OSINT de seleção de alvo /⏳

Só leitura — não altera nada no alvo. Só em alvo seu ou autorizado por escrito.

Os passos

16.1 npx gitleaks detect --source . --report-path gitleaks-report.json (no repo) → encontra wrangler.jsonc + sbp_ ⏳. 16.2 crt.sh mensal + Wayback trimestral ✅ (hoje zerado). 16.3 Google dorks: site:DOMINIO inurl:admin · filetype:env|sql|log · intitle:"index of". Entregável: INVENTARIO-SUPERFICIE.md + /security.txt.

PurpleLab // plataforma de treino ofensivo + defensivo // Fase 1 — portal dinamico