From 5ebe67da837277074089408cca4c3c17158023e8 Mon Sep 17 00:00:00 2001 From: Tib3rius <48113936+Tib3rius@users.noreply.github.com> Date: Sun, 29 May 2022 21:06:23 -0400 Subject: [PATCH] Updated Usage (markdown) --- Usage.md | 88 ++++++++++++++++++++++++++++++-------------------------- 1 file changed, 47 insertions(+), 41 deletions(-) diff --git a/Usage.md b/Usage.md index a9a3f26..9648121 100644 --- a/Usage.md +++ b/Usage.md @@ -8,20 +8,19 @@ usage: autorecon [-t TARGET_FILE] [-p PORTS] [-m MAX_SCANS] [-mp MAX_PORT_SCANS] [--only-scans-dir] [--no-port-dirs] [--heartbeat HEARTBEAT] [--timeout TIMEOUT] [--target-timeout TARGET_TIMEOUT] [--nmap NMAP | --nmap-append NMAP_APPEND] [--proxychains] [--disable-sanity-checks] [--disable-keyboard-control] - [--force-services SERVICE [SERVICE ...]] [--accessible] [-v] [--version] - [--subdomain-enum.domain VALUE] [--subdomain-enum.wordlist VALUE [VALUE ...]] - [--subdomain-enum.threads VALUE] [--curl.path VALUE] - [--dirbuster.tool {feroxbuster,gobuster,dirsearch,ffuf,dirb}] + [--force-services SERVICE [SERVICE ...]] [-mpti PLUGIN:NUMBER [PLUGIN:NUMBER ...]] + [-mpgi PLUGIN:NUMBER [PLUGIN:NUMBER ...]] [--accessible] [-v] [--version] + [--curl.path VALUE] [--dirbuster.tool {feroxbuster,gobuster,dirsearch,ffuf,dirb}] [--dirbuster.wordlist VALUE [VALUE ...]] [--dirbuster.threads VALUE] - [--dirbuster.ext VALUE] [--vhost-enum.hostname VALUE] + [--dirbuster.ext VALUE] [--dirbuster.recursive] [--onesixtyone.community-strings VALUE] + [--subdomain-enum.domain VALUE] [--subdomain-enum.wordlist VALUE [VALUE ...]] + [--subdomain-enum.threads VALUE] [--vhost-enum.hostname VALUE] [--vhost-enum.wordlist VALUE [VALUE ...]] [--vhost-enum.threads VALUE] - [--wpscan.api-token VALUE] [--onesixtyone.community-strings VALUE] - [--global.username-wordlist VALUE] [--global.password-wordlist VALUE] - [--global.domain VALUE] [-h] + [--wpscan.api-token VALUE] [--global.username-wordlist VALUE] + [--global.password-wordlist VALUE] [--global.domain VALUE] [-h] [targets ...] -Network reconnaissance tool to port scan and automatically enumerate services found on multiple -targets. +Network reconnaissance tool to port scan and automatically enumerate services found on multiple targets. positional arguments: targets IP addresses (e.g. 10.0.0.1), CIDR notation (e.g. 10.0.0.1/24), or resolvable @@ -32,8 +31,8 @@ optional arguments: Read targets from file. -p PORTS, --ports PORTS Comma separated list of ports / port ranges to scan. Specify TCP/UDP ports by - prepending list with T:/U: To scan both TCP/UDP, put port(s) at start or - specify B: e.g. 53,T:21-25,80,U:123,B:123. Default: None + prepending list with T:/U: To scan both TCP/UDP, put port(s) at start or specify + B: e.g. 53,T:21-25,80,U:123,B:123. Default: None -m MAX_SCANS, --max-scans MAX_SCANS The maximum number of concurrent scans to run. Default: 50 -mp MAX_PORT_SCANS, --max-port-scans MAX_PORT_SCANS @@ -47,28 +46,28 @@ optional arguments: ~/.config/AutoRecon/global.toml --tags TAGS Tags to determine which plugins should be included. Separate tags by a plus symbol (+) to group tags together. Separate groups with a comma (,) to create - multiple groups. For a plugin to be included, it must have all the tags - specified in at least one group. Default: default + multiple groups. For a plugin to be included, it must have all the tags specified + in at least one group. Default: default --exclude-tags TAGS Tags to determine which plugins should be excluded. Separate tags by a plus symbol (+) to group tags together. Separate groups with a comma (,) to create - multiple groups. For a plugin to be excluded, it must have all the tags - specified in at least one group. Default: None + multiple groups. For a plugin to be excluded, it must have all the tags specified + in at least one group. Default: None --port-scans PLUGINS Override --tags / --exclude-tags for the listed PortScan plugins (comma separated). Default: None --service-scans PLUGINS Override --tags / --exclude-tags for the listed ServiceScan plugins (comma separated). Default: None - --reports PLUGINS Override --tags / --exclude-tags for the listed Report plugins (comma - separated). Default: None + --reports PLUGINS Override --tags / --exclude-tags for the listed Report plugins (comma separated). + Default: None --plugins-dir PLUGINS_DIR The location of the plugins directory. Default: ~/.config/AutoRecon/plugins --add-plugins-dir PLUGINS_DIR - The location of an additional plugins directory to add to the main one. - Default: None + The location of an additional plugins directory to add to the main one. Default: + None -l [TYPE], --list [TYPE] - List all plugins or plugins of a specific type. e.g. --list, --list