Systems Audit
Tooling & Methodology
This page documents the tools and frameworks used in the course of investigations. It is not exhaustive — some tools are withheld to protect operational security — but it represents the core stack.
Reconnaissance
- subfinder — subdomain discovery
- amass — attack surface mapping
- assetfinder — related domains
- httpx — probe verification
Domain Analysis
- whois — registration records
- dnsx — DNS enumeration
- certificate transparency — crt.sh
- waybackurls — historical snapshots
Document Intelligence
- exiftool — metadata extraction
- pdfid — PDF analysis
- strings — embedded content
- tesseract — OCR extraction
Network Mapping
- nmap — port scanning
- masscan — wide-scale discovery
- shodan — internet census
- censys — asset inventory
Verification
- reverse image search — TinEye, Google
- geolocation — Google Maps, Sentinel Hub
- chronolocation — Wayback Machine
- social media cross-referencing
Analysis
- maltego — link analysis
- spiderfoot — automation
- maigret — username search
- holehe — email verification