OSINT & footprinting

beginnerExternal & Wireless

TL;DR

OSINT is building a picture of a target from public information before you touch anything — domains, subdomains, email formats, technologies, people. It shapes everything that follows, and the best of it is completely passive.

What it is

Open-source intelligence: what you can learn about an organisation from information that’s already out there. On an external test it’s the recon that decides where you even look.

What you’re building

Keeping it clean

Stay within scope and prefer passive sources — you can learn an enormous amount without sending the target a single packet. Note where each finding came from; it makes the report far stronger.

← Back to External & Wireless