OSINT 外景侦察
原名:conducting-external-reconnaissance-with-osint
使用OSINT技术进行外部侦察,在不接触目标系统的情况下绘制组织外部攻击面,收集DNS记录、证书透明度日志、搜索结果、社交媒体、代码仓库和泄露数据库,构建目标档案。适用于渗透测试的被动信息收集阶段、外部足迹收集或社会工程活动中的员工/邮箱情报收集。
- 分类
- 学习研究
- 版本
- v1.0.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 0
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-09-05
- TRACE 评分
- 3.4 / 5
内容概览
- Performing the initial reconnaissance phase of a penetration test to gather intelligence before active scanning - Mapping an organization's external attack surface to identify unknown or shadow IT assets - Collecting employee information, email formats, and organizational structure for social engineering campaigns - Identifying exposed credentials, leaked data, or sensitive documents published on the internet - Scoping the breadth of an organization's digital footprint prior to a red team engagement Do not use for stalking, harassment, or unauthorized surveillance of individuals. OSINT gathering must be conducted within the scope of an authorized engagement and comply with applicable privacy laws (GDPR, CCPA). - Written authorization to perform reconnaissance against the target organization - Dedicated research workstation with a VPN or Tor for anonymized queries when required - OSINT …