Sponsored by

Compilation of recon workflows

Posted in Cheatsheets on March 25, 2019

Compilation of recon workflows

Hi, this is a compilation of recon workflows found online. Use it as inspiration for creating your own Web pentest / bug bounty recon workflow.

These are all the ones that I could find. So if yours is missing and you want to see it featured above too, please send it to [email protected].

I will update this every time I have a new flowchart or mindmap. So keep an eye on this page!

Lazyrecon’s workflow by @CaptMeelo

Source

Recon workflow found on Reddit

Source

Recon workflow by @rvismit

Source

Recon workflow by @rub003

Source

Recon workflow by @Aishee_Nguyen

Source

Assessment mindmap by @dsopas

Source

Autorecon’s workflow by JoshuaMart

Source

Recon steps by 0xpatrik

Source

Visual guide to recon by @NahamSec

Source

imran parray

Source

Domain footprinting by dnsdumpster.com

Source

Recon map by @_sehno_

Source

Recon summary by @Jhaddix

Source

OSINT domain name by @@TheGelios

Source

Source

WAHH Methodology desktop background by @Jhaddix

Source

AWS S3 recon flow

Source

Multiple worflows for recon automation by @mhmdiaa

Source

Input can be a domain, registrant name or registrant email:


Let me know if you have any comments, requests, questions… Feedback is always welcome.

See you next time!

Top