Footprinting
Infrastructure-based Enumeration
Command | Description |
| Certificate transparency. |
| Scan each IP address in a list using Shodan. |
Host-based Enumeration
FTP
Command | Description |
| Interact with the FTP service on the target. |
| Interact with the FTP service on the target. |
| Interact with the FTP service on the target. |
| Interact with the FTP service on the target using encrypted connection. |
| Download all available files on the target FTP server. |
SMB
Command | Description |
| Null session authentication on SMB. |
| Connect to a specific SMB share. |
| Interaction with the target using RPC. |
| Username enumeration using Impacket scripts. |
| Enumerating SMB shares. |
| Enumerating SMB shares using null session authentication. |
| SMB enumeration using enum4linux. |
NFS
Command | Description |
| Show available NFS shares. |
| Mount the specific NFS share.umount ./target-NFS |
| Unmount the specific NFS share. |
DNS
Command | Description |
| NS request to the specific nameserver. |
| ANY request to the specific nameserver. |
| AXFR request to the specific nameserver. |
| Subdomain brute forcing. |
SMTP
Command | Description |
|
IMAP/POP3
Command | Description |
| Log in to the IMAPS service using cURL. |
| Connect to the IMAPS service. |
| Connect to the POP3s service. |
SNMP
Command | Description |
| Querying OIDs using snmpwalk. |
| Bruteforcing community strings of the SNMP service. |
| Bruteforcing SNMP service OIDs. |
MySQL
Command | Description |
| Login to the MySQL server. |
MSSQL
Command | Description |
| Log in to the MSSQL server using Windows authentication. |
IPMI
Command | Description |
| IPMI version detection. |
| Dump IPMI hashes. |
Linux Remote Management
Command | Description |
| Remote security audit against the target SSH service. |
| Log in to the SSH server using the SSH client. |
| Log in to the SSH server using private key. |
| Enforce password-based authentication. |
Windows Remote Management
Command | Description |
| Check the security settings of the RDP service. |
| Log in to the RDP server from Linux. |
| Log in to the WinRM server. |
| Execute command using the WMI service. |
Oracle TNS
Command | Description |
| Perform a variety of scans to gather information about the Oracle database services and its components. |
| Log in to the Oracle database. |
| Upload a file with Oracle RDBMS. |
Last updated