Attack Surface Management

Enumerate Hostnames via OSINT Sources

Inputs

domainssource-configuration

Outputs

subdomainssubdomain-detailspotential-hostnamespotential-hostname-detailssubdomain-wildcardssubdomain-wildcard-detailspotential-hostname-wildcardspotential-hostname-wildcard-details

Enumerate subdomains and hostnames passively using OSINT data sources

trickest-mhmdiaa2024-07-04
Attack Surface Management

Enumerate Hostnames via Root Domain DNS Brute Force

Inputs

domainswordlist

Outputs

subdomainssubdomain-details

Enumerate sub-subdomains of a list of hostnames using DNS brute force on the most likely hostnames

trickest-mhmdiaa2024-07-04
Attack Surface Management

Enumerate Hostnames via Recursive DNS Brute Force

Inputs

hostnameslevel-2-wordlistlevel-3-wordlistlevel-4-wordlisthostnames-per-level

Outputs

hostnameshostname-details

Enumerate sub-subdomains of a list of hostnames using DNS brute force on the most likely hostnames

trickest-mhmdiaa2024-07-04
Attack Surface Management

Enumerate Hostnames via DNS Permutations Brute Force

Inputs

hostnames

Outputs

hostnameshostname-details

Enumerate hostnames by checking for permutations of known hostnames

trickest-mhmdiaa2024-07-04
Attack Surface Management

Enumerate Hostnames via Crawling

Inputs

depthweb-servers

Outputs

subdomainssubdomain-details

Enumerate subdomains by crawling web servers and analyzing their HTML content and headers

trickest-mhmdiaa2024-07-04
Attack Surface Management

Generate Custom DNS Wordlists

Inputs

hostnames

Outputs

level-1-wordlistlevel-2-wordlistlevel-3-wordlistlevel-4-wordlist

Generate custom DNS brute force wordlists using known hostnames

trickest-mhmdiaa2024-07-04
Attack Surface Management

Enumerate DNS Records

Inputs

hosts

Outputs

dns-recordsresolving-hostnamesip-address-detailsip-addressessubdomainssubdomain-detailspotential-hostnamespotential-hostname-detailssubdomain-wildcardssubdomain-wildcard-detailspotential-hostname-wildcardspotential-hostname-wildcard-details

Enumerate DNS records for a list of hostnames, IP addresses, or IP ranges

trickest-mhmdiaa2024-07-04
Attack Surface Management

Probe for Web Servers

Inputs

hosts

Outputs

web-serversweb-server-detailssubdomainssubdomain-detailspotential-hostnamespotential-hostname-detailssubdomain-wildcardssubdomain-wildcard-detailspotential-hostname-wildcardspotential-hostname-wildcard-details

Probe for web servers on a list of hostnames, IP addresses, or IP ranges

trickest-mhmdiaa2024-07-04
Attack Surface Management

Scan for Open Ports

Inputs

hostsport-threshold

Outputs

port-detailshostname-portsip-ports

Scan for the top 1000 most common open ports on a list of hostnames, IP addresses, or IP ranges

trickest-mhmdiaa2024-07-04
Attack Surface Management

Fingerprint Network Services

Inputs

port-details

Outputs

network-service-details

Identify services running on network ports

trickest-mhmdiaa2024-07-04
Attack Surface Management

Fingerprint Web Technologies

Inputs

web-servers

Outputs

web-technologies

Identify technologies running on a list of web servers

trickest-mhmdiaa2024-07-04