HTB Cheatsheet

CommandDescription
dig ns DOMAIN @NAMESERVERNS request to the specific nameserver.
dig any DOMAIN @NAMESERVERANY request to the specific nameserver.
dig axfr DOMAIN @NAMESERVERAXFR request to the specific nameserver (Zone transfers).
for sub in $(cat /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-110000.txt);do dig $sub.inlanefreight.htb @10.129.14.128 | grep -v ';|SOA' | sed -r '/^\s*$/d' | grep $sub | tee -a subdomains.txt;doneManual subdomain brute forcing.
dnsenum --dnsserver NAMESERVER --enum -p 0 -s 0 -o found_subdomains.txt -f /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-110000.txt DOMAINSubdomain brute forcing.

You should check Footprinting Theory ๐ŸŒš to get further knowledge.