🥷 Top sites for passive reconnaissance

Passive reconnaissance is a critical step for bug bounties or penetration testing engagements, get ready!

Passive reconnaissance is the process of collecting information in a covert manner about an intended target without the target knowing what is occurring.

Mainly is done searching information about the target on the Internet (Google, Linkedin, etc) and also searching for metadata (i.e. domain registers information, OSINT tools, etc).

Another effective way to do passive recon is obviously through Google, actually there is a term for that: Google dorking or google dorks, you can read more about it below:

Learn Pentesting like a Pro
How to use Google Dorks easily
Google Dork is an advanced Google search query using special commands such as allinurl, allintitle, etc to leverage Google to find public information. Is also a good way to perform passive reconnaissance. Offensive Security has the major Google Dork database called GHDB…
Read more

Did I miss some great tool? Please add it in the comments below 🙂






Leave a Reply

Your email address will not be published. Required fields are marked *