port, - --list service + List all plugins or plugins of a specific type. e.g. --list, --list port, --list + service -o OUTPUT, --output OUTPUT The output directory for results. Default: results --single-target Only scan a single target. A directory named after the target will not be @@ -76,11 +75,11 @@ optional arguments: directory. Default: False --only-scans-dir Only create the "scans" directory for results. Other directories (e.g. exploit, loot, report) will not be created. Default: False - --no-port-dirs Don't create directories for ports (e.g. scans/tcp80, scans/udp53). Instead - store all results in the "scans" directory itself. Default: False + --no-port-dirs Don't create directories for ports (e.g. scans/tcp80, scans/udp53). Instead store + all results in the "scans" directory itself. Default: False --heartbeat HEARTBEAT - Specifies the heartbeat interval (in seconds) for scan status messages. - Default: 60 + Specifies the heartbeat interval (in seconds) for scan status messages. Default: + 60 --timeout TIMEOUT Specifies the maximum amount of time in minutes that AutoRecon should run for. Default: None --target-timeout TARGET_TIMEOUT @@ -98,6 +97,12 @@ optional arguments: --force-services SERVICE [SERVICE ...] A space separated list of services in the following style: tcp/80/http tcp/443/https/secure + -mpti PLUGIN:NUMBER [PLUGIN:NUMBER ...], --max-plugin-target-instances PLUGIN:NUMBER [PLUGIN:NUMBER ...] + A space separated list of plugin slugs with the max number of instances (per + target) in the following style: nmap-http:2 dirbuster:1. Default: None + -mpgi PLUGIN:NUMBER [PLUGIN:NUMBER ...], --max-plugin-global-instances PLUGIN:NUMBER [PLUGIN:NUMBER ...] + A space separated list of plugin slugs with the max number of global instances in + the following style: nmap-http:2 dirbuster:1. Default: None --accessible Attempts to make AutoRecon output more accessible to screenreaders. Default: False -v, --verbose Enable verbose output. Repeat for more verbosity. @@ -107,15 +112,6 @@ optional arguments: plugin arguments: These are optional arguments for certain plugins. - --subdomain-enum.domain VALUE - The domain to use as the base domain (e.g. example.com) for subdomain - enumeration. Default: None - --subdomain-enum.wordlist VALUE [VALUE ...] - The wordlist(s) to use when enumerating subdomains. Separate multiple wordlists - with spaces. Default: ['/usr/share/seclists/Discovery/DNS/subdomains- - top1million-110000.txt'] - --subdomain-enum.threads VALUE - The number of threads to use when enumerating subdomains. Default: 10 --curl.path VALUE The path on the web server to curl. Default: / --dirbuster.tool {feroxbuster,gobuster,dirsearch,ffuf,dirb} The tool to use for directory busting. Default: feroxbuster @@ -127,6 +123,21 @@ plugin arguments: --dirbuster.ext VALUE The extensions you wish to fuzz (no dot, comma separated). Default: txt,html,php,asp,aspx,jsp + --dirbuster.recursive + Enables recursive searching (where available). Warning: This may cause + significant increases to scan times. Default: False + --onesixtyone.community-strings VALUE + The file containing a list of community strings to try. Default: + /usr/share/seclists/Discovery/SNMP/common-snmp-community-strings-onesixtyone.txt + --subdomain-enum.domain VALUE + The domain to use as the base domain (e.g. example.com) for subdomain + enumeration. Default: None + --subdomain-enum.wordlist VALUE [VALUE ...] + The wordlist(s) to use when enumerating subdomains. Separate multiple wordlists + with spaces. Default: ['/usr/share/seclists/Discovery/DNS/subdomains- + top1million-110000.txt'] + --subdomain-enum.threads VALUE + The number of threads to use when enumerating subdomains. Default: 10 --vhost-enum.hostname VALUE The hostname to use as the base host (e.g. example.com) for virtual host enumeration. Default: None @@ -138,10 +149,6 @@ plugin arguments: The number of threads to use when enumerating virtual hosts. Default: 10 --wpscan.api-token VALUE An API Token from wpvulndb.com to help search for more vulnerabilities. - --onesixtyone.community-strings VALUE - The file containing a list of community strings to try. Default: - /usr/share/seclists/Discovery/SNMP/common-snmp-community-strings- - onesixtyone.txt global plugin arguments: These are optional arguments that can be used by all plugins. @@ -153,8 +160,7 @@ global plugin arguments: A wordlist of passwords, useful for bruteforcing. Default: /usr/share/seclists/Passwords/darkweb2017-top100.txt --global.domain VALUE - The domain to use (if known). Used for DNS and/or Active Directory. Default: - None + The domain to use (if known). Used for DNS and/or Active Directory. Default: None ``` ## Targets / Target Files