Overview

Reconnaissance gathers information about a target before deeper testing begins, identifying systems, domains, employees, technologies, and possible entry points within an authorized scope.

Key concepts

  • Passive vs. active recon
  • OSINT, footprinting
  • Domain/email enumeration, technology profiling

How it works

Reconnaissance is the process of gathering information about a target before performing deeper security testing — helping identify systems, domains, employees, technologies, and possible entry points within an authorized scope.

Types of reconnaissance

TypeWhat it means
Passive reconnaissanceGathering information without directly interacting with the target's systems.
Active reconnaissanceGathering information through direct interaction with authorized target systems.
Open-source intelligence (OSINT)Information collected from publicly available sources.
FootprintingBuilding a profile of a target's systems, network presence, and technologies.
Domain enumerationIdentifying domains and subdomains associated with an organization.
Email enumerationIdentifying email formats, addresses, or mail-related systems associated with an organization.
Technology profilingIdentifying operating systems, web servers, frameworks, services, and security products used by a target.

Core concepts

TermMeaning
Domain nameA human-readable address used to locate an internet resource.
SubdomainA division of a main domain pointing to a separate service or system.
IP addressA numerical address identifying a device on a network.
WHOIS recordPublic registration information about a domain name.
DNS recordInformation connecting domain names to services, IP addresses, mail servers, and other resources.
MetadataInformation embedded in files that can reveal author, date, location, or software used.