CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium
A penetration tester is performing reconnaissance against a target organization's web infrastructure. They have identified the main domain and want to find as many associated subdomains as possible without directly interacting with the target's DNS servers. They need a tool that can leverage various public data sources to achieve this passively. Which tool is best suited for this purpose?
- ANmap with `--script=dns-brute`
- BBurp Suite's 'Target' tab
- CMetasploit's 'auxiliary/gather/dns/dns_enum'
- DAmass
Show answer & explanationAnswer & explanation
Correct answer: D. Amass
Amass is a powerful and versatile open-source tool specifically designed for extensive passive subdomain enumeration. It gathers subdomain information from a multitude of public data sources like search engines, Certificate Transparency logs, WHOIS records, and more, without directly querying the target's DNS.
Why the other options are wrong
- A. Nmap's dns-brute script performs active brute-forcing of DNS, directly interacting with the target's DNS.
- B. Burp Suite's Target tab primarily maps the web application during active browsing, not for extensive passive subdomain discovery.
- C. Metasploit's dns_enum module performs active DNS enumeration and zone transfer attempts, which are not passive.
Amass for Subdomain Enumeration
An open-source tool used for extensive passive subdomain enumeration by collecting data from various public OSINT sources like search engines, CT logs, and WHOIS records.
- Aggregates data from many public sources.
- Performs passive subdomain discovery.
- Avoids direct interaction with target DNS servers.
- Highly effective for comprehensive subdomain mapping.
Memory trick: AMASS Many Subdomains Quietly