Skip to content
← LibraryTechnique entry
W-RECON-FINGERPRINTReconnaissance

Tech Stack Fingerprinting

Identify frameworks, CMS, server, JS libs via headers, cookies, error pages, /robots.txt — Wappalyzer / WhatWeb.

§ Where this technique fits

W-RECON-FINGERPRINT is catalogued under the Reconnaissance tactic of the offensive-security kill-chain. It appears in 28 approved dossiers in the registry, typically at step 1.1 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    API Endpoint Discovery
    W-RECON-API-DISCO · Reconnaissance
    seen 1×
  2. 02seen 1×
  3. 03
    Atlassian Confluence / Jira RCE
    SAAS-ATLAS-CVE · Initial Access
    seen 1×
  4. 04
    CDN Origin Bypass
    CDN-ORIGIN-BYPASS · Defense Evasion
    seen 1×
  5. 05
    Citrix Bleed (CVE-2023-4966)
    VPN-CITRIX-BLEED · Credential Access
    seen 1×
  6. 06
    Cross-Chain Bridge Exploit
    W3-BRIDGE-EXPLOIT · Impact
    seen 1×
  7. 07
    DMARC Bypass (p=none / sub-policy)
    EM-DMARC-BYPASS · Initial Access
    seen 1×
  8. 08
    Deserialization — Java (ysoserial)
    W-DESER-JAVA · Execution
    seen 1×