The invention provides a method for information investigation and penetration testing based on
workflow, and relates to the technical field of
computer software information. Based on the
workflow, the method realizes the detection, filtering and de-duplication of the
domain name, IP, IP port, URL and
fingerprint of the
test target through the information detection pipeline and the
penetration test pipeline, and conducts information detection and penetration testing for various vulnerabilities. The information detection pipeline is used to detect the information of the input target. Through the input IP and URL, the IP, URL, port and
fingerprint information are obtained and stored based on multiple plug-ins, which are used for the
penetration test pipeline call; the
penetration test pipeline is connected with the information detection pipeline. , based on different multiple plug-ins, use the IP, URL, port and
fingerprint obtained by the reconnaissance pipeline to perform penetration testing on various vulnerabilities, store the tested
vulnerability information and output the
test report at the same time. The method can detect and collect the information of the
test target in a short time, and automatically carry out the
vulnerability penetration, which improves the efficiency of the penetration test.