Reconnaissance and OSINT
Know Your Target
Attackers spend far more time learning about a target than attacking it. Reconnaissance ("recon") is that learning phase. Good recon makes the rest of a test faster and more accurate. For defenders it answers a sobering question: what can an outsider already learn about us?
OSINT (Open Source Intelligence) means collecting information from publicly available sources. Nothing is hacked. It is all out in the open, and that is exactly the problem.
Legal and ethical note: OSINT on your own organisation or an authorised client is fine. Do not use these techniques to stalk, harass or profile private individuals. Collecting personal data may also fall under data-protection law such as the Nigeria Data Protection Act 2023 and GDPR.
Passive vs Active Recon
- Passive: you never touch the target's systems. Search engines, WHOIS, certificate logs, social media, job adverts. Nothing shows in the target's logs.
- Active: you interact with the target, such as port scanning or visiting hidden URLs. It can be detected, so it needs authorisation.
What OSINT Can Reveal
| Source | What you may learn |
|---|---|
| WHOIS / DNS records | Domain owner, registrar, name servers, mail servers, sub-domains |
| Certificate transparency logs (crt.sh) | Sub-domains such as vpn., staging., admin. |
| Search engines | Exposed documents, login pages, error messages |
| Social media / LinkedIn | Staff names, roles and email format, technologies used |
| Job adverts | Tech stack ("Experience with Fortinet, Oracle, AWS") |
| GitHub and paste sites | Leaked keys, passwords and internal code |
| Shodan / Censys | Internet-facing devices, open ports and software versions |
Google Dorking
Google dorking uses advanced search operators to find things that were exposed by mistake:
site:example.com filetype:pdf # PDF files on one site
site:example.com inurl:admin # pages with "admin" in the URL
intitle:"index of" "backup" # open directory listings
site:example.com ext:sql | ext:env # possible leaked config files
Defenders run these against their own domains to find accidental exposure, like a spreadsheet of customers or a .env file with passwords. The Google Hacking Database (GHDB) lists many examples.
Shodan: The Search Engine for Devices
Shodan continuously scans the internet and records the banners of devices: webcams, routers, databases, industrial systems. A query like org:"Example Ltd" port:3389 can show a company's exposed Remote Desktop servers. It is legal to search what Shodan has already indexed. It is not legal to log in to what you find.
Real breaches have started with an internet-exposed database or camera that no one knew about. The lesson for defenders: if Shodan can find it, so can an attacker.
theHarvester
theHarvester collects email addresses, sub-domains, hosts and names from public sources such as search engines and certificate logs. A typical command looks like:
theHarvester -d example.com -b crtsh,duckduckgo
Email addresses reveal the company's format (first.last@company.com), which attackers use to build phishing lists. Sub-domains like staging. or test. are often less protected than the main site.
A Nigerian and Global Case
A logistics company in Lagos publishes its staff directory, an "IT helpdesk" phone number and a job advert mentioning its VPN vendor. A simple search shows a forgotten test. sub-domain running an old admin panel. None of this needed any hacking. Companies in London or Nairobi leak the same way, which is why a good pentest report often begins with "what we found without touching your network".
Try It: Recon Simulator
In the editor on the right you have two tools using a fictional company, Kola Logistics (kola-logistics.example):
- Dork builder: pick operators and see the search string and what it could reveal.
- theHarvester simulator: run it and read the results. Then answer: which finding is the biggest risk, and how would you fix it?
Everything here is simulated. No real searches or requests are made.
Try it yourself
Key Takeaways
- Recon is the learning phase. OSINT uses public information such as WHOIS, certificate logs, search engines, social media, job adverts and GitHub.
- Passive recon does not touch the target. Active recon does, so it needs authorisation.
- Google dorking (site:, filetype:, inurl:, intitle:) finds exposed files and pages. Defenders should dork their own domains.
- Shodan indexes internet-facing devices. If Shodan can see your system, so can an attacker.
- theHarvester collects emails and sub-domains. Forgotten test and staging hosts are common weak spots. Respect privacy law and only target what you are authorised to assess.
Quick Quiz
1.What is the difference between passive and active reconnaissance?
2.Why do defenders run Google dorks against their own domain?
3.theHarvester finds the email addresses first.last@company.com. Why does this matter for security?
Ready to go further?
CareerEx gives you structured 12-week training, live classes every Saturday and Sunday, real tutor feedback, and a certificate. Join the next cohort.
Join CareerEx