home.social

#recon — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #recon, aggregated by home.social.

  1. Advanced Subdomain Discovery with Amass and Cheat Sheet

    In this cheat sheet, I cover essential Amass commands, enumeration techniques, and practical workflows for effective recon.
    denizhalil.com/2026/05/02/owas

    #CyberSecurity #OWASP #Amass #SubdomainEnumeration #Recon #OSINT #AttackSurface #BugBounty

  2. Advanced Subdomain Discovery with Amass and Cheat Sheet

    In this cheat sheet, I cover essential Amass commands, enumeration techniques, and practical workflows for effective recon.
    denizhalil.com/2026/05/02/owas

    #CyberSecurity #OWASP #Amass #SubdomainEnumeration #Recon #OSINT #AttackSurface #BugBounty

  3. Advanced Subdomain Discovery with Amass and Cheat Sheet

    In this cheat sheet, I cover essential Amass commands, enumeration techniques, and practical workflows for effective recon.
    denizhalil.com/2026/05/02/owas

    #CyberSecurity #OWASP #Amass #SubdomainEnumeration #Recon #OSINT #AttackSurface #BugBounty

  4. Plum, for Proactive Land Uncovering & Monitoring, is an orchestration tool to learn, monitor, and document an exposure surface. It coordinates work between scanning agents, keeps historical results, and makes observations searchable over time.

    This project, part of D4 which was initially co-funded by the European Union, is still young, but it already addresses a concrete need: helping CIRCL to keep a global view of Luxembourg’s IP space, especially in the context of NIS2-related activities. The goal is not only to scan, but to maintain actionable knowledge of the national perimeter, its visible exposures and allows vulnerability discovery in the context of incident response.

    #plum #scanning #networkscanning #cybersecurity #recon #csirt

    d4-project.org/2026/04/29/Plum

  5. This Is What a Personal Surveillance System Actually Looks Like

    You stop thinking of it as surveillance. It becomes “the system.” Just part of how things run.

    cha1nc0der.wordpress.com/2026/

  6. This Is What a Personal Surveillance System Actually Looks Like

    You stop thinking of it as surveillance. It becomes “the system.” Just part of how things run.

    cha1nc0der.wordpress.com/2026/

  7. This Is What a Personal Surveillance System Actually Looks Like

    You stop thinking of it as surveillance. It becomes “the system.” Just part of how things run.

    cha1nc0der.wordpress.com/2026/

  8. This Is What a Personal Surveillance System Actually Looks Like

    You stop thinking of it as surveillance. It becomes “the system.” Just part of how things run.

    cha1nc0der.wordpress.com/2026/

  9. This Is What a Personal Surveillance System Actually Looks Like

    You stop thinking of it as surveillance. It becomes “the system.” Just part of how things run.

    cha1nc0der.wordpress.com/2026/

  10. NiamonX Internet Surface (Beta) is now live — a passive, privacy-respecting OSINT & attack-surface intelligence platform built to map real-world exposure at global scale.

    Instead of noisy scans or shallow datasets, the platform merges:
    • internet-wide scanning (≈3,000 ports)
    • multi-source enrichment (WHOIS/RDAP, public registries, partner crawlers)
    • deep tech fingerprinting
    • graph-based topology mapping
    • AI-driven risk reports

    The topology graph reveals relationships between IP ranges, domains, ASNs, software stacks, libraries, misconfigurations, and exposed services — not just “open ports”.
    Patterns and systemic weaknesses become visible instantly.

    The built-in AI Auditor produces contextual security reports:
    • attack-path analysis
    • CVE clustering & prioritization
    • business impact breakdown
    • actionable remediation roadmap
    A process that normally takes days can now be done in hours.

    The entire system is designed with security & privacy in mind:
    • hardened infrastructure
    • zero request logging
    • no user tracking
    • only quota counters for rate enforcement

    Available across all plans — including the free tier.

    If you’re doing OSINT, threat hunting, red/blue team work, or asset discovery, this is a tool worth exploring.

    🔗 dash.niamonx.io/internet_surface
    🔗 is.niamonx.io

    #OSINT #ThreatIntel #Infosec #AttackSurface #SecurityTools #CyberSecurity #Recon #AI #PassiveRecon #NiamonX

  11. NiamonX Internet Surface (Beta) is now live — a passive, privacy-respecting OSINT & attack-surface intelligence platform built to map real-world exposure at global scale.

    Instead of noisy scans or shallow datasets, the platform merges:
    • internet-wide scanning (≈3,000 ports)
    • multi-source enrichment (WHOIS/RDAP, public registries, partner crawlers)
    • deep tech fingerprinting
    • graph-based topology mapping
    • AI-driven risk reports

    The topology graph reveals relationships between IP ranges, domains, ASNs, software stacks, libraries, misconfigurations, and exposed services — not just “open ports”.
    Patterns and systemic weaknesses become visible instantly.

    The built-in AI Auditor produces contextual security reports:
    • attack-path analysis
    • CVE clustering & prioritization
    • business impact breakdown
    • actionable remediation roadmap
    A process that normally takes days can now be done in hours.

    The entire system is designed with security & privacy in mind:
    • hardened infrastructure
    • zero request logging
    • no user tracking
    • only quota counters for rate enforcement

    Available across all plans — including the free tier.

