Security Consultants and Penetration Testers
Initial reconnaissance phase of a professional penetration testing engagement
The Recon mind map template is a comprehensive cybersecurity framework designed for bug bounty hunters and penetration testers to systematically gather intelligence. Covering 79 distinct nodes, this cheat sheet organizes the reconnaissance phase into 12 critical categories including Passive Gathering, Subdomains, and Port Scan. It serves as a technical roadmap for security professionals to map an organization's digital footprint using industry-standard tools and manual techniques. The structure provides specific command-line examples for tools like 'subfinder' and 'amass', while also integrating advanced search methods such as 'Shodan Dorking' and 'Google Dorking' to identify exposed assets and sensitive information across the web.
NutzungsbedingungenInitial reconnaissance phase of a professional penetration testing engagement
Setting up an automated reconnaissance pipeline for bug bounty programs
Learning the standard OSINT and discovery tools used in modern cybersecurity
Download and open the .xmind file to view the full MoRamadan Recon methodology and tool hierarchy.
Modify the children nodes under 'Automated Scan' or 'Port Scan' to include your preferred local scripts or API keys.
Use the map as a live checklist by marking branches as complete as you finish each phase of your information gathering.
This template includes a structured hierarchy of reconnaissance methodologies, ranging from passive OSINT gathering to active port scanning. It features specific tool recommendations, GitHub repository links for automation, and exact command-line arguments for popular security tools used in the discovery phase of a penetration test.
You can use this template as a step-by-step checklist during your initial engagement phase. Start with the 'Passive Gathering' nodes to build a profile, then move to 'Subdomains' and 'Cloud' discovery to expand your scope, ensuring you don't miss critical assets like 'S3 Buckets' or exposed 'JS Filles'.
Yes, the template is fully editable. You can add your own custom dorks to the 'Google Dorking' section, update tool flags in the 'Subdomains' branch, or insert new automation scripts into the 'Automated Scan' category to keep your methodology current with the latest cybersecurity trends.
The template suggests a multi-tool approach. By following the 'Subdomains' branch, you can combine passive results from 'crt.sh' with active enumeration using 'amass' and 'dnsenum', then use the provided 'subfinder' commands to consolidate your findings into a clean target list.
Teilen Sie Ihre Mindmap-Vorlagen mit Erstellern weltweit und verdienen Sie mit Ihrer Arbeit.