Skip to content

Latest commit

Β 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

Web-Enumeration-Automation

A streamlined bash script designed to automate the initial reconnaissance and enumeration phases of a penetration test or bug bounty hunt. This script ties together popular command-line tools to discover subdomains, filter for active hosts, and perform basic port scanning.

πŸš€ Features

  • Automated Directory Structuring: Automatically creates organized folders for your target to keep scan results tidy.
  • Subdomain Harvesting: Uses assetfinder to quickly gather potential subdomains.
  • Alive Host Probing: Filters the gathered subdomains with httprobe to identify which hosts are actively responding on HTTPS (port 443).
  • Port Scanning: Passes the live hosts to nmap for a rapid initial port scan.
  • (Optional/Commented): Built-in hooks for amass if you want to expand subdomain discovery.

πŸ› οΈ Prerequisites

Ensure you have the following tools installed and accessible in your system's $PATH:

πŸ“₯ Installation

  1. Clone the repository:
    git clone [https://github.com/SureshDeora/Web-Enumeration-Automation.git](https://github.com/SureshDeora/Web-Enumeration-Automation.git)
    
    Navigate to the directory:
    

Bash cd Web-Enumeration-Automation Make the script executable:

Bash chmod +x run.sh πŸ’» Usage Run the script by passing the target domain as an argument:

Bash ./run.sh example.com πŸ“‚ Output Structure When you run the script against example.com, it generates the following directory structure in your current working directory:

Plaintext example.com/ └── recon/ β”œβ”€β”€ final.txt # Final list of raw subdomains β”œβ”€β”€ httprobe/ β”‚ └── alive.txt # List of active subdomains (HTTPS) └── scans/ β”œβ”€β”€ scanned.txt.nmap # Nmap scan output files β”œβ”€β”€ scanned.txt.gnmap └── scanned.txt.xml βš™οΈ How It Works (Under the Hood) Initialization: Checks if a directory for the target domain exists; if not, creates one along with a recon/ subdirectory.

Subdomain Enumeration: Runs assetfinder against the target and greps for the domain to filter out noise.

Probing: Pipes the sorted, unique subdomains into httprobe to check for active connections on port 443, stripping the protocol headers for clean IP/domain lists.

Scanning: Uses nmap -T4 against the active hosts to quickly identify open ports and outputs the results in all formats (-oA).

⚠️ Disclaimer This tool is intended for educational purposes, bug bounty hunting, and authorized penetration testing only. Do not run this script against targets you do not have explicit permission to test.

About

Web Enumeration Automation with Bash Scripting

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages