<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Bug-Bounty on Njeru Mtwaiti</title>
    <link>https://blog.njerumtwaiti.com/tags/bug-bounty/</link>
    <description>Recent content in Bug-Bounty on Njeru Mtwaiti</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Fri, 20 Jun 2025 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://blog.njerumtwaiti.com/tags/bug-bounty/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Web Recon Methodology: How I Map an Attack Surface</title>
      <link>https://blog.njerumtwaiti.com/posts/web-recon-methodology/</link>
      <pubDate>Fri, 20 Jun 2025 00:00:00 +0000</pubDate>
      <guid>https://blog.njerumtwaiti.com/posts/web-recon-methodology/</guid>
      <description>&lt;p&gt;Reconnaissance is where engagements are won or lost. The best exploit in the world is useless if you aimed it at the wrong target. This post breaks down my web recon process — what I run, in what order, and what I&amp;rsquo;m actually looking for.&lt;/p&gt;&#xA;&lt;h2 id=&#34;philosophy-first&#34;&gt;&#xA;  Philosophy First&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#philosophy-first&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Recon is not about running every tool you have. It&amp;rsquo;s about building an accurate mental model of the target:&lt;/p&gt;</description>
    </item>
    <item>
      <title>recon-toolkit</title>
      <link>https://blog.njerumtwaiti.com/projects/recon-toolkit/</link>
      <pubDate>Sat, 01 Mar 2025 00:00:00 +0000</pubDate>
      <guid>https://blog.njerumtwaiti.com/projects/recon-toolkit/</guid>
      <description>&lt;p&gt;A modular recon automation framework that chains together passive and active discovery techniques — subdomain brute-forcing, DNS resolution, HTTP probing, port scanning, and screenshot capture — into a single pipeline.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Features:&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Passive subdomain discovery via crt.sh, Shodan, and VirusTotal APIs&lt;/li&gt;&#xA;&lt;li&gt;Active DNS brute-force with custom wordlists&lt;/li&gt;&#xA;&lt;li&gt;HTTP service detection and technology fingerprinting&lt;/li&gt;&#xA;&lt;li&gt;Automated screenshot capture of live hosts&lt;/li&gt;&#xA;&lt;li&gt;Output to structured JSON and HTML reports&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;&lt;strong&gt;Tech:&lt;/strong&gt; Python, asyncio, aiohttp, dnspython, Shodan API&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
