osint

OSINT (open-source intelligence) is the practice of collecting and analyzing publicly available information, such as websites, DNS records, search engines, social media, public records and leaked data, to build a picture of a target. In cybersecurity it is the reconnaissance phase of a penetration test, and it is equally important for threat intelligence, incident response and understanding your own organization’s exposure.

Common OSINT techniques include subdomain and DNS enumeration, attack surface mapping, employee and email discovery, metadata analysis and searching for exposed services. They often rely on tools such as theHarvester, Amass, Shodan, Maltego, Recon-ng and SpiderFoot.

Start with our complete guide to OSINT and attack surface mapping, then follow the hands-on reconnaissance walkthroughs across Cracking Station. Use OSINT responsibly: gather only public information, respect privacy laws, and test organizations only with authorization.

Back to top button