External Recon Methodology
metodoloji offensive
External Recon Methodology metodoloji notudur. Keşif → hipotez → PoC → kanıt akışını tutarlı uygula.
Metodoloji
Section titled “Metodoloji”-
Kapsam ve engel listesini kilitle.
-
Pasif/aktif keşif ile envanter çıkar.
-
Risk odaklı hipotezleri PoC ile doğrula.
-
Kanıt ve sonraki pivot notunu paketle.
Dış recon
Section titled “Dış recon”bbot -t domain.com -f subdomain-enumsubfinder -d domain.com -silent | httpx -title -tech-detectnaabu -list live.txt -p - -c 50nuclei -l live.txt -severitySecret sızıntısı
Section titled “Secret sızıntısı”trufflehog git https://github.com/ORG/REPO --only-verifiedgitleaks detect --source . -vgh search code "AKIA filename:.env" --owner ORGrequest/response, komut çıktısı, ekran, hash, zaman damgası, etki özetimkdir -p evidence/metodoloji && tee evidence/metodoloji/notes.txtChecklist
Section titled “Checklist”[ ] fingerprint / profil alındı[ ] primitif veya erişim doğrulandı[ ] PoC etkiyi gösterdi[ ] kanıt paketlendi[ ] sonraki pivot not edildi