Skip to content
The route
03

Offensive · stage 3 of 10

Reconnaissance, OSINT & Scanning

Everything a target publishes without meaning to: subdomains, dorks, leaked keys in public repositories, staff email addresses — then Nmap to turn a map into a list of open doors.

Intermediate6 sessions7 h 50 mSessions 13–14, 18–19, 59–60
Get full access · ₹699

This module is included — it is not sold on its own.

// Sessions in this module

2 sections · 6 sessions · 7 h 50 m

Mapping the attack surface5 h 1 m

Everything a target publishes without meaning to.

  1. 01Subdomains and subdomain enumeration · Sublist3r · SubBrute · VirusTotal · httpstatus.io · whois1:28:41
  2. 02Google dorking · The Google Hacking Database1:35:48
  3. 03GitHub recon · Gitrob · GitHound1:46:47
  4. 04Hunter.io and theHarvester9:36
Port scanning with Nmap2 h 49 m
  1. 01Logical ports · Nmap · Scanning and scan types · Hibernation vs shutdown1:07:16
  2. 02Hunting for security jobs and internships · Advanced Nmap scans1:41:25

₹699

All 10 modules · lifetime access

Get access