- Public info gathering
- AIO Recon Tools
- Domain Enum
- Subdomain Enum
- Network Scanning
- Host Scanning
- Packet Scanning
- Recon Methodology (WiP)
- Files
- SSL/TLS
- Ports
- Web
- General Info
- Web Scanners
- Quick tricks
- Header injections
- Bruteforcing
- Online hashes cracked
- Crawl/Fuzz
- LFI/RFI
- Upload bypasses
- SQLi
- SSRF & Open Redirect
- XSS
- CSP
- XXE
- Cookie Padding
- Webshells
- CORS
- CSRF
- Web Cache Poisoning
- Broken Links
- Clickjacking
- HTTP Request Smuggling
- Web Sockets
- CRLF
- IDOR
- Web Cache Deception
- Session fixation
- Email attacks
- Pastejacking
- HTTP Parameter pollution
- SSTI
- Prototype Pollution
- Web Services
- Cloud