Avsnitt Course 35 - Footprinting and Reconnaissance | Episode 7: Information Gathering and Domain Reconnaissance Lab CyberCode Academy Spela Dela
In this lesson, you’ll learn about: reconnaissance using Recon-ng1. What is Recon-ng? A full-featured web reconnaissance frameworkPre-installed on Kali LinuxDesigned to automate OSINT and domain reconnaissance 🔹 Core Concept Works like a framework (similar to Metasploit)Uses modules to perform different recon tasks 👉 Purpose: Build a structured database of target intelligence 2. Tool Overview Recon-ng 🔹 Key Capabilities Domain intelligence gatheringContact harvestingSubdomain discoveryFile and directory enumeration 👉 Advantage: Organizes results into a workspace database 3. Workspace & Domain Setup🔹 Initial Steps Create a workspaceAdd target domain 👉 Why it matters: Keeps recon data organized and reusable 4. Contact Harvesting🔹 Module: whois_pocs Extracts:NamesEmail addressesLocations 👉 Use Case: Build a target profileUseful for:Social engineeringOSINT correlation 5. Host Discovery & Stealth🔹 Module: bing_domain_web Finds:HostsIndexed subdomains 🔹 Stealth Feature Recon-ng introduces delays (sleep) between requests 👉 Benefit: Mimics human browsingReduces detection riskAvoids IP blocking 6. Subdomain Brute-Forcing🔹 Module: brute_hosts Uses wordlists to guess subdomains 🔹 Output Hidden subdomainsAssociated IP addresses 👉 Importance: Expands the attack surfaceReveals hidden infrastructure 7. Sensitive File Discovery🔹 Module: interesting_files Searches for:robots.txtBackup filesConfig files 👉 Why it matters: May expose:Hidden directoriesInternal pathsMisconfigurations 8. Analyzing Server Responses🔹 HTTP Status Codes 404 → Resource not found (client-side issue)300-series → Redirection 👉 Insight: Helps understand:Server behaviorApplication structure 9. Cybersecurity Use Case🔹 Reconnaissance Phase Early stage of:Penetration testingBug bounty hunting 🔹 What You Achieve Map:DomainsSubdomainsContactsInfrastructure 👉 Outcome: Clear view of the target environment Key Takeaways Recon-ng is a modular recon frameworkUses workspaces to organize intelligenceAutomates multiple OSINT tasksIncludes stealth techniques to avoid detectionProvides structured data for further testing Big PictureRecon-ng helps you:👉 Move from raw data → structured intelligence databaseMental Model Recon-ng → “Collect + organize recon data”Analysis → “Turn data into actionable insights” You can listen and download our episodes for free on more than 10 different platforms:https://linktr.ee/cybercode_academy Rss Apple Podcaster →