1---2name: performing-open-source-intelligence-gathering3description: Open Source Intelligence (OSINT) gathering is the first active phase of a red team engagement, where operators collect publicly available information about the target organization to identify attack s4license: Apache-2.05---6# Performing Open Source Intelligence Gathering78## Overview910Open Source Intelligence (OSINT) gathering is the first active phase of a red team engagement, where operators collect publicly available information about the target organization to