GO KALI FREE
IntermediateBug Bounty

OSINT for Bug Bounty: Reconnaissance for Vulnerability Hunting

Master OSINT techniques for bug bounty hunting. Learn subdomain discovery, technology fingerprinting, email enumeration, infrastructure mapping, and how to use Maltego for bug bounty reconnaissance.

#bug-bounty#osint#reconnaissance#subdomain-discovery#maltego#vulnerability-hunting

# OSINT for Bug Bounty: Reconnaissance for Vulnerability Hunting

Effective reconnaissance is the foundation of successful bug bounty hunting. The more you know about a target's infrastructure, the more attack surfaces you can identify. The sections below detail OSINT techniques specifically tailored for bug bounty programs, with focus on using [Maltego](/tools/maltego) for comprehensive reconnaissance.

Why OSINT Matters in Bug Bounty

Bug bounty rewards go to hunters who find vulnerabilities others miss. Thorough OSINT provides:

  • **Expanded Attack Surface**: Discover forgotten or poorly maintained assets
  • **Context Understanding**: Know the technology stack and architecture
  • **Prioritization**: Focus on high-value, potentially vulnerable targets
  • **Edge Over Competition**: Find assets that automated scanners miss
  • **Compliance**: Stay within program scope and rules
  • Reconnaissance Methodology

    Phase 1: Scope Mapping

    Before diving into tools, understand the program scope.

  • **Read the Program Rules**:
  • - What domains are in-scope?

    - What subdomains are explicitly excluded?

    - What testing is allowed?

    - What is the reward structure?

  • **Create a Scope Document**:
  • - List all in-scope domains

    - Note any exclusions

    - Document allowed testing methods

    - Record program-specific rules

  • **Set Up Your Environment**:
  • - Create a dedicated workspace in [Maltego](/tools/maltego)

    - Configure necessary API keys

    - Prepare your testing tools

    - Set up note-taking system

    Phase 2: Subdomain Discovery

    Subdomain enumeration is the most critical OSINT activity for bug bounty. More subdomains mean more potential attack surface.

    Certificate Transparency (Free, No API Key)

    Certificate transparency logs record all SSL/TLS certificates issued. This is one of the richest sources of subdomain data.

    # Query crt.sh for certificate transparency data
    curl -s "https://crt.sh/?q=%25.example.com&output=json" | jq -r '.[].name_value' | sort -u
    
    # Using Maltego
    # 1. Add Domain entity
    # 2. Run "To Certificate (crt.sh)" transform
    # 3. Results include subdomains from certificate SANs
    

    Advantages:

  • No API key required
  • Historical data available
  • Often finds subdomains missed by DNS enumeration
  • Updated in near real-time
  • Limitations:

  • Only finds subdomains that have had SSL certificates
  • May include expired or revoked certificates
  • Can include third-party services
  • Passive DNS (Free with limits)

    Passive DNS databases store historical DNS resolution data.

    # Using SecurityTrails (free tier: 50 requests/month)
    # API request for subdomains
    curl -s "https://api.securitytrails.com/v1/domain/example.com/subdomains" \
      -H "APIKEY: your-api-key"
    

    Google Dorking (Free)

    Use search engine operators to find indexed subdomains.

    # Find indexed subdomains
    site:*.example.com -www
    
    # Find login pages
    site:*.example.com inurl:login
    
    # Find admin panels
    site:*.example.com inurl:admin
    
    # Find API endpoints
    site:*.example.com inurl:api
    
    # Find documentation
    site:*.example.com filetype:pdf OR filetype:doc
    

    Amass (Free, Open Source)

    OWASP Amass provides deep passive and active subdomain enumeration.

