Information Gathering
DNS Enumeration
Passive Info Gathering
whois <target.com / $IP>
https://whois.icann.org/en
http://who.is/
http://whois.domaintools.com/
https://whois.net/Active Info Gathering
host target.com
nslookup target.com
nslookup -type= <NS,MX,PTR,A,CNAME,SOA> target.com
//Interactive Mode
nslookup
>set q=<ns,mx,ptr,a,cname,soa>
>target.com
dig target.com +short
dig target.com any
dig target.com <NS,MX,PTR,A,CNAME,SOA>
fierce -dns target.com
fierce -dns target.com --dnsserver <DNS Server>
dnsmap target.com
dnsrecon -d target.com
dmitry -iwnse target.comLast updated