Unit I โ€ข Passive Reconnaissance

Passive Reconnaissance & OSINT

Gather target information without touching the system. Learn OSINT basics, Google Dorking, WHOIS lookups, DNS enumeration, theHarvester, and Shodan to discover exposed information.

What is OSINT?

Definition

OSINT stands for Open Source Intelligence. It involves collecting and analyzing publicly available information from various sources to gather actionable intelligence about a target without ever touching their systems.

Key Principle

Passive reconnaissance means no direct interaction with the target. You're not scanning ports, sending packets, or triggering alarmsโ€”just gathering information from publicly available sources on the internet.

Information Sources

๐ŸŒ

Internet

Websites, blogs, social media, forums, GitHub, company pages

๐Ÿ“ฐ

Publications

News articles, press releases, academic papers, industry reports

๐Ÿ“ธ

Multimedia

Images, videos, metadata (EXIF), podcasts, YouTube channels

๐Ÿ“‹

Public Records

Government databases, legal documents, business filings, court records

OSINT Definition and Applications

OSINT Tools & Resources

Hunter.io

Email address finder and verification

Visit Tool

Dehashed

Search leaked credentials database

Visit Tool

HaveIBeenPwned

Check if email/password in breaches

Visit Tool

Wayback Machine

View archived versions of websites

Visit Tool

Reverse Image Search

Google Images reverse search

Visit Tool

VirusTotal

File and URL analysis

Visit Tool
Sock Puppets for OSINT

Ethical Considerations in OSINT

  • โœ“ Always have written authorization for OSINT activities
  • โœ“ Use sock puppets only when ethically justified and with proper safeguards
  • โœ“ Respect privacy and data protection regulations (GDPR, CCPA)
  • โœ“ Document all sources and findings for reporting

Key Takeaways

  • 1. Passive reconnaissance gathers intelligence without alerting targets
  • 2. Google Dorking reveals sensitive documents and exposed information
  • 3. WHOIS and DNS provide ownership and infrastructure details
  • 4. theHarvester automates email and subdomain collection
  • 5. Shodan finds internet-exposed services and vulnerable devices
  • 6. Always conduct OSINT ethically with proper authorization