recon

Tools & Defense

Nmap Mastery: Service Discovery and NSE Scripting

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Passive and Active Reconnaissance: Subdomain Enumeration with Amass and ffuf

A practical walkthrough of passive and active recon: DNS footprinting, subdomain enumeration with Amass, and vhost/path fuzzing with ffuf.
Web Exploitation

REST API Penetration Testing Methodology: From Recon to BOLA

A practical, repeatable methodology for testing REST APIs: BOLA, mass assignment, broken rate limiting, and blue-team defenses.
Mobile API OSINT

OSINT for Red Teamers: Mapping People and Infrastructure

A practical red-team OSINT workflow for enumerating people and infrastructure with theHarvester, Shodan, breach data, and DNS recon.
Mobile API OSINT

Subdomain Enumeration and Attack Surface Mapping with Amass, Subfinder, and httpx

A practical recon workflow chaining amass, subfinder, httpx, and ffuf to map an organization's external attack surface.