All tools
15 cheatsheets in Reconnaissance & OSINT
Amass
ReconnaissanceIn-depth attack surface mapping and subdomain enumeration via passive and active techniques.
Assetfinder
ReconnaissanceFind domains and subdomains related to a given domain using passive sources (Tom Hudson).
Censys
ReconnaissanceInternet-wide scan data and certificate intelligence for hosts, services, and attack surface research.
dig
ReconnaissanceDNS lookup utility for querying record types, tracing resolution, and debugging DNSSEC.
dnsenum
ReconnaissancePerl DNS enumerator for zone transfers, subdomain brute force, reverse lookups, and WHOIS.
dnsrecon
ReconnaissancePython DNS enumeration tool for records, zone transfers, brute force, and cache snooping.
Fierce
ReconnaissanceDNS reconnaissance tool that locates non-contiguous IP space near target domains.
nslookup
ReconnaissanceInteractive and non-interactive DNS query tool available on Linux and Windows for basic record lookups.
OSINT
ReconnaissanceOpen-source intelligence workflow: domains, emails, people, breaches, and infrastructure using Google dorks and free OSINT tools.
Recon-ng
ReconnaissanceModular reconnaissance framework with workspaces, modules, and API-driven OSINT collectors.
Shodan
ReconnaissanceSearch engine for Internet-connected devices, banners, ports, and exposed services via CLI and web.
SpiderFoot
ReconnaissanceOSINT automation platform correlating IPs, domains, emails, breaches, and social data from 200+ modules.
Subdomain Enumeration
ReconnaissanceFind subdomains via passive sources, DNS brute force, certificate transparency, and permutation — then probe which are live.
Subfinder
ReconnaissanceFast passive subdomain discovery using curated OSINT sources and API integrations.
theHarvester
ReconnaissanceOSINT gathering for emails, subdomains, hosts, and employee names from public sources.