Phase 6 · Ethical Hacking & Penetration Testing

Topics

Reconnaissance & OSINT

Part of the Cybersecurity Roadmap.

Summary

Gathering publicly available information about a target before any active testing — Open Source Intelligence techniques reveal exposed employee info, technology stacks, and misconfigured public assets.

How to Learn This

  • 1Practice OSINT techniques on a legal target (like your own organization or a designated practice target).
  • 2Learn to use tools like Shodan or similar to find exposed services (on authorized targets only).
  • 3Understand passive reconnaissance (no direct contact) versus active reconnaissance (direct probing).
InsideEdge

Stuck on this topic? Ask an Insider

Get 1:1 guidance from people who've walked this exact path — free on the InsideEdge app.

Download
InsideEdge