Subfinder:
subfinder -d tcm-sec.comassetfinder:
assetfinder tcm-sec.com
#to save it to an output file:
assetfinder tcm-sec.com > tcm-sec.txtto count how many assetfinder found in that text file:
wc -l tcm-sec.txt(this is EL not EYE)
find admin links:
cat tcm-sec.txt | grep admcould also look for:
- api, vpn, cpanel, dev
amass:
amass enum -d tcm-sec.comhttprobe:
cat tcm-sec.txt | httprobe -s -p https:443gowitness:
grab the alive links and put them in txt then:
ctrl+R
https://
#spam click replace until red
:443
#samecommand line kung fu:
Run it:
gowitness file -f ./tcm-secS.txt -P domainpicsyuh --no-http