I'm in the throes of target host recon for another pentest, and thought I'd share some workflow / automation stuff.
In the past, I've discussed using historic DNS “mining” to collect target hosts in the domain.
http://news.poseidon-us.com/TTGNlJ
Related