โ† All cheat sheets

DMITRY

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

DMitry (Deepmagic Information Gathering Tool) performs passive and active
reconnaissance on a target host. It gathers subdomains, email addresses,
uptime info, TCP port scans, and whois lookups.

BASIC USAGE#

dmitry <target>                  # Basic run (default options)
dmitry -o output.txt <target>    # Save results to file

WHOIS LOOKUPS#

dmitry -w <target>               # Perform whois lookup on host
dmitry -i <target>               # Perform whois lookup on IP address
dmitry -wi <target>              # Both host and IP whois lookups

SUBDOMAIN ENUMERATION#

dmitry -s <target>               # Search for subdomains
dmitry -se <target>              # Search subdomains + email addresses

EMAIL HARVESTING#

dmitry -e <target>               # Search for email addresses
dmitry -se <target>              # Subdomains + email addresses

UPTIME INFORMATION#

dmitry -u <target>               # Retrieve Netcraft uptime data

PORT SCANNING#

dmitry -p <target>               # Perform TCP port scan
dmitry -p -f <target>            # Port scan with TCP/IP fingerprinting
dmitry -pb <target>              # Port scan with banner grabbing
dmitry -p -t 3 <target>          # Port scan with TTL set to 3 seconds

COMBINED SCANS#

dmitry -winsepo out.txt <target> # Full reconnaissance scan
dmitry -winsep <target>          # Full scan without saving to file
dmitry -ise <target>             # IP whois + subdomains + emails
dmitry -pb <target>              # Port scan with banners

OUTPUT OPTIONS#

dmitry -o report.txt <target>    # Save output to file
dmitry -o /path/report <target>  # Save to specific path

EXAMPLES#

# Full recon on a domain
dmitry -winsepo domain_report.txt example.com

# Quick subdomain and email harvest
dmitry -se example.com

# Port scan with banner grabbing
dmitry -pb 192.168.1.1

# Whois and uptime check
dmitry -wu example.com

NOTES#

- Requires root privileges for some scan types
- Uses Netcraft for uptime and host info
- Subdomain search uses search engines
- Port scan covers common ports by default
- Results can be combined for comprehensive recon