Systems Audit

Tooling & Methodology

This page documents the tools and frameworks used in the course of investigations. It is not exhaustive — some tools are withheld to protect operational security — but it represents the core stack.

Reconnaissance

  • subfinder — subdomain discovery
  • amass — attack surface mapping
  • assetfinder — related domains
  • httpx — probe verification

Domain Analysis

  • whois — registration records
  • dnsx — DNS enumeration
  • certificate transparency — crt.sh
  • waybackurls — historical snapshots

Document Intelligence

  • exiftool — metadata extraction
  • pdfid — PDF analysis
  • strings — embedded content
  • tesseract — OCR extraction

Network Mapping

  • nmap — port scanning
  • masscan — wide-scale discovery
  • shodan — internet census
  • censys — asset inventory

Verification

  • reverse image search — TinEye, Google
  • geolocation — Google Maps, Sentinel Hub
  • chronolocation — Wayback Machine
  • social media cross-referencing

Analysis

  • maltego — link analysis
  • spiderfoot — automation
  • maigret — username search
  • holehe — email verification