OSINT for Bug Bounty: Reconnaissance for Vulnerability Hunting
Master OSINT techniques for bug bounty hunting. Learn subdomain discovery, technology fingerprinting, email enumeration, infrastructure mapping, and how to use Maltego for bug bounty reconnaissance.
# OSINT for Bug Bounty: Reconnaissance for Vulnerability Hunting
Effective reconnaissance is the foundation of successful bug bounty hunting. The more you know about a target's infrastructure, the more attack surfaces you can identify. The sections below detail OSINT techniques specifically tailored for bug bounty programs, with focus on using [Maltego](/tools/maltego) for comprehensive reconnaissance.
Why OSINT Matters in Bug Bounty
Bug bounty rewards go to hunters who find vulnerabilities others miss. Thorough OSINT provides:
Reconnaissance Methodology
Phase 1: Scope Mapping
Before diving into tools, understand the program scope.
- What domains are in-scope?
- What subdomains are explicitly excluded?
- What testing is allowed?
- What is the reward structure?
- List all in-scope domains
- Note any exclusions
- Document allowed testing methods
- Record program-specific rules
- Create a dedicated workspace in [Maltego](/tools/maltego)
- Configure necessary API keys
- Prepare your testing tools
- Set up note-taking system
Phase 2: Subdomain Discovery
Subdomain enumeration is the most critical OSINT activity for bug bounty. More subdomains mean more potential attack surface.
Certificate Transparency (Free, No API Key)
Certificate transparency logs record all SSL/TLS certificates issued. This is one of the richest sources of subdomain data.
# Query crt.sh for certificate transparency data
curl -s "https://crt.sh/?q=%25.example.com&output=json" | jq -r '.[].name_value' | sort -u
# Using Maltego
# 1. Add Domain entity
# 2. Run "To Certificate (crt.sh)" transform
# 3. Results include subdomains from certificate SANs
Advantages:
Limitations:
Passive DNS (Free with limits)
Passive DNS databases store historical DNS resolution data.
# Using SecurityTrails (free tier: 50 requests/month)
# API request for subdomains
curl -s "https://api.securitytrails.com/v1/domain/example.com/subdomains" \
-H "APIKEY: your-api-key"
Google Dorking (Free)
Use search engine operators to find indexed subdomains.
# Find indexed subdomains
site:*.example.com -www
# Find login pages
site:*.example.com inurl:login
# Find admin panels
site:*.example.com inurl:admin
# Find API endpoints
site:*.example.com inurl:api
# Find documentation
site:*.example.com filetype:pdf OR filetype:doc
Amass (Free, Open Source)
OWASP Amass provides deep passive and active subdomain enumeration.
# Passive enumeration only (no direct target contact)
amass enum -passive -d example.com -o amass-passive.txt
# Active enumeration (requires authorization)
amass enum -active -d example.com -o amass-active.txt
# Brute force subdomain discovery
amass enum -brute -d example.com -o amass-brute.txt
# Using multiple data sources
amass enum -passive -d example.com -src
Maltego for Subdomain Discovery
[Maltego](/tools/maltego) automates subdomain discovery through transforms:
- To DNS Name - Full (comprehensive enumeration)
- To Certificate (crt.sh) (certificate transparency)
- To DNS Name (Brute Force) (dictionary-based)
Phase 3: Technology Fingerprinting
Knowing the technology stack helps identify potential vulnerabilities.
Web Technology Detection
# Using Wappalyzer (browser extension)
# Visit target site and run Wappalyzer
# Results include: Web server, CMS, frameworks, libraries
# Using WhatWeb (command line)
whatweb https://example.com
# Using Maltego
# 1. Add Website entity
# 2. Run "To Technology" transform
# 3. Identify frameworks, CMS, server software
Framework-Specific Enumeration
WordPress:
# Enumerate WordPress plugins
wpscan --url https://example.com --enumerate vp
# Enumerate WordPress users
wpscan --url https://example.com --enumerate u
# Check for vulnerable themes
wpscan --url https://example.com --enumerate vt
Laravel:
# Check for debug mode
curl -s https://example.com | grep -i "laravel"
# Check .env file exposure
curl -s https://example.com/.env
Spring Boot:
# Check Actuator endpoints
curl -s https://example.com/actuator
curl -s https://example.com/actuator/env
curl -s https://example.com/actuator/health
Phase 4: Email Enumeration
Email addresses are valuable for:
Email Discovery Tools
# theHarvester
theHarvester -d example.com -b all -f harvester-output.html
# holehe (email verification)
holehe example@email.com
# Maltego transforms
# 1. Add Domain entity
# 2. Run "To Email Address" transform
# 3. Results include discovered email addresses
Email Pattern Analysis
Analyze discovered emails to understand naming conventions:
| Pattern | Example | Format |
|---------|---------|--------|
| First.Last | john.doe@example.com | firstname.lastname@domain |
| FirstLast | johndoe@example.com | firstname.lastname@domain |
| First.Last | j.doe@example.com | initial.lastname@domain |
| FirstLast | john.d@example.com | firstname.initial@domain |
Understanding patterns allows you to:
Phase 5: Infrastructure Mapping
Map the complete infrastructure to identify all potential targets.
