OSINT & footprinting
TL;DR
OSINT is building a picture of a target from public information before you touch anything — domains, subdomains, email formats, technologies, people. It shapes everything that follows, and the best of it is completely passive.
What it is
Open-source intelligence: what you can learn about an organisation from information that’s already out there. On an external test it’s the recon that decides where you even look.
What you’re building
- The attack surface: domains, subdomains, IP ranges, exposed services.
- The tech: what software, frameworks and providers they use.
- The people: email address format, names and roles — the input to password and phishing work.
- The leaks: credentials in past breaches, secrets in public repos, documents with metadata.
Keeping it clean
Stay within scope and prefer passive sources — you can learn an enormous amount without sending the target a single packet. Note where each finding came from; it makes the report far stronger.