    If you’re doing OSINT, threat hunting, red/blue team work, or asset discovery, this is a tool worth exploring.

    🔗 dash.niamonx.io/internet_surface
    🔗 is.niamonx.io

    #OSINT #ThreatIntel #Infosec #AttackSurface #SecurityTools #CyberSecurity #Recon #AI #PassiveRecon #NiamonX

  12. Everyone's making final updates for the initial release of @owasp Amass v5!

    Register and join our workshop at @defcon for additional details: lu.ma/hf83v61c

    #security #infosec #redteam #recon #osint #attacksurface @defconowasp

  13. Everyone's making final updates for the initial release of @owasp Amass v5!

    Register and join our workshop at @defcon for additional details: lu.ma/hf83v61c

    #security #infosec #redteam #recon #osint #attacksurface @defconowasp

  14. Everyone's making final updates for the initial release of @owasp Amass v5!

    Register and join our workshop at @defcon for additional details: lu.ma/hf83v61c

    #security #infosec #redteam #recon #osint #attacksurface @defconowasp

  15. Everyone's making final updates for the initial release of @owasp Amass v5!

    Register and join our workshop at @defcon for additional details: lu.ma/hf83v61c

    #security #infosec #redteam #recon #osint #attacksurface @defconowasp

  16. Everyone's making final updates for the initial release of @owasp Amass v5!

    Register and join our workshop at @defcon for additional details: lu.ma/hf83v61c

    #security #infosec #redteam #recon #osint #attacksurface @defconowasp

  17. If you're planning to attend @defcon 33, and would like to quickly get up to speed on the upcoming Amass v5.0 release, then please consider registering for this workshop being hosted in the @owasp Community Room!

    #security #infosec #owasp #recon #osint #DEFCON #attacksurface

    lu.ma/hf83v61c

  18. Today I found a TUI for discovering subdomains! 🕵️

    🌊 v**oyage:** A subdomain enumeration tool for your terminal

    🚀 Supports multiple discovery methods, real-time monitoring & more!

    🦀 Written in Rust & built with @ratatui_rs

    ⭐ GitHub: github.com/clickswave/voyage

  19. Fresh article on how to build, #RE, #debug, and #recon #XPC services on #macOS with an #XCode #Programming walkthrough (#C and #NSXPC APIs). Plus actual #debugging tips with #LLDB. If you are into #macOS/#iOS, this one's for you - #code included.
    Enjoy!

    karol-mazurek.medium.com/xpc-p

  20. Going to be in #nyc this upcoming Wednesday? Come learn with the @owasp Global Board!

    I'll be co-hosting with @redteamblueteam and doing a talk to introduce the new @amass project that builds your attack surface mapping infrastructure!

    #infosec #cyber #cybersecurity #security #recon #reconnaissance #attacksurface #attacksurfacemanagement

    meetup.com/owasp-new-york-city

  21. CW: Poll: Autism Awareness in App Profiles

    As I continue to #unmask during #Autism Awareness Month, I’ve been adjusting my various online profiles to raise awareness that I’m #Autistic. I’m curious whether others see this as useful. Or if you have done it, have you observed any effect on your interactions or success with folks online?

    #AutismAwarenessMonth #ActuallyAutistic #Sctuff #GROWLr #Grindr #BiggerCity #Recon #FetLife @actuallyautistic

  22. I recently made a highly efficient subdomain discovery wordlist by scanning the entire IPv4 space for SSL certs.

    I've written a full article on the project, which is, in fact, my first public InfoSec article ever!

    I would love to hear what you think!

    You can read it here:
    n0kovo.github.io/posts/subdoma

    (boosts and shares highly appreciated ❤️)

    #infosec #writeup #redteam #pentesting #recon #reconnaissance #enumeration #subdomain #subdomains #wordlist #masscan #osint #bugbounty #bughunter #hacking

  23. I recently made a highly efficient subdomain discovery wordlist by scanning the entire IPv4 space for SSL certs.

    I've written a full article on the project, which is, in fact, my first public InfoSec article ever!

    I would love to hear what you think!

    You can read it here:
    n0kovo.github.io/posts/subdoma

    (boosts and shares highly appreciated ❤️)

    #infosec #writeup #redteam #pentesting #recon #reconnaissance #enumeration #subdomain #subdomains #wordlist #masscan #osint #bugbounty #bughunter #hacking

  24. United States Air Force RQ-4 Global Hawk 10-2045 as FORTE10 at FL580 #AE5420 over Greece and about to go feet wet in the Aegean as it RTB. The Global Hawk is an uncrewed reconnaissance drone and is part of the NATOP responce to the russian invasion #NAFO #milair #RQ4 ##planespotting #haveglass #aviation #AvGeek #spotter #aviationdaily #photography #aircraft #Nikon #Z9 #AvgeeksofMastodon #Recon

  25. #ffuf - Fuzz Faster U Fool on multiple hosts

    for i in cat urls.txt; do ffuf -u $i/FUZZ -w wordlist.txt -mc 200,302,401 -se ;done

    github.com/ffuf/ffuf

    Pro Tip: If you are not finding any valid endpoints, try within a discovered path adding ..;/ to the url.

    ie site.tld/somedir/..;/FUZZ

    #bypass #payloads github.com/aufzayed/bugbounty/

    #bugbounty #bugbountytips #fuzzing #owasp #recon #osint