본문으로 건너뛰기

Recon

템플릿 언어:English

Mohamed RamadanMohamed Ramadan

미리보기 로딩 중...

사용 사례

소개

The Recon mind map template is a comprehensive cybersecurity framework designed for bug bounty hunters and penetration testers to systematically gather intelligence. Covering 79 distinct nodes, this cheat sheet organizes the reconnaissance phase into 12 critical categories including Passive Gathering, Subdomains, and Port Scan. It serves as a technical roadmap for security professionals to map an organization's digital footprint using industry-standard tools and manual techniques. The structure provides specific command-line examples for tools like 'subfinder' and 'amass', while also integrating advanced search methods such as 'Shodan Dorking' and 'Google Dorking' to identify exposed assets and sensitive information across the web.

cybersecurityreconnaissance
이용약관

이 템플릿을 사용할 때

Security Consultants and Penetration Testers

Initial reconnaissance phase of a professional penetration testing engagement

Bug Bounty Hunters and Independent Researchers

Setting up an automated reconnaissance pipeline for bug bounty programs

Cybersecurity Students and Junior Analysts

Learning the standard OSINT and discovery tools used in modern cybersecurity

이 템플릿 사용 방법

단계 1

Import the reconnaissance map

Download and open the .xmind file to view the full MoRamadan Recon methodology and tool hierarchy.

단계 2

Customize your toolset

Modify the children nodes under 'Automated Scan' or 'Port Scan' to include your preferred local scripts or API keys.

단계 3

Execute and track progress

Use the map as a live checklist by marking branches as complete as you finish each phase of your information gathering.

자주 묻는 질문

This template includes a structured hierarchy of reconnaissance methodologies, ranging from passive OSINT gathering to active port scanning. It features specific tool recommendations, GitHub repository links for automation, and exact command-line arguments for popular security tools used in the discovery phase of a penetration test.

You can use this template as a step-by-step checklist during your initial engagement phase. Start with the 'Passive Gathering' nodes to build a profile, then move to 'Subdomains' and 'Cloud' discovery to expand your scope, ensuring you don't miss critical assets like 'S3 Buckets' or exposed 'JS Filles'.

Yes, the template is fully editable. You can add your own custom dorks to the 'Google Dorking' section, update tool flags in the 'Subdomains' branch, or insert new automation scripts into the 'Automated Scan' category to keep your methodology current with the latest cybersecurity trends.

The template suggests a multi-tool approach. By following the 'Subdomains' branch, you can combine passive results from 'crt.sh' with active enumeration using 'amass' and 'dnsenum', then use the provided 'subfinder' commands to consolidate your findings into a clean target list.

공유하고 싶은 템플릿이 있나요?

전 세계 크리에이터와 마인드맵 템플릿을 공유하고 작품으로 수익을 창출하세요.

무료 템플릿