Cyber Security Basics 📂 Slides · 16 of 17 56 min read

Cyber Kill Chain: Reconnaissance — How Every Breach Really Begins

Reconnaissance is Phase 1 of the Cyber Kill Chain — the quiet information-gathering that decides every later stage. This tutorial covers passive vs active recon, OSINT and modern 2026 methods, how attackers turn scattered public facts into an attack map, real recon-led breaches (Target, SolarWinds, Twitter, RSA), and how defenders detect recon and shrink their attack surface. With animated diagrams.

Cyber Kill Chain — Reconnaissance

Before a single exploit is fired, an attacker studies you. Reconnaissance is Phase 1 — quiet, patient, and where every breach truly begins. Learn how it works, the real cases it powered, and how defenders see it coming.
Passive vs Active OSINT Attack Surface Detection & Defense

Press Next → or use ← → arrow keys

The Big Picture

The Cyber Kill Chain — 7 Phases

Lockheed Martin's model describes the stages an intruder moves through. Reconnaissance is the first link — and the earlier you break the chain, the cheaper the defense.

1 · Reconyou are here 2 · Weaponize 3 · Deliver 4 · Exploit 5 · Install 6 · C2 (control) 7 · Actions 🎯 the focus of this tutorial
🔗
Why "Chain" Matters

An attack only succeeds if every link holds. Break any one and the intrusion fails — so defenders push detection as far left as possible. Recon is the leftmost, cheapest place to win.

The Story

The Breach That Started With a Fish Tank

Recon finds the door nobody was watching
In a now-famous North American casino incident, attackers didn't hammer the firewall. During reconnaissance they mapped every internet-connected device and found an internet-connected fish-tank thermostat — a smart aquarium sensor no one thought of as "IT." It became the foothold; from there they pivoted and quietly exfiltrated a high-roller database. The whole breach was set up by knowing what to look at.
💡
The Lesson

Attackers don't break in where you're strong — they enter where you didn't know you were exposed. Reconnaissance is how they find that place, and it happens before any alarm is designed to trip.

Definition

What Is Reconnaissance?

🕵️
"Casing the Joint"

Reconnaissance is the information-gathering phase — the attacker builds a detailed picture of the target's people, technology, and exposure before acting. Like a burglar watching a house for a week: which doors, which hours, which neighbours notice.

👥
People
Employees, roles, emails, org chart, who has access, who's new, who overshares.
💻
Technology
Domains, IPs, open ports, software versions, cloud buckets, VPN & email gateways.
🏢
Business
Vendors, partners, tech stack from job posts, mergers, physical locations.
⏳
Slow, Quiet, and Legal-Looking

Much of recon uses publicly available information and generates no traffic to the target at all — which is exactly why it's so hard to detect and so valuable to the attacker.

The Core Split

Passive vs Active Reconnaissance

TARGETacme-corp.com PASSIVE reconnever touches target Google · LinkedIn · WHOIS reads 3rd-party data ACTIVE reconsends packets to target port scan · enum · probe directly probes → may be logged
🤫
Passive — invisible

Gathers intel from third parties (search engines, public records, social media). The target sees nothing. Low risk, huge yield.

📡
Active — noisier

Interacts directly with the target's systems (scanning, probing). Faster & deeper — but it hits logs, so it can be detected.

Passive Toolkit

How Passive Recon Works (OSINT)

🌐
WHOIS & DNS
Domain owners, name servers, subdomains, mail records — the org's public network skeleton.
🔎
Search-engine dorking
Crafted queries surface exposed docs, logins, and config files search engines quietly indexed.
💼
LinkedIn & job posts
Org charts, employee names, and — from job ads — the exact tech stack in use.
🛰️
Internet-wide scan data
Services like Shodan/Censys already scanned the whole internet — attackers just search the results.
📜
Certificate transparency
Public TLS-certificate logs reveal hidden subdomains (dev, staging, vpn) the moment a cert is issued.
🗝️
Breach & paste dumps
Leaked credentials from other breaches reveal reused passwords and valid email formats.
🧩
OSINT = Open-Source Intelligence

None of this requires touching the target. Automated OSINT frameworks stitch these sources into one profile in minutes — turning scattered public facts into a precise map.

Active Toolkit

How Active Recon Works

🚪
Port scanning
Which "doors" (ports) are open? Reveals reachable services — web, mail, RDP, databases.
🏷️
Banner grabbing
Services announce their software & version — a shortcut to "which known bugs apply?"
🗺️
Network mapping
Traceroutes and host discovery sketch the topology — firewalls, gateways, live hosts.
📋
Service enumeration
Poking a service for users, shares, endpoints — the detail that turns a map into a plan.
🕸️
Web app spidering
Crawling a site for hidden pages, parameters, and old endpoints left online.
📶
Wireless / physical
Driving by to catch Wi-Fi networks, or on-site "tailgating" and badge-watching.
🚨
The Trade-Off Attackers Weigh

Active recon is faster and more precise — but every probe is a footprint in your logs. Skilled attackers scan slowly and from many IPs to blend into normal internet background noise.

Current Methods

Reconnaissance in 2026

☁️
Cloud asset discovery
Misconfigured storage buckets, exposed APIs, and forgotten cloud instances are today's low-hanging fruit.
🐙
Source-code & secret leaks
Public code repos leak API keys, tokens, and internal URLs in commit history far more often than teams realize.
🤖
AI-assisted OSINT
LLMs summarize a target's footprint, draft convincing pretexts, and correlate data faster than any analyst.
🔗
Supply-chain mapping
Can't breach the target? Map its vendors and hit the weakest one — the Target & SolarWinds pattern.
📱
Social-media profiling
Photos leak badges & screens; "day one at…" posts flag new hires ripe for a welcome-themed phish.
🎣
Deepfake pretexting
Voice/video clones of executives make recon-driven "CEO fraud" calls dangerously believable.
📈
The Shift

Modern recon is continuous and automated. Attackers watch for the moment you spin up a new server, leak a key, or post a job ad — and pounce on the window before you notice.

CEH Deep-Dive

"Footprinting" — The Formal Name for Recon

📚
Same Phase, Textbook Term

In the CEH/ethical-hacking body of knowledge, reconnaissance is called Footprinting — "the collection of every possible piece of information about the target and its network." It is the first step of ethical hacking.

🛡️
Know security posture
Understand the target's external & internal defenses.
🎯
Reduce focus area
Narrow a huge target down to a few promising entry points.
🐛
Identify vulnerabilities
Spot weak, outdated, or misconfigured systems.
🗺️
Draw a network map
Sketch domains, IP ranges, hosts, and topology.
🏷️
Types You'll See Named

Passive & active (as covered) · Internet footprinting (via search engines/apps) · Pseudonymous footprinting (posting under an assumed name so intel traces back to someone else, not the attacker).

CEH Deep-Dive

The Footprinting Methodology

A disciplined engagement works through these sources in order — then documents every finding.

1 · Search engines 2 · Google hacking 3 · Social networks 4 · Website 5 · Email 6 · Competitive intel 7 · WHOIS 8 · DNS 9 · Network / tracert 10 · Social engineering 11 · Document ALL findings
📝
Always Scope First, Document Last

A legitimate engagement begins with authorization & a defined scope and ends by documenting all findings — the same rigor a defender uses to audit their own exposure.

CEH Deep-Dive

Google Dorking & the GHDB

Advanced search operators turn a search engine into a precision recon tool — surfacing files and pages that were indexed but never meant to be found.

OperatorFindsOperatorFinds
site:Results within a domainintitle:Keyword in page title
related:Similar web pagesinurl:Keyword in the URL
cache:Google's cached copyintext:Keyword in body text
link:Pages linking to a URLfiletype:Specific file types (pdf, xls…)
🗂️
GHDB — Google Hacking Database

Popularized by Johnny Long, the GHDB (hosted on exploit-db.com) is a curated library of dork queries that expose login portals, exposed config files, error messages, and vulnerable devices. Defenders check it against their own domain to find what leaks.

CEH Deep-Dive

WHOIS Footprinting & the 5 RIRs

🌐
What WHOIS Reveals

Registrant name & org, country, name servers, IP address & location, ASN, domain status, and registration/expiry dates — plus WHOIS, IP, registrar & hosting history.

🔐
Defense: WHOIS Privacy

Enable registrar privacy/redaction so registrant emails & phone numbers don't become free phishing fuel.

RIRAcronymRegion
African Network Information CenterAFRINICAfrica
American Registry for Internet NumbersARINUS, Canada, parts of the Caribbean, Antarctica
Asia-Pacific Network Information CentreAPNICAsia, Australia, New Zealand & neighbours
Latin America & Caribbean Network Info CentreLACNICLatin America & parts of the Caribbean
Réseaux IP Européens Network Coordination CentreRIPE NCCEurope, Russia, Middle East, Central Asia
CEH Deep-Dive

DNS Footprinting — Reading the Records

DNS records quietly describe an organization's mail, hosts, and services. Knowing the record types is knowing where to look.

RecordReveals
AHost's IP address
MXMail server
NSName server
CNAMEAliases to a host
SOAAuthority for the domain
RecordReveals
SRVService records
PTRIP → host (reverse)
RPResponsible person
HINFOHost / OS info
TXTUnstructured text (SPF, keys)
⚠️
The Leaky Ones

HINFO can hand an attacker your OS; TXT records often leak third-party services via SPF. Prune what you publish and disable zone transfers to strangers.

