Content
A few things to look out for:
-
Naming patterns: A host named “firewall.yourcustomerdomain.com” is likely the firewall itself, allowing you to select the relevant testing tools you should be using for this type of domain.
-
Dev environments: A host named “webdevel.anothersite.com” is likely a development server, and could yield some interesting results.
-
Outdated software: IP addresses running outdated software versions has the potential to increase the attack surface
From there, pivot: the subnets and IPs you uncover may reveal infrastructure you didn't know existed. Use passive DNS intelligence to drill down into the newly discovered networks and keep mapping outwards.
GO DEEPER WITH DETEQTIVE
The infrastructure you don't know about is usually the infrastructure that matters most. Deteqtive's broader DNS coverage and one-click pivoting surface related subnets, hosts, and IPs you'd likely miss doing this manually, so nothing stays out of scope by accident.
Want to know more? Deteqtive is currently in early access, you can find more information here or get in touch if you have any questions.