Lesson 3 30 minutesFree Lesson
Passive Reconnaissance Techniques
Reconnaissance is the foundation of any penetration test. Passive reconnaissance gathers information without directly interacting with the target, leaving no trace. Techniques include OSINT (Open Source Intelligence), DNS analysis, WHOIS lookups, Google hacking (dorks), and social media analysis.
OSINT tools: Maltego (relationship mapping), Shodan (internet-connected device search), theHarvester (emails and subdomains), Recon-ng (web reconnaissance framework), and SpiderFoot (automated OSINT collection).
Google dorks for information gathering: site:target.com filetype:pdf, intitle:"index of" site:target.com, "password" filetype:xls site:target.com. These techniques reveal information the target may not realize is publicly accessible.
🎯 Key Takeaways
→ Review the core concepts from this lesson before moving on
→ Apply these concepts in the Training Labs CTF challenges
→ Complete the quiz below to test your understanding