CEH Deep-Dive

Network Footprinting & Traceroute

🗺️
What It Extracts

Network address ranges · hostnames · exposed hosts · OS & app versions · patch state · the structure of apps & back-end servers.

🧰
Classic Tools

whois · ping · nslookup · tracert / traceroute. Ping also reveals if a host is live, its TTL, and (via the DF bit) the path MTU.

tracert — hop-by-hop path to the target
C:\> tracert example.com
 1   1 ms   192.168.0.1     <- gateway
 2   *      request timed out
 3   2 ms   110.37.216.157
 …
16 213 ms   152.195.65.133
17 211 ms   93.184.216.34   <- target
Trace complete.

Each hop maps a router between attacker and target — building the network map.

🛡️
Defense

Rate-limit/deny ICMP at the edge, hide internal hops, and watch for traceroute/scan bursts in your logs — active network footprinting is detectable.

CEH Deep-Dive

Email & Website Footprinting

📧
Email footprinting
A tracked email + its header reveals: destination address, sender's IP, sender's mail server, exact time & date, and the mail server's authentication system. Tools trace an email hop by hop with IPs and locations.
🕸️
Website footprinting
Netcraft reveals OS, web server & tech; web spiders harvest names & emails; mirroring (HTTrack) clones a whole site for offline study; and the Wayback Machine (archive.org) resurrects pages you thought you deleted.
🕰️
The Internet Doesn't Forget

Old credentials, staff names, and directory structures live on in archived snapshots and search caches long after you remove them. Assume anything ever public is still public.

CEH Deep-Dive

The Recon Toolkit (Awareness)

🔗
Maltego
Data-mining & link analysis — draws a node graph of relationships between domains, people, emails, and infrastructure via "Transforms."
🐍
Recon-ng
A modular, Python web-recon framework (Kali) — show modules, use, set source, run to automate OSINT.
📄
FOCA
Extracts metadata hidden in public documents (Office/PDF) — usernames, software, folder paths, printer names.
🛰️
Shodan / Censys
Search engines for internet-connected devices — find exposed servers, IoT, and their versions by filter.
🌾
theHarvester
Gathers emails, subdomains, hosts & employee names from public sources into one list.
🔎
Netcraft / Domain tools
Site technology, hosting history, and WHOIS/DNS lookups from the browser.
🧑‍🏫
Know Them to Defend Against Them

These are the same tools blue teams and pen-testers run on their own organization — an OSINT self-assessment shows you exactly what an attacker would collect.

CEH Deep-Dive

Footprinting Countermeasures

🛡️ THE COUNTERMEASURE CHECKLIST
1
Restrict social-media access from the corporate network, and train staff on what not to overshare.
2
Configure servers & devices to avoid data leakage — strip version banners, disable directory listing, block zone transfers.
3
Educate, train & raise awareness of footprinting, its impact, and social-engineering tactics.
4
Avoid revealing sensitive information in annual reports, press releases, and job ads.
5
Prevent search engines from caching sensitive pages; use robots controls and WHOIS privacy.
6
Enforce security policies, configure security zones, use strong encryption & password protection.
🔁
Footprint Yourself First

Run the whole methodology against your own organization on a schedule — the fastest way to find and close what leaks before an attacker maps it.

The Payoff

How Scattered Facts Become an Attack Map

emails from LinkedIn subdomains from CT logs tech stack from job ads open ports from scan leaked creds from dumps Target Profilethe attack surface map Weakest entry point chosen→ next phase: Weaponization
🧠
Correlation Is the Weapon

Any single fact looks harmless. But combined — a name + email format + a vulnerable service version + a reused password — they become a precise, low-noise plan of attack. Recon's true output is focus.

The Shopping List

What Attackers Are Hunting For

They want…Because it enables…
Employee names & email formatTargeted phishing & password-spray lists
Exposed services & versionsMatching a known, unpatched vulnerability
Forgotten / shadow IT assetsAn unmonitored way in (the fish tank)
Leaked credentials & API keysLogging in instead of breaking in
Vendors & partnersA softer supply-chain route to you
Org structure & who's newConvincing pretexts for social engineering
🎯
The Attacker's Mantra

"Why hack in if you can log in?" Most modern intrusions start not with an exploit, but with information — a valid credential, a known bug, an exposed asset — all found during reconnaissance.

