From the course: Security Testing Essential Training

Unlock the full course today

Join today to access over 23,200 courses taught by industry experts.

Open-source intelligence

Open-source intelligence

- [Teacher] Another passive information gathering technique is open-source intelligence or OSINT gathering. With OSINT gathering, you use publicly available repositories in an effort to identify target systems without ever touching the target systems themselves. OSINT gathering can be very useful but it's not without its drawbacks. For one, OSINT gathering could be inaccurate or outdated. OSINT gathering may return information about a system that was decommissioned months ago resulting in a false positive. Another drawback to OSINT gathering is that it's often geared toward internet-facing systems. It's highly likely that you'll find useful relevant information about live hosts on the customer's internal network using this technique. The one exception to that rule is a DNS zone transfer. If your customer hasn't properly restricted DNS zone transfers to internal authorized hosts, or better yet disabled them entirely, then…

Contents