Recon _Alias Information Gathering

From previous posts hope you readers have got some idea about redteaming and its stages now its time to jump over some technical aspects of Redteaming.

If u want to murder someone or propose someone you would be knowing about the target right , In simple manners recon is all about information collection. Although various blogs about OSINT were available ,I ll try to simplify as much as important points which needs to be considered while using recon

OK Cool What is OSINT :


Open-source intelligence (OSINT)​​is using ​publicly available ​sources to collect information (i.e., intelligence) about persons or entities from a wide array of sources including the Internet.

OSINT is usually performed during the Reconnaissance phase of hacking, and information collected from this phase is carried over into the Network Enumeration phase. Due to the broad amount of information available on the web, attackers must have a clear and defined search framework​,as well as a wide array of OSINT collection tools to facilitate processing the data; otherwise they risk getting lost in the overwhelming sea of information or just briefing it up

Remember osint is not recon,its just a phase of recon.

Some Points to be remembered if its domain/website/webapplication:

* Do a google Searching & Dorking 





* Always use search engines
* Do a WHOIS search
* Do a tracert to the domain
* Use Spokeo for person search
* Shodan,censys,zoomeye were your friends use it nmap scripts
* Some tools which you can use were  maltego,datasploit,Automater etc


There were lot of tools and blogs around OSINT though ,have enclosed my OSINT document which contains all links and sites . so you can use during your OSINT phases.


Remember its huge list so use it wisely.
 

Comments