    # Passive enumeration only (no direct target contact)
    amass enum -passive -d example.com -o amass-passive.txt
    
    # Active enumeration (requires authorization)
    amass enum -active -d example.com -o amass-active.txt
    
    # Brute force subdomain discovery
    amass enum -brute -d example.com -o amass-brute.txt
    
    # Using multiple data sources
    amass enum -passive -d example.com -src
    

    Maltego for Subdomain Discovery

    [Maltego](/tools/maltego) automates subdomain discovery through transforms:

  • **Add Seed Entity**: Create a Domain entity for the target
  • **Run Transforms**:
  • - To DNS Name - Full (comprehensive enumeration)

    - To Certificate (crt.sh) (certificate transparency)

    - To DNS Name (Brute Force) (dictionary-based)

  • **Expand Results**: Run additional transforms on discovered subdomains
  • **Analyze**: Identify patterns and high-value targets
  • Phase 3: Technology Fingerprinting

    Knowing the technology stack helps identify potential vulnerabilities.

    Web Technology Detection

    # Using Wappalyzer (browser extension)
    # Visit target site and run Wappalyzer
    # Results include: Web server, CMS, frameworks, libraries
    
    # Using WhatWeb (command line)
    whatweb https://example.com
    
    # Using Maltego
    # 1. Add Website entity
    # 2. Run "To Technology" transform
    # 3. Identify frameworks, CMS, server software
    

    Framework-Specific Enumeration

    WordPress:

    # Enumerate WordPress plugins
    wpscan --url https://example.com --enumerate vp
    
    # Enumerate WordPress users
    wpscan --url https://example.com --enumerate u
    
    # Check for vulnerable themes
    wpscan --url https://example.com --enumerate vt
    

    Laravel:

    # Check for debug mode
    curl -s https://example.com | grep -i "laravel"
    
    # Check .env file exposure
    curl -s https://example.com/.env
    

    Spring Boot:

    # Check Actuator endpoints
    curl -s https://example.com/actuator
    curl -s https://example.com/actuator/env
    curl -s https://example.com/actuator/health
    

    Phase 4: Email Enumeration

    Email addresses are valuable for:

  • Password reset attacks
  • Social engineering (with authorization)
  • Account takeover attempts
  • Identifying employees and roles
  • Email Discovery Tools

    # theHarvester
    theHarvester -d example.com -b all -f harvester-output.html
    
    # holehe (email verification)
    holehe example@email.com
    
    # Maltego transforms
    # 1. Add Domain entity
    # 2. Run "To Email Address" transform
    # 3. Results include discovered email addresses
    

    Email Pattern Analysis

    Analyze discovered emails to understand naming conventions:

    | Pattern | Example | Format |

    |---------|---------|--------|

    | First.Last | john.doe@example.com | firstname.lastname@domain |

    | FirstLast | johndoe@example.com | firstname.lastname@domain |

    | First.Last | j.doe@example.com | initial.lastname@domain |

    | FirstLast | john.d@example.com | firstname.initial@domain |

    Understanding patterns allows you to:

  • Predict other employees' email addresses
  • Create targeted wordlists
  • Identify email verification bypasses
  • Phase 5: Infrastructure Mapping

    Map the complete infrastructure to identify all potential targets.

    IP and Network Analysis

    # Resolve all subdomains to IPs
    for sub in $(cat subdomains.txt); do
        echo "$sub: $(dig +short $sub | head -1)"
    done | tee resolved-ips.txt
    
    # Identify unique IP ranges
    cat resolved-ips.txt | cut -d: -f2 | sort -u
    
    # Check for cloud services
    # AWS: Check for .amazonaws.com
    # Azure: Check for .azurewebsites.net
    # GCP: Check for .googleapis.com
    

    Shodan for Service Discovery

    # Query Shodan for services on discovered IPs
    # (Requires API key)
    
    # Using Maltego
    # 1. Add IP Address entities
    # 2. Run "Shodan IP" transform
    # 3. Identify open services and banners
    

    Phase 6: Hidden Content Discovery

    Find hidden files, directories, and endpoints.

