← Back to Courses

Advanced Web Reconnaissance

ULTRA-DETAILED: Master infrastructure fingerprinting, DNS analysis, and automated reconnaissance tradecraft.

Curriculum

20 Modules
1

Infrastructure Fingerprinting & The DNS Deep Dive

Strategic context, protocol internals, and advanced tradecraft for DNS reconnaissance.

2

Passive Subdomain Enumeration

Using sources like CRT.sh, VirusTotal, and search engines to find subdomains without touching the target.

3

Active Subdomain Enumeration

Brute-forcing subdomains with MassDNS and permutation scanning.

4

Port Scanning & Service Discovery

Effective use of Nmap and Masscan to find open ports.

5

Web Technology Fingerprinting

Identifying CMS, frameworks, and libraries using Wappalyzer and BuiltWith logic.

6

Content Discovery (Dirbusting)

Finding hidden directories and files using Ffuf and Gobuster.

7

Parameter Discovery & Fuzzing

Finding hidden GET/POST parameters that might be vulnerable.

8

GitHub Reconnaissance

Finding secrets and leaked code in public repositories.

9

Cloud Asset Discovery

Enumerating S3 buckets, Azure Blobs, and Google Cloud Storage.

10

Visual Reconnaissance (Screenshots)

Automating screenshots with EyeWitness/Aquatone to identify interesting targets quickly.

11

JavaScript Analysis for Recon

Extracting endpoints and secrets from client-side JS files.

12

Internet-Wide Scanning Data

Using Shodan, Censys, and Fofa for passive infrastructure analysis.

13

WAF Detection & Evasion

Identifying Web Application Firewalls and finding the origin IP.

14

API Reconnaissance

Discovering and mapping undocumented API endpoints (Swagger/GraphQL).

15

Subdomain Takeovers

Identifying and verifying subdomain takeover vulnerabilities.

16

Wayback Machine & Archive Recon

Mining archived data for old endpoints and deleted secrets.

17

Email & User Enumeration

Finding valid users via password reset and registration endpoints.

18

Custom Wordlist Generation

Creating target-specific wordlists using CeWL and other tools.

19

Recon Automation Pipelines

Building a continuous monitoring system with multiple tools.

20

Final Exam: The Black Box

A complete recon assessment against a simulated target.

Course Info

~600 Minutes
20 Modules
Start Learning