DNS Enumeration
MITRE ATT&CK™ Gather Victim Network Information: DNS - T1590.002
Theory
Practice
# Simple DNS resolution
dig domain.com
#Enum records
dig MX domain.com
dig NS domain.com
dig A domain.com
dig txt domain.com
dig AAAA domain.com
#If supported by the DNS server, we can use the ANY query and dump all records
dig any domain.com
#Zone transfert
dig axfr domain.com @ns.domain.com# Simple DNS resolution
host domain.com
# Enum records
host -t MX www.domain.com
host -t NS domain.com
host -t A domain.com
host -t txt domain.com
host -t AAAA domain.com
# Reverse DNS
# Works if the DNS is configured with a PTR record
host 149.56.244.87
# Bash script reverse DNS lookup an IP addresses range
for ip in $(seq 200 254); do host 51.222.169.$ip; done | grep -v "not found"Ressource
Last updated