization