Open Source Intelligence (OSINT) & Passive Recon teaches you to turn public domain, DNS, and certificate data into a documented external-footprint assessment. Three guided labs cover Whois enumeration, DNS record analysis, zone transfers, and theHarvester; a final challenge combines infrastructure mapping with subdomain discovery and email-roster generation.
You work from an Ubuntu 22.04 terminal against public records and deliberately selected educational domains. The course emphasizes collecting reproducible command output, separating raw results from cleaned target lists, and recognizing that public data can still be sensitive or time-dependent.
What You Will Learn
- Save and filter Whois records to identify registrar details, public contacts, and authoritative nameservers
- Query A, AAAA, MX, TXT, CNAME, and NS records with
hostanddig - Explain the security impact of an exposed DNS zone transfer and preserve complete AXFR results
- Install and run theHarvester through
uvand select a public Certificate Transparency source - Normalize discovered subdomains with shell filters, sorting, and deduplication
- Correlate ownership, DNS, mail, certificate, and subdomain evidence into an external footprint
- Convert a provided employee-name list into a constrained email roster for an authorized simulation
Who This Course Is For
This course is for junior red-teamers, penetration-testing learners, defenders performing attack-surface reviews, and analysts who want practical command-line OSINT skills. It focuses on public infrastructure intelligence rather than active port scanning or exploitation.
Prerequisites: Basic Linux shell use, redirection and text filtering, plus familiarity with domains, IP addresses, DNS, and email naming. You should understand that reconnaissance must stay within an authorized scope.
Learning environment: Four independent activities in browser-accessible Ubuntu 22.04 virtual machines: three guided labs and one challenge. The exercises query live Whois, DNS, GitHub, and Certificate Transparency services using ubuntu.com, kali.org, and the security-training domain zonetransfer.me; command-line tools and staged employee data support the workflows.
Frequently Asked Questions
Is every activity completely passive and invisible to the target?
No. Whois and Certificate Transparency collection rely on third-party public records, but DNS lookups and AXFR attempts send queries to DNS infrastructure. They are low-impact reconnaissance, not a guarantee of zero target interaction or invisibility.
Do I need an API key, paid OSINT account, or my own domain?
No. The theHarvester exercise uses the public crtsh source, and the other tasks use standard Whois and DNS services. Public internet access is required, but no learner-supplied key, subscription, or domain is used.
Will my output always match the examples exactly?
Not necessarily. Whois registrations, DNS records, certificate logs, tool versions, and external service responses can change. The examples illustrate structure; you should interpret and save the live results returned during the lab.
May I run these workflows against any organization?
Use them only for assets you own, explicitly authorized assessments, or training targets such as zonetransfer.me. Public availability does not remove privacy, contractual, or legal obligations, especially when aggregating employee information.





