root@blog:~#

View on GitHub

Reconnaissance Tools

Usage Tool
Target Validation nslookup, dnsrecon, WHOIS
Subdomain Search Amass, Sublist3r, crt.sh, dig
Fingerprinting Nmap, NetCat, Wappalyzer, WhatWeb, BuiltWith
Data Leaks WeLeakInfo, HaveIBeenPwned, Breach-Parse

Identify Target

Bug Bounty

Using Bug Crowd I found Lime as a legal target for testing

targetpage

Target

Information Gathering

Hunter.io

Web Tool for Identifying Emails (li.me is there main website)

hunter hunted

Sublist3r

Quick and Easy Search Engine Scanner

sublist3r

crt.sh

Web Tool for Sub Domain Searching

crtsh

Although These result arent very intersting further scrolling reveals admin/test tools

crtres

Amass

Best Subdomain Searcher

amass

amasss

Fingerprinting

Wappalyzer

FireFox Extension for Webpages

wapp

wappfe

Built With Web Tool for Fingerprinting

lime bwf

limebike

WhatWeb

Built in Fingerprinter

watweb

WebProxy

BurpSuite Community Eddition

Best Web Scanner

burpc burp