How to: Recon and Content Discovery
ID: 5b9bdec7-3ce0-5d0a-bb01-af5826bfb2b4
STIX ID: report--5b9bdec7-3ce0-5d0a-bb01-af5826bfb2b4
Feed Name: HackerOne Blog
This blog post by Ben Sadeghipour details reconnaissance methodologies for expanding an organization's attack surface—covering recursive subdomain brute forcing, GitHub searches for leaked credentials and endpoints, AWS S3 discovery (including lazys3), and asset identification via Censys, Shodan, and Archive.org—while emphasizing creativity, scope awareness, and common caveats to avoid false positives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
