DNS Enumeration
DNS enumeration is the reconnaissance technique of collecting a target’s DNS information: A, AAAA, MX, NS, TXT and CNAME records, subdomains, mail servers and name servers. It reveals hosts and services an organization exposes to the internet, making it one of the first steps in OSINT and penetration testing.
Common techniques include querying records with dig, nslookup and host, checking for misconfigured zone transfers (AXFR), brute-forcing subdomains, and searching certificate transparency logs. Tools such as dnsrecon, dnsenum, Amass and Subfinder automate much of the work. Learn the full process in our complete guide to OSINT and attack surface mapping. Enumerate only domains you own or are authorized to test.
-
CPENT v2 Labs Manuals and Training
OSINT and Attack Surface Mapping: Complete Hands-On Guide
Quick answer: OSINT (open-source intelligence) is collecting publicly available information…
Read More »