100% Free Forever
AI-Powered Learning
Industry Expert Content
Certificates & Badges
Learn At Your Own Pace
Offensive Security & Penetration Testing
30 minadvanced

Passive recon — OSINT, WHOIS and certificate transparency

Passive reconnaissance gathers intelligence about a target from public sources without ever sending traffic to the target's own systems. By querying registries, search engines, and public logs, a tester maps domains, technologies, and exposed assets while remaining invisible to the target. This quiet phase shapes every later decision, revealing where the attack surface lives before any active probe risks detection. Done well, passive recon turns a blank scope into a rich, structured picture of an organization.

Analogy🏏Cricket
🏏 Think of it like cricket: Active recon is the captain walking out to inspect the pitch on match morning, pressing the surface, checking the grass, watching how the ball behaves in the nets. Unlike studying old footage from afar, this inspection happens on the ground itself and is visible to everyone. Just as that inspection reveals conditions no video could, active scanning reveals live services no public record shows, and just as it happens with the ground's permission, scanning happens only within authorized scope.
Lesson 2 of 35
0% complete