The objective of the lab is to extract information about the target organization that include, but are not limited to:

  • Organization Information
  • Network Information
  • System Information
  • Windows 11 virtual machine
  • Parrot Security virtual machine
  • Web browsers 
  • Admin privileges to run the tools

✅ LAB 01: Footprinting through Advanced Google Hacking Techniques

Examples:

intitle:login site:example.org

CompanyName filetype:pdf ceh

intitle:”index of” “backup”

✅ Outcome: Discover configuration files, backups, or databases exposed via misconfigured web servers.

✅ LAB 02: Footprinting through Web Services

✅ Find Company’s Domains, Subdomains, and Hosts

✅ LAB 03: Footprinting through WHOIS Lookup

whois example.com

✅ Outcome: Domain owner, admin contact, registrar, DNS details, hosting provider.

✅ LAB 04: Footprinting through Email Footprinting

theharvester -d example.com -b google

✅ Outcome: Collects emails and hosts related to the domain using public search engines.

✅ LAB 05: Footprinting using Social Networking Sites

cd sherlock

sherlock “Elon Musk”

Search:

  • Employee names
  • Job roles + tech stack (e.g., “admin AWS site:linkedin.com”)

✅ Outcome: Gather information about a target person over various social networking sites.

✅ LAB 06: Gather DNS information

Use:

Windows Command Prompt:

>nslookup

>set type=a 

>www.example.com

  • do the same thing with set type=cname

Online Tool:

https://www.kloth.net/services/nslookup.php

Wappalyzer browser extension

✅ Outcome: domain name, IP address mapping .

✅ LAB 07: Network Tracerouting

Windows Command Prompt:

>tracert www.example.com

Linux Command Prompt:

$traceroute www.example.com

✅ LAB 08: Email Tracking

✅ Outcome: Know if an email was opened, IP address of reader, location, device.

✅ LAB 09: Using Maltego for Footprinting

Steps:

  1. Open Maltego
  2. Start a new graph
  3. Add domain entity: example.com
  4. Run transforms to gather DNS, email, phone, subdomains

✅ Outcome: Visualized entity relationships (people, emails, websites, infrastructure).

✅ LAB 10: Perform Footprinting with AI

Objective: Automate service enumeration using sgpt.

sgpt –shell “Footprint the target** **website www.example.com“

**✅ Ask ShellGPT using prompt **

🧠 CEH Tip:

✅ Start with Google Dorks
Use advanced search operators to uncover exposed login portals, misconfigured servers, and sensitive files.
🧠 Tip: Try intitle:”index of” site:example.com to find open directories.

✅ Map the Digital Surface
Tools like Netcraft, DNSDumpster, and Whois reveal domain structure, DNS records, hosting providers, and more.
🔗 Tip: Always combine passive (Netcraft, Whois) and active (nslookup, dig) methods.

✅ Harvest Intelligence with OSINT
Use TheHarvester and Sherlock to extract emails, usernames, and social media accounts linked to your target domain.
🧠 Tip: Filter by platform for better profiling, e.g., site:linkedin.com AWS engineer.

✅ Visualize Infrastructure
Use Maltego to build a relationship graph of domains, emails, and subdomains.
🔗 Tip: Great for connecting the dots between people, systems, and leaked data.

✅ Use AI to Speed It Up
ShellGPT can automate information gathering across tools.
💡 Example Prompt:
sgpt –shell “Extract WHOIS info and DNS records for example.com”