Skip to content
← LibraryTechnique entry
W-RECON-DIRBRUTEReconnaissance

Directory & File Bruteforce

feroxbuster / ffuf / gobuster against likely paths and extensions. Finds /admin, /backup.sql, /.git, /.env.

§ Where this technique fits

W-RECON-DIRBRUTE is catalogued under the Reconnaissance tactic of the offensive-security kill-chain. It appears in 3 approved dossiers in the registry, typically at step 2 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Debug / Admin Endpoint Exposed
    W-DEBUG-ENDPOINT · Discovery
    seen 1×
  2. 02
    JavaScript Source Map Exposure
    W-RECON-SOURCEMAP · Reconnaissance
    seen 1×
  3. 03
    Tech Stack Fingerprinting
    W-RECON-FINGERPRINT · Reconnaissance
    seen 1×