    Directory Bruteforcing

    # Using ffuf
    ffuf -u https://example.com/FUZZ -w /path/to/wordlist.txt
    
    # Using dirsearch
    dirsearch -u https://example.com -e php,html,js
    
    # Common paths to check
    # /admin, /login, /api, /backup, /config
    # /.git, /.env, /.htaccess
    # /robots.txt, /sitemap.xml, /crossdomain.xml
    

    JavaScript Analysis

    # Extract URLs from JavaScript files
    cat js-file.js | grep -oP 'https?://[^"\'\']+' | sort -u
    
    # Check for API endpoints
    cat js-file.js | grep -oP '/api/[^"\'\']+' | sort -u
    
    # Look for secrets
    cat js-file.js | grep -iE '(api[_-]?key|secret|token|password)' 
    

    Phase 7: Using Maltego for Bug Bounty Recon

    [Maltego](/tools/maltego) provides a visual, automated approach to bug bounty reconnaissance.

    Maltego Bug Bounty Workflow

  • **Create Investigation Graph**:
  • - Add target domain as seed entity

    - Create separate graphs for each investigation phase

  • **Subdomain Enumeration**:
  • - Run "To DNS Name - Full" transform

    - Run "To Certificate (crt.sh)" transform

    - Run "To DNS Name (Brute Force)" transform

    - Merge and deduplicate results

  • **Service Discovery**:
  • - Select discovered IP addresses

    - Run "Shodan IP" transform

    - Identify open services and potential vulnerabilities

  • **Technology Fingerprinting**:
  • - Select discovered websites

    - Run technology detection transforms

    - Note frameworks and versions

  • **Email Discovery**:
  • - Run "To Email Address" transform on domain

    - Analyze email patterns

    - Identify high-value targets

  • **Analysis and Prioritization**:
  • - Color-code entities by risk level

    - Add notes for interesting findings

    - Export high-priority targets for testing

    Maltego Custom Transforms for Bug Bounty

    Create custom transforms for bug bounty-specific tasks:

    # Custom transform for URL extraction
    from maltego_trx.maltego import MaltegoTransform, MaltegoMsg
    from maltego_trx.transform import DiscoverableTransform
    import requests
    
    class URLExtractorTransform(DiscoverableTransform):
        @classmethod
        def create_entities(cls, request: MaltegoMsg, response: MaltegoTransform):
            website_url = request.Value
            
            try:
                # Fetch page content
                r = requests.get(website_url, timeout=10)
                
                # Extract URLs using regex
                import re
                urls = re.findall(r'https?://[^"\'\'>\s]+', r.text)
                
                # Add unique URLs as entities
                for url in set(urls):
                    entity = response.addEntity("maltego.Website", url)
                    entity.addProperty("url", "URL", "loose", url)
                    
            except Exception as e:
                response.addException(str(e))
    

    Bug Bounty Recon Checklist

    Scope and Planning

  • [ ] Read program rules and scope
  • [ ] Create scope document
  • [ ] Set up investigation workspace
  • [ ] Configure tools and API keys
  • Subdomain Discovery

  • [ ] Certificate transparency (crt.sh)
  • [ ] Passive DNS enumeration
  • [ ] Amass passive enumeration
  • [ ] Amass active enumeration (if allowed)
  • [ ] Google dorking
  • [ ] Maltego transforms
  • Technology Fingerprinting

  • [ ] Web server identification
  • [ ] CMS detection
  • [ ] Framework identification
  • [ ] JavaScript library analysis
  • [ ] Cloud service detection
  • Email Enumeration

  • [ ] Email address discovery
  • [ ] Email pattern analysis
  • [ ] High-value target identification
  • Infrastructure Mapping

  • [ ] IP address resolution
  • [ ] Network range identification
  • [ ] Cloud infrastructure mapping
  • [ ] Service discovery (Shodan)
  • Hidden Content

  • [ ] Directory bruteforcing
  • [ ] File discovery
  • [ ] JavaScript analysis
  • [ ] API endpoint discovery
  • [ ] Backup file detection
  • Analysis and Prioritization

  • [ ] Identify high-value targets
  • [ ] Note potential vulnerabilities
  • [ ] Create testing plan
  • [ ] Document methodology
  • Common Bug Bounty Targets

