Footprinting & Reconnaissance
A focused review of passive and active reconnaissance, search techniques, OSINT sources, domain and DNS intelligence, people and document exposure, mapping tools, countermeasures, and safe hands-on practice.
CEH v13 Theory Exam
High-yield knowledge for MCQ-style questions.
◎Core Concept
- Footprinting, or reconnaissance, is the first phase of ethical hacking: gathering information to understand a target before scanning or exploitation.
- Passive reconnaissance relies on public or third-party sources and avoids direct interaction with target-controlled systems.
- Active reconnaissance sends queries or traffic that may reach target-controlled infrastructure and is more likely to be logged.
- The objective is to turn scattered facts into a usable map of people, domains, technologies, systems, and possible exposure.
Analogy: studying a building from public information and observation before approaching any door.
▦Information Collected
- Organization: locations, telephone numbers, public documents, press releases, business relationships, and web technologies.
- People: employee names, roles, public profiles, contact patterns, and technology clues.
- Network: domains, subdomains, IP ranges, DNS records, mail servers, hosting providers, and visible topology.
- Systems: internet-facing services, server technologies, software versions, document metadata, and exposed identifiers.
Exam idea: the value comes from correlation—one public fact may confirm or expand another.
⌕Search Engines & Google Operators
Restrict results to a domain
Find a specific document type
Match terms in a page title
Match terms in a URL
Find sites considered similar
Use quotation marks for exact text
Current note: operators such as cache:, link:, and info: are historical or unreliable in modern Google Search. For older content, use a web archive.
◉GHDB, Shodan & Internet Archives
- GHDB: a categorized collection of search queries used to locate exposed files, directories, login pages, error messages, and other indexed information.
- Shodan: a search engine for indexed internet-facing devices and services; results can include banners, ports, products, and observed locations.
- Censys and ZoomEye: alternative platforms for discovering and analyzing exposed internet assets.
- Wayback Machine: reveals historical versions of websites and can expose old paths, content, or technology clues.
- Search-engine results can be stale, incomplete, or incorrectly attributed; validate important findings.
🌐Domains, WHOIS & DNS
- Netcraft and DNSDumpster: help identify domains, subdomains, hosts, providers, and visible relationships.
- WHOIS/RDAP: can reveal registrar, registration dates, name servers, status codes, and network ownership.
- Registrant names and contact details are often redacted or privacy-protected; absence of personal data is normal.
- A/AAAA: host to IPv4/IPv6; MX: mail; NS: authoritative name servers; CNAME: alias; TXT: text and verification data; PTR: reverse lookup.
- DNS queries are low-impact but can still interact with target-controlled infrastructure, so classification depends on the source queried.
♙People, Email & Metadata Footprinting
- Public company pages, job listings, professional profiles, and press releases can reveal names, roles, locations, projects, and technology stacks.
- theHarvester aggregates public-source email, host, and domain information using supported providers.
- Sherlock checks a username across many sites; matches require manual validation because false positives are common.
- ExifTool or FOCA can reveal usernames, software versions, paths, authors, and other metadata in authorized documents.
- Collect only what is necessary and lawful. Public availability does not remove privacy, policy, or authorization obligations.
⌘Automated Mapping & AI
- Maltego: visualizes relationships among domains, IPs, email addresses, organizations, and other entities.
- Recon-ng: organizes reconnaissance into modules, workspaces, records, and reports.
- AI assistants: can structure queries, normalize notes, suggest validation steps, and summarize authorized findings.
- AI output is not evidence. Validate commands, scope, sources, timestamps, and entity matches before using the result.
- Never paste confidential client data or credentials into an unapproved AI service.
✓Footprinting Countermeasures
- Minimize unnecessary information in websites, documents, job listings, public profiles, catalogs, and press releases.
- Remove document metadata and review files before publication.
- Use domain-registration privacy where appropriate and monitor domain, DNS, and certificate exposure.
- Configure web servers to suppress verbose banners, directory listings, debug pages, and sensitive error details.
- Apply least privilege to public cloud assets and prevent accidental indexing of sensitive content.
- Train staff against oversharing and social engineering; continuously review the organization’s external footprint.
!Common MCQ Traps
- Passive recon does not mean “harmless”; it means no direct interaction with the target’s systems.
- Shodan indexes services and device banners; it is not simply a conventional vulnerability scanner.
- WHOIS/RDAP may identify a registrar or network owner without revealing a private registrant.
- A DNS zone transfer can expose a zone only when the server permits it; it is not the same as a normal DNS lookup.
