Reconnaissance & Footprinting

An Interactive Guide to Information Gathering

What is Reconnaissance?

Reconnaissance, or Footprinting, is the foundational phase of ethical hacking. It involves collecting as much information as possible about a target system, network, or organization. This initial intelligence gathering is crucial for understanding the target's attack surface and identifying potential vulnerabilities before launching any actual tests. The entire process is divided into two main approaches: Passive and Active. Use the toggles below to explore the techniques for each.

OSINT

Gathering information from publicly available sources like websites and public records.

Google Dorking

Using advanced search operators to find sensitive information indexed by search engines.

WHOIS Lookups

Querying databases to get domain registration details like owner and name servers.

DNS Enumeration

Querying DNS records to map out network infrastructure and services.

Social Media Intel

Analyzing social media profiles to find employee details and technology stacks.

Website Analysis

Inspecting website history and configuration files like `robots.txt`.

Technique Comparison: Detectability vs. Information Gain