Phase 6 · Ethical Hacking & Penetration Testing
TopicsReconnaissance & OSINT
Part of the Cybersecurity Roadmap.
Summary
Gathering publicly available information about a target before any active testing — Open Source Intelligence techniques reveal exposed employee info, technology stacks, and misconfigured public assets.
How to Learn This
- 1Practice OSINT techniques on a legal target (like your own organization or a designated practice target).
- 2Learn to use tools like Shodan or similar to find exposed services (on authorized targets only).
- 3Understand passive reconnaissance (no direct contact) versus active reconnaissance (direct probing).
More topics in Ethical Hacking & Penetration Testing
Stuck on this topic? Ask an Insider
Get 1:1 guidance from people who've walked this exact path — free on the InsideEdge app.