    High-Value Subdomains

    | Subdomain Pattern | Potential Value |

    |-------------------|-----------------|

    | admin.* | Administrative interfaces |

    | staging.* | Development environments |

    | dev.* | Development servers |

    | api.* | API endpoints |

    | mail.* | Email servers |

    | vpn.* | VPN endpoints |

    | internal.* | Internal tools |

    | test.* | Testing environments |

    | old.* | Deprecated services |

    | legacy.* | Legacy applications |

    High-Value Paths

    | Path Pattern | Potential Value |

    |-------------|-----------------|

    | /admin | Administrative interface |

    | /login | Authentication endpoints |

    | /api | API endpoints |

    | /graphql | GraphQL endpoints |

    | /.env | Environment variables |

    | /.git | Git repository |

    | /backup | Backup files |

    | /config | Configuration files |

    | /debug | Debug information |

    | /actuator | Spring Boot actuator |

    Conclusion

    OSINT is the foundation of successful bug bounty hunting. By systematically discovering subdomains, fingerprinting technologies, mapping infrastructure, and identifying hidden content, you can uncover vulnerabilities that automated scanners miss.

    Tools like [Maltego](/tools/maltego) automate and visualize the reconnaissance process, allowing you to focus on analysis and vulnerability discovery. Combine Maltego's capabilities with command-line tools like Amass, theHarvester, and Shodan for comprehensive coverage.

    Remember to always operate within program scope and rules. Document your methodology, prioritize your findings, and continuously expand your reconnaissance techniques. The best bug bounty hunters are those who can find attack surfaces that others overlook.

    For related topics, explore [OSINT Investigation Workflow](/learn/osint-investigation-workflow) for structured methodology and [Maltego Transforms Explained](/learn/maltego-transforms-explained) for custom transform development.

    Frequently Asked Questions

    Why is OSINT important for bug bounty hunting?

    Thorough OSINT expands your attack surface discovery, reveals forgotten or poorly maintained assets, helps understand the technology stack, prioritizes high-value targets, and gives you an edge over hunters who rely only on automated scanners.

    What is the most critical OSINT activity for bug bounty?

    Subdomain enumeration is the most critical OSINT activity. More subdomains mean more potential attack surface. Use certificate transparency logs (crt.sh), Sublist3r, Amass, and Maltego to discover as many subdomains as possible.

    What are certificate transparency logs?

    Certificate transparency logs record all SSL/TLS certificates issued by certificate authorities. Query crt.sh to find subdomains that have been issued certificates, revealing infrastructure that may not appear in DNS records or web searches.

    How do you discover subdomains for bug bounty?

    Use multiple methods: certificate transparency (crt.sh), DNS brute-forcing (Sublist3r, Amass), passive sources (VirusTotal, Shodan), web crawling, and Maltego transforms. Combining methods reveals more subdomains than any single tool.

    What is technology fingerprinting?

    Technology fingerprinting identifies the software, frameworks, and services running on target systems. Use Wappalyzer, BuiltWith, or WhatWeb to detect CMS versions, JavaScript frameworks, server software, and analytics tools that may have known vulnerabilities.

    How do you enumerate email addresses for bug bounty?

    Use theHarvester to collect emails from public sources, check LinkedIn profiles, search certificate transparency logs, examine WHOIS records, and use Maltego's email transforms. Email patterns help understand internal naming conventions and potentially reveal valid accounts.

    What is infrastructure mapping in bug bounty?

    Infrastructure mapping identifies IP ranges, cloud providers, CDN configurations, and hosting arrangements for the target. Use Shodan, BGP data, ASN lookups, and reverse DNS to understand how the target's systems are organized and interconnected.

    How do you stay within bug bounty scope?

    Read program rules carefully, create a scope document listing all in-scope and out-of-scope assets, use only authorized testing methods, avoid accessing other users' data, and document everything for legal protection if issues arise.

    What tools complement Maltego for bug bounty OSINT?

    Essential tools include Sublist3r and Amass for subdomain discovery, Shodan for service scanning, Wappalyzer for technology detection, theHarvester for email enumeration, and ffuf or Gobuster for directory fuzzing on discovered subdomains.

    How does OSINT give you an edge over other hunters?

    OSINT reveals assets that automated scanners miss: forgotten subdomains, legacy applications, staging environments, API endpoints, and third-party integrations. Manual OSINT often discovers vulnerabilities in overlooked assets that mass scanners skip.