CEH v13 Prep · Module 02

Footprinting & Reconnaissance

A focused review of passive and active reconnaissance, search techniques, OSINT sources, domain and DNS intelligence, people and document exposure, mapping tools, countermeasures, and safe hands-on practice.

Exam FocusPassive vs active recon, Google operators, GHDB, Shodan, WHOIS, DNS, OSINT, and defenses
Practical FocusAuthorized collection, source validation, DNS mapping, metadata review, correlation, and reporting
Tools to KnowGoogle, Shodan, Netcraft, DNSDumpster, WHOIS, dig, theHarvester, Maltego, and Recon-ng

1

CEH v13 Theory Exam

High-yield knowledge for MCQ-style questions.

◎Core Concept

  • Footprinting, or reconnaissance, is the first phase of ethical hacking: gathering information to understand a target before scanning or exploitation.
  • Passive reconnaissance relies on public or third-party sources and avoids direct interaction with target-controlled systems.
  • Active reconnaissance sends queries or traffic that may reach target-controlled infrastructure and is more likely to be logged.
  • The objective is to turn scattered facts into a usable map of people, domains, technologies, systems, and possible exposure.

Analogy: studying a building from public information and observation before approaching any door.

▦Information Collected

  • Organization: locations, telephone numbers, public documents, press releases, business relationships, and web technologies.
  • People: employee names, roles, public profiles, contact patterns, and technology clues.
  • Network: domains, subdomains, IP ranges, DNS records, mail servers, hosting providers, and visible topology.
  • Systems: internet-facing services, server technologies, software versions, document metadata, and exposed identifiers.

Exam idea: the value comes from correlation—one public fact may confirm or expand another.

⌕Search Engines & Google Operators

site:
Restrict results to a domain
filetype:
Find a specific document type
intitle:
Match terms in a page title
inurl:
Match terms in a URL
related:
Find sites considered similar
Exact phrase
Use quotation marks for exact text

Current note: operators such as cache:, link:, and info: are historical or unreliable in modern Google Search. For older content, use a web archive.

◉GHDB, Shodan & Internet Archives

  • GHDB: a categorized collection of search queries used to locate exposed files, directories, login pages, error messages, and other indexed information.
  • Shodan: a search engine for indexed internet-facing devices and services; results can include banners, ports, products, and observed locations.
  • Censys and ZoomEye: alternative platforms for discovering and analyzing exposed internet assets.
  • Wayback Machine: reveals historical versions of websites and can expose old paths, content, or technology clues.
  • Search-engine results can be stale, incomplete, or incorrectly attributed; validate important findings.

🌐Domains, WHOIS & DNS

  • Netcraft and DNSDumpster: help identify domains, subdomains, hosts, providers, and visible relationships.
  • WHOIS/RDAP: can reveal registrar, registration dates, name servers, status codes, and network ownership.
  • Registrant names and contact details are often redacted or privacy-protected; absence of personal data is normal.
  • A/AAAA: host to IPv4/IPv6; MX: mail; NS: authoritative name servers; CNAME: alias; TXT: text and verification data; PTR: reverse lookup.
  • DNS queries are low-impact but can still interact with target-controlled infrastructure, so classification depends on the source queried.

♙People, Email & Metadata Footprinting

  • Public company pages, job listings, professional profiles, and press releases can reveal names, roles, locations, projects, and technology stacks.
  • theHarvester aggregates public-source email, host, and domain information using supported providers.
  • Sherlock checks a username across many sites; matches require manual validation because false positives are common.
  • ExifTool or FOCA can reveal usernames, software versions, paths, authors, and other metadata in authorized documents.
  • Collect only what is necessary and lawful. Public availability does not remove privacy, policy, or authorization obligations.

⌘Automated Mapping & AI

  • Maltego: visualizes relationships among domains, IPs, email addresses, organizations, and other entities.
  • Recon-ng: organizes reconnaissance into modules, workspaces, records, and reports.
  • AI assistants: can structure queries, normalize notes, suggest validation steps, and summarize authorized findings.
  • AI output is not evidence. Validate commands, scope, sources, timestamps, and entity matches before using the result.
  • Never paste confidential client data or credentials into an unapproved AI service.

✓Footprinting Countermeasures

  • Minimize unnecessary information in websites, documents, job listings, public profiles, catalogs, and press releases.
  • Remove document metadata and review files before publication.
  • Use domain-registration privacy where appropriate and monitor domain, DNS, and certificate exposure.
  • Configure web servers to suppress verbose banners, directory listings, debug pages, and sensitive error details.
  • Apply least privilege to public cloud assets and prevent accidental indexing of sensitive content.
  • Train staff against oversharing and social engineering; continuously review the organization’s external footprint.

