NahamSec Methodology
Still working on it..
Target -> Subdomains -> IPs (Shodan & Censys) -> Portscan -> Ffuf
Google Dorks
site:target.com ext:php/jsp
site:target.com inurl:'&'
Shodan
target.com http.favicon.hash:12345678
ssl:target.com http.title:login
Last updated