CyberCheatsheets

All tools

15 cheatsheets in Reconnaissance & OSINT

Amass

Reconnaissance

In-depth attack surface mapping and subdomain enumeration via passive and active techniques.

attack-surfacednsosintsubdomain

Assetfinder

Reconnaissance

Find domains and subdomains related to a given domain using passive sources (Tom Hudson).

osintpassivesubdomain

Censys

Reconnaissance

Internet-wide scan data and certificate intelligence for hosts, services, and attack surface research.

asmcertificatesinternet-scanosint

dig

Reconnaissance

DNS lookup utility for querying record types, tracing resolution, and debugging DNSSEC.

dnsrecordstroubleshooting

dnsenum

Reconnaissance

Perl DNS enumerator for zone transfers, subdomain brute force, reverse lookups, and WHOIS.

dnssubdomainzone-transfer

dnsrecon

Reconnaissance

Python DNS enumeration tool for records, zone transfers, brute force, and cache snooping.

dnssrvsubdomainzone-transfer

Fierce

Reconnaissance

DNS reconnaissance tool that locates non-contiguous IP space near target domains.

dnsscansubdomain

nslookup

Reconnaissance

Interactive and non-interactive DNS query tool available on Linux and Windows for basic record lookups.

dnstroubleshootingwindows

OSINT

Reconnaissance

Open-source intelligence workflow: domains, emails, people, breaches, and infrastructure using Google dorks and free OSINT tools.

footprintinginvestigationosintrecon

Recon-ng

Reconnaissance

Modular reconnaissance framework with workspaces, modules, and API-driven OSINT collectors.

automationframeworkmodularosint

Shodan

Reconnaissance

Search engine for Internet-connected devices, banners, ports, and exposed services via CLI and web.

bannersinternet-scaniotosint

SpiderFoot

Reconnaissance

OSINT automation platform correlating IPs, domains, emails, breaches, and social data from 200+ modules.

automationcorrelationguiosint

Subdomain Enumeration

Reconnaissance

Find subdomains via passive sources, DNS brute force, certificate transparency, and permutation — then probe which are live.

attack-surfacebug-bountydnsrecon

Subfinder

Reconnaissance

Fast passive subdomain discovery using curated OSINT sources and API integrations.

osintprojectdiscoverysubdomain

theHarvester

Reconnaissance

OSINT gathering for emails, subdomains, hosts, and employee names from public sources.

breachemailosintsubdomain