!Common MCQ Traps

  • Passive recon does not mean “harmless”; it means no direct interaction with the target’s systems.
  • Shodan indexes services and device banners; it is not simply a conventional vulnerability scanner.
  • WHOIS/RDAP may identify a registrar or network owner without revealing a private registrant.
  • A DNS zone transfer can expose a zone only when the server permits it; it is not the same as a normal DNS lookup.
  • Finding a username, email, subdomain, or service is a lead—not proof of identity, ownership, or vulnerability.
  • Search operators retrieve indexed material; they do not bypass authentication or authorization.

?Sample MCQ

Knowledge Check

Which technique best represents passive footprinting?

  1. Querying a target-owned DNS server directly
  2. Running a port scan against the target
  3. Reviewing archived versions of the organization’s public website
  4. Attempting a DNS zone transfer from an authoritative server
Correct answer: C — the archive is a third-party public source, so the learner does not interact directly with the target’s infrastructure.

2

CEH v13 Practical Scenarios

Authorized reconnaissance using a training organization, reserved domains, owned systems, and documented scope.

1

Advanced Search Techniques

site:example.org
site:example.org filetype:pdf
site:example.org intitle:"login"
site:example.org inurl:archive

Goal: practice narrowing indexed results and classify each discovery without opening restricted content.

2

Map Domains and Hosts

  1. Use Netcraft and DNSDumpster with an authorized training domain.
  2. Record discovered domains, subdomains, hosts, and providers.
  3. Compare the two sources and note duplicates or conflicting results.
  4. Mark every unverified result as a hypothesis rather than a confirmed asset.

Goal: build a validated first-pass map of the organization’s visible internet footprint.

3

WHOIS and RDAP Review

whois example.com
whois 192.0.2.10
  • Identify registrar or RIR, dates, status codes, name servers, and network ownership.
  • Record redacted fields as unavailable—do not infer hidden personal details.

Goal: distinguish domain-registration data from IP-allocation data and recognize privacy redaction.

4

Public Email and Host Discovery

theHarvester -d example.com -b crtsh
  1. Use only a domain included in the authorized lab scope.
  2. Review public-source results for email formats, hosts, and subdomains.
  3. Remove duplicates and label uncertain or outdated entries.
  4. Do not message discovered addresses or attempt credential use.

Goal: demonstrate public-source aggregation while preserving privacy and scope.

5

Social and Technology Clues

  1. Use a fictitious organization or profiles created for the lab.
  2. Identify public roles, locations, job requirements, and technology references.
  3. Use Sherlock only with a lab-owned username and validate matches manually.
  4. Record the minimum information needed for the exercise.

Goal: recognize oversharing and false attribution without profiling a real individual.

6

DNS Record Mapping

nslookup example.com
nslookup -type=mx example.com
dig example.com A
dig example.com MX
dig example.com NS

Goal: map names to addresses and identify authoritative and mail infrastructure. Use only approved domains.

7

Network Path Observation

# Windows
tracert example.com

# Linux
traceroute example.com

Goal: observe visible hops and latency while remembering that filtering, load balancing, and routing changes can make paths incomplete or inconsistent.

8

Email Header and Privacy Review

  1. Send a message between two lab-controlled mailboxes.
  2. Inspect Received, Message-ID, SPF, DKIM, and DMARC-related header fields.
  3. Compare what the header reveals with what a recipient actually needs.
  4. Discuss how tracking pixels affect privacy and require notice, consent, and policy review.

Goal: understand email footprinting without covertly tracking another person.

9

Build a Maltego Map

  1. Create a new graph and add the authorized training domain as the root entity.
  2. Run only approved transforms for DNS, hosts, and public-source relationships.
  3. Separate observed facts from inferred relationships.
  4. Attach source and collection date to important findings.

Goal: visualize relationships while maintaining provenance and avoiding false conclusions.

10

AI-Assisted Recon Notes

Organize these authorized lab findings into:
1. confirmed assets
2. unverified leads
3. conflicting evidence
4. safe validation steps
5. defensive recommendations

Goal: use AI to structure and review evidence—not to invent findings or expand beyond the approved scope.

✓Practical Strategy

  • Define the authorized organization, domains, systems, data sources, and collection limits before starting.
  • Begin with passive sources, then use low-impact active queries only when scope permits.
  • For every finding, record the source, timestamp, confidence, validation status, and business relevance.
  • Correlate at least two sources before treating a domain, account, technology, or relationship as confirmed.
  • Do not download sensitive files, contact employees, track recipients, access the dark web, or probe systems unless the lab explicitly authorizes it.
  • Finish with a concise asset map, exposure summary, and defensive recommendations.

Key Takeaways

  • Theory: know passive versus active reconnaissance, major search operators, GHDB, Shodan, WHOIS/RDAP, DNS records, OSINT tools, and countermeasures.
  • Practical: collect, validate, correlate, map, and document authorized information without turning an unverified lead into a false conclusion.
  • Mindset: reconnaissance quality depends on source reliability, freshness, attribution, and context—not simply the amount of data collected.
  • Professional rule: public information is not automatically permission to profile, contact, track, or access; stay inside the written scope.
Next step: complete the Module 02 quiz and validate the key concepts.