Case Files

Recon-Led Breaches You Know

🎯
Retail giant, 2013
Attackers mapped the retailer's vendors, found an HVAC contractor with network access, phished it, and pivoted into payment systems — 40M+ cards. Recon chose the vendor, not the store.
🛰️
Software supply chain, 2020
The SolarWinds campaign studied a trusted software vendor deeply, then poisoned its update — reaching thousands of downstream targets. Recon identified the single point of maximum reach.
🐦
Social platform, 2020
Attackers profiled employees, identified those with internal admin tools, and phoned them with a tailored pretext — hijacking high-profile accounts. Pure people-recon.
🔑
Security firm, 2011
The RSA breach began with recon-crafted emails to specific staff, titled to look routine ("Recruitment Plan"). One click opened the door to seed-token data.
🧵
The Common Thread

In every case, the quiet first phase decided the whole attack. The exploit was almost a formality once recon had found the right person, vendor, or exposed system.

Blue Team

Can You Detect Reconnaissance?

Passive recon is nearly invisible — but active recon and its follow-through leave traces if you're watching.

📊
Log & scan analytics
Bursts of connections across many ports, or from one source to many hosts, betray scanning. SIEM correlation flags the pattern.
🍯
Honeypots & canary tokens
Fake assets and "tripwire" credentials that no legitimate user should ever touch — one hit = someone's poking around.
📡
Threat intelligence
Feeds of known-malicious scanner IPs and infrastructure let you block or watch reconnaissance sources early.
🔔
Brand & leak monitoring
Alerts when your domain, credentials, or code appear in paste sites, breach dumps, or new look-alike domains.
📜
Certificate log watching
Monitor CT logs for your own new subdomains — so you learn about exposed dev/staging hosts before attackers do.
🌐
Deception at the edge
WAFs and web decoys log crawler and enumeration behavior, turning an attacker's probing into your early warning.
👀
Reframe It

You may not stop someone looking at public data — but detected recon is a free warning that you're being targeted, giving you time to harden before the real attack lands.

Defense

Shrink What Recon Can Find

🗺️
Know your own surface
Run attack-surface management — continuously discover your internet-facing assets before attackers catalog them. You can't defend what you don't know you have.
🧹
Minimize the footprint
Retire shadow IT, close unused ports, strip version banners, lock down cloud buckets, and scrub secrets from public code.
🎭
Reduce OSINT leakage
Train staff on oversharing; keep job ads generic; use privacy on WHOIS; think before posting photos of desks & badges.
🔐
Assume creds leak
MFA everywhere + no password reuse + credential-leak monitoring — so a found password isn't a found account.
🤝
Vet your supply chain
Your vendors are part of your attack surface. Segment their access and hold them to your security bar.
🧪
Think like the attacker
Run your own recon on yourself (red-team / OSINT self-assessment) and fix what it surfaces first.
🛡️
The Defender's Edge

Every asset you retire, every secret you rotate, every banner you hide makes the attacker's map emptier — pushing them toward noisier methods you can detect.

Quick Recap

Passive vs Active — Side by Side

AspectPassive reconActive recon
Touches the target?No — third-party sourcesYes — direct probing
DetectabilityNearly invisibleVisible in logs
Speed & depthSlower, broadFaster, precise
ExampleWHOIS, LinkedIn, Shodan, CT logsPort scans, banner grabs, enumeration
Best defenseReduce OSINT footprintMonitoring, IDS/IPS, deception
⚖️
Attackers Use Both

Real campaigns start passive (quiet, build the picture), then go active only to confirm the few targets worth the risk. Your defense must cover both halves.

Cheat Sheet

Golden Rules of Reconnaissance

🏆 KEY TAKEAWAYS
1
Recon is Phase 1 of every breach. Break the chain here and the attack costs the adversary the most.
2
Passive recon is invisible — it reads public data. Active recon touches you and can be detected.
3
Your public footprint is the attacker's map. OSINT turns scattered facts into a precise plan.
4
"Why hack in if you can log in?" Leaked credentials & exposed assets beat exploits — assume they exist.
5
Know your own attack surface before attackers do — discover, minimize, and monitor it continuously.
6
Detected recon is a free early warning. Honeypots, canary tokens, and leak monitoring buy you time.
FINAL

The Battle Begins Before the Breach

Phase 1of the kill chain
2 typesPassive & active
OSINTThe attacker's map
Shift leftCheapest defense
🎯
The Whole Idea

Reconnaissance is the patient, quiet work that decides every later phase — mapping people, technology, and exposure, mostly from public data. Defenders win by seeing their own surface first, shrinking it, and turning an attacker's probing into an early warning. Break the chain at the first link and the rest never happens.

🧠
One Sentence to Remember

Attackers study you before they touch you — so study yourself first. Next in the kill chain: Weaponization, where intel becomes a tailored payload.

🎯 End of tutorial · Press ← to review, or click Restart