Free DIY Recon Toolkit
A purpose index of the external reconnaissance tools and the 5-step methodology we use — for authorized assessments, education, and defensive research.
Authorized use only
The tools and techniques listed here are for authorized security assessments, education, and defensive research only. Never use them on systems without explicit written permission from the asset owner. Unauthorized security testing is illegal.
- Unauthorized testing
- Intrusive exploitation
- Accessing sensitive data
- Anything outside written scope / permission
Reconnaissance methodology
A simple 5-step flow for external recon.
OSINT
Passive information gathering
Network Mapping
Identify hosts and ports
Enumeration
Service fingerprinting
Discovery
Identify exposures
Analysis
Prioritize findings
Tools reference
A purpose index — no runnable syntax, just what each tool is for.
Port scanning and service fingerprinting
Use non-intrusive scanning and stay within authorized scope.
Fast port scanning to support deeper enumeration
Use responsibly — avoid high-impact scan settings.
Subdomain enumeration and asset discovery
Combine passive sources with validated results.
DNS probing and validation of discovered hosts
Validate and deduplicate results.
OSINT collection for emails, subdomains, and metadata
Prefer passive sources where possible.
Certificate transparency search for subdomains and domains
Good starting point for passive discovery.
Internet-facing device and service exposure discovery
Useful for exposure validation and context.
Domain registration and ownership context
May help with asset ownership questions.
Automated OSINT collection and correlation
Review results carefully for false positives.
Modular recon framework for data gathering
Great for structured collection.
Vulnerability scanning and reporting support
Validate findings and avoid intrusive checks.
SSL/TLS configuration analysis
Useful for identifying weak ciphers and misconfigurations.
Key considerations
Before you start
- Obtain written authorization for all targets
- Define scope boundaries clearly
- Document your source IPs for the client SOC
- Establish communication channels for critical findings
- Agree on report format and delivery timeline
During the assessment
- Stay within authorized scope
- Log activities for evidence
- Validate findings before reporting
- Report critical issues immediately
- Avoid intrusive or destructive testing
Want prioritized findings without the DIY?
The External Exposure Audit Sprint delivers prioritized findings with evidence and a remediation roadmap in 3–5 business days.