Prox OffensiveInformation Security
Free resource

Free DIY Recon Toolkit

A purpose index of the external reconnaissance tools and the 5-step methodology we use — for authorized assessments, education, and defensive research.

Authorized use only

The tools and techniques listed here are for authorized security assessments, education, and defensive research only. Never use them on systems without explicit written permission from the asset owner. Unauthorized security testing is illegal.

  • Unauthorized testing
  • Intrusive exploitation
  • Accessing sensitive data
  • Anything outside written scope / permission

Reconnaissance methodology

A simple 5-step flow for external recon.

1

OSINT

Passive information gathering

2

Network Mapping

Identify hosts and ports

3

Enumeration

Service fingerprinting

4

Discovery

Identify exposures

5

Analysis

Prioritize findings

Tools reference

A purpose index — no runnable syntax, just what each tool is for.

nmapNetwork

Port scanning and service fingerprinting

Use non-intrusive scanning and stay within authorized scope.

rustscanNetwork

Fast port scanning to support deeper enumeration

Use responsibly — avoid high-impact scan settings.

amassDNS

Subdomain enumeration and asset discovery

Combine passive sources with validated results.

dnsxDNS

DNS probing and validation of discovered hosts

Validate and deduplicate results.

theHarvesterOSINT

OSINT collection for emails, subdomains, and metadata

Prefer passive sources where possible.

crt.shOSINT

Certificate transparency search for subdomains and domains

Good starting point for passive discovery.

shodanOSINT

Internet-facing device and service exposure discovery

Useful for exposure validation and context.

whoisOSINT

Domain registration and ownership context

May help with asset ownership questions.

SpiderFootOSINT

Automated OSINT collection and correlation

Review results carefully for false positives.

recon-ngOSINT

Modular recon framework for data gathering

Great for structured collection.

nessusVuln Scanning

Vulnerability scanning and reporting support

Validate findings and avoid intrusive checks.

testssl.shTLS

SSL/TLS configuration analysis

Useful for identifying weak ciphers and misconfigurations.

Key considerations

Before you start

  • Obtain written authorization for all targets
  • Define scope boundaries clearly
  • Document your source IPs for the client SOC
  • Establish communication channels for critical findings
  • Agree on report format and delivery timeline

During the assessment

  • Stay within authorized scope
  • Log activities for evidence
  • Validate findings before reporting
  • Report validated critical issues within 24 hours through the agreed secure channel
  • Avoid intrusive or destructive testing

Want prioritized findings without the DIY?

For the External Exposure Audit Sprint, typical delivery is 3–5 business days after scope, prerequisites, and the start date are confirmed.