- Finding a username, email, subdomain, or service is a lead—not proof of identity, ownership, or vulnerability.
- Search operators retrieve indexed material; they do not bypass authentication or authorization.
?Sample MCQ
Which technique best represents passive footprinting?
- Querying a target-owned DNS server directly
- Running a port scan against the target
- Reviewing archived versions of the organization’s public website
- Attempting a DNS zone transfer from an authoritative server
CEH v13 Practical Scenarios
Authorized reconnaissance using a training organization, reserved domains, owned systems, and documented scope.
Advanced Search Techniques
site:example.org
site:example.org filetype:pdf
site:example.org intitle:"login"
site:example.org inurl:archive
Goal: practice narrowing indexed results and classify each discovery without opening restricted content.
Map Domains and Hosts
- Use Netcraft and DNSDumpster with an authorized training domain.
- Record discovered domains, subdomains, hosts, and providers.
- Compare the two sources and note duplicates or conflicting results.
- Mark every unverified result as a hypothesis rather than a confirmed asset.
Goal: build a validated first-pass map of the organization’s visible internet footprint.
WHOIS and RDAP Review
whois example.com
whois 192.0.2.10
- Identify registrar or RIR, dates, status codes, name servers, and network ownership.
- Record redacted fields as unavailable—do not infer hidden personal details.
Goal: distinguish domain-registration data from IP-allocation data and recognize privacy redaction.
Public Email and Host Discovery
theHarvester -d example.com -b crtsh
- Use only a domain included in the authorized lab scope.
- Review public-source results for email formats, hosts, and subdomains.
- Remove duplicates and label uncertain or outdated entries.
- Do not message discovered addresses or attempt credential use.
Goal: demonstrate public-source aggregation while preserving privacy and scope.
Social and Technology Clues
- Use a fictitious organization or profiles created for the lab.
- Identify public roles, locations, job requirements, and technology references.
- Use Sherlock only with a lab-owned username and validate matches manually.
- Record the minimum information needed for the exercise.
Goal: recognize oversharing and false attribution without profiling a real individual.
DNS Record Mapping
nslookup example.com
nslookup -type=mx example.com
dig example.com A
dig example.com MX
dig example.com NS
Goal: map names to addresses and identify authoritative and mail infrastructure. Use only approved domains.
Network Path Observation
# Windows
tracert example.com
# Linux
traceroute example.com
Goal: observe visible hops and latency while remembering that filtering, load balancing, and routing changes can make paths incomplete or inconsistent.
Email Header and Privacy Review
- Send a message between two lab-controlled mailboxes.
- Inspect Received, Message-ID, SPF, DKIM, and DMARC-related header fields.
- Compare what the header reveals with what a recipient actually needs.
- Discuss how tracking pixels affect privacy and require notice, consent, and policy review.
Goal: understand email footprinting without covertly tracking another person.
Build a Maltego Map
- Create a new graph and add the authorized training domain as the root entity.
- Run only approved transforms for DNS, hosts, and public-source relationships.
- Separate observed facts from inferred relationships.
- Attach source and collection date to important findings.
Goal: visualize relationships while maintaining provenance and avoiding false conclusions.
AI-Assisted Recon Notes
Organize these authorized lab findings into:
1. confirmed assets
2. unverified leads
3. conflicting evidence
4. safe validation steps
5. defensive recommendations
Goal: use AI to structure and review evidence—not to invent findings or expand beyond the approved scope.
✓Practical Strategy
- Define the authorized organization, domains, systems, data sources, and collection limits before starting.
- Begin with passive sources, then use low-impact active queries only when scope permits.
- For every finding, record the source, timestamp, confidence, validation status, and business relevance.
- Correlate at least two sources before treating a domain, account, technology, or relationship as confirmed.
- Do not download sensitive files, contact employees, track recipients, access the dark web, or probe systems unless the lab explicitly authorizes it.
- Finish with a concise asset map, exposure summary, and defensive recommendations.
Key Takeaways
- Theory: know passive versus active reconnaissance, major search operators, GHDB, Shodan, WHOIS/RDAP, DNS records, OSINT tools, and countermeasures.
- Practical: collect, validate, correlate, map, and document authorized information without turning an unverified lead into a false conclusion.
- Mindset: reconnaissance quality depends on source reliability, freshness, attribution, and context—not simply the amount of data collected.
- Professional rule: public information is not automatically permission to profile, contact, track, or access; stay inside the written scope.