IP and Network Analysis
# Resolve all subdomains to IPs
for sub in $(cat subdomains.txt); do
echo "$sub: $(dig +short $sub | head -1)"
done | tee resolved-ips.txt
# Identify unique IP ranges
cat resolved-ips.txt | cut -d: -f2 | sort -u
# Check for cloud services
# AWS: Check for .amazonaws.com
# Azure: Check for .azurewebsites.net
# GCP: Check for .googleapis.com
Shodan for Service Discovery
# Query Shodan for services on discovered IPs
# (Requires API key)
# Using Maltego
# 1. Add IP Address entities
# 2. Run "Shodan IP" transform
# 3. Identify open services and banners
Phase 6: Hidden Content Discovery
Find hidden files, directories, and endpoints.
Directory Bruteforcing
# Using ffuf
ffuf -u https://example.com/FUZZ -w /path/to/wordlist.txt
# Using dirsearch
dirsearch -u https://example.com -e php,html,js
# Common paths to check
# /admin, /login, /api, /backup, /config
# /.git, /.env, /.htaccess
# /robots.txt, /sitemap.xml, /crossdomain.xml
JavaScript Analysis
# Extract URLs from JavaScript files
cat js-file.js | grep -oP 'https?://[^"\'\']+' | sort -u
# Check for API endpoints
cat js-file.js | grep -oP '/api/[^"\'\']+' | sort -u
# Look for secrets
cat js-file.js | grep -iE '(api[_-]?key|secret|token|password)'
Phase 7: Using Maltego for Bug Bounty Recon
[Maltego](/tools/maltego) provides a visual, automated approach to bug bounty reconnaissance.
Maltego Bug Bounty Workflow
- Add target domain as seed entity
- Create separate graphs for each investigation phase
- Run "To DNS Name - Full" transform
- Run "To Certificate (crt.sh)" transform
- Run "To DNS Name (Brute Force)" transform
- Merge and deduplicate results
- Select discovered IP addresses
- Run "Shodan IP" transform
- Identify open services and potential vulnerabilities
- Select discovered websites
- Run technology detection transforms
- Note frameworks and versions
- Run "To Email Address" transform on domain
- Analyze email patterns
- Identify high-value targets
- Color-code entities by risk level
- Add notes for interesting findings
- Export high-priority targets for testing
Maltego Custom Transforms for Bug Bounty
Create custom transforms for bug bounty-specific tasks:
# Custom transform for URL extraction
from maltego_trx.maltego import MaltegoTransform, MaltegoMsg
from maltego_trx.transform import DiscoverableTransform
import requests
class URLExtractorTransform(DiscoverableTransform):
@classmethod
def create_entities(cls, request: MaltegoMsg, response: MaltegoTransform):
website_url = request.Value
try:
# Fetch page content
r = requests.get(website_url, timeout=10)
# Extract URLs using regex
import re
urls = re.findall(r'https?://[^"\'\'>\s]+', r.text)
# Add unique URLs as entities
for url in set(urls):
entity = response.addEntity("maltego.Website", url)
entity.addProperty("url", "URL", "loose", url)
except Exception as e:
response.addException(str(e))
Bug Bounty Recon Checklist
Scope and Planning
Subdomain Discovery
Technology Fingerprinting
Email Enumeration
Infrastructure Mapping
Hidden Content
Analysis and Prioritization
Common Bug Bounty Targets
High-Value Subdomains
| Subdomain Pattern | Potential Value |
|-------------------|-----------------|
| admin.* | Administrative interfaces |
| staging.* | Development environments |
| dev.* | Development servers |
| api.* | API endpoints |
| mail.* | Email servers |
| vpn.* | VPN endpoints |
| internal.* | Internal tools |
| test.* | Testing environments |
| old.* | Deprecated services |
| legacy.* | Legacy applications |
High-Value Paths
| Path Pattern | Potential Value |
|-------------|-----------------|
| /admin | Administrative interface |
| /login | Authentication endpoints |
| /api | API endpoints |
| /graphql | GraphQL endpoints |
| /.env | Environment variables |
| /.git | Git repository |
| /backup | Backup files |
| /config | Configuration files |
| /debug | Debug information |
| /actuator | Spring Boot actuator |
Conclusion
OSINT is the foundation of successful bug bounty hunting. By systematically discovering subdomains, fingerprinting technologies, mapping infrastructure, and identifying hidden content, you can uncover vulnerabilities that automated scanners miss.
Tools like [Maltego](/tools/maltego) automate and visualize the reconnaissance process, allowing you to focus on analysis and vulnerability discovery. Combine Maltego's capabilities with command-line tools like Amass, theHarvester, and Shodan for comprehensive coverage.
Remember to always operate within program scope and rules. Document your methodology, prioritize your findings, and continuously expand your reconnaissance techniques. The best bug bounty hunters are those who can find attack surfaces that others overlook.
For related topics, explore [OSINT Investigation Workflow](/learn/osint-investigation-workflow) for structured methodology and [Maltego Transforms Explained](/learn/maltego-transforms-explained) for custom transform development.