Skip to content
← LibraryTechnique entry
W-RECON-GITHUB-DORKReconnaissance

GitHub / GitLab Dorking

Search public repos for org email, internal hostnames, JWT secrets, AWS keys, private keys.

§ Where this technique fits

W-RECON-GITHUB-DORK is catalogued under the Reconnaissance tactic of the offensive-security kill-chain. It appears in 14 approved dossiers in the registry, typically at step 1.1 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Valid Accounts
    T1078 · Initial Access
    seen 2×
  2. 02
    0ktapus SMS-Phish Sweep
    APT-OKTASS-0KTAPUS · Initial Access
    seen 1×
  3. 03
    Exploit Public-Facing Application
    T1190 · Initial Access
    seen 1×
  4. 04
    GitHub Personal Access Token Leak
    SAAS-GH-PAT-LEAK · Credential Access
    seen 1×
  5. 05
    Insider Admin-Panel Coercion (Twitter 2020)
    APT-INSIDER-PANEL · Initial Access
    seen 1×
  6. 06
    Package Maintainer Takeover
    SUP-PACKAGE-TAKEOVER · Initial Access
    seen 1×
  7. 07
    Pretexting
    SE-PRETEXT · Initial Access
    seen 1×
  8. 08
    Secret Echo to Build Log
    CI-SECRET-IN-LOG · Credential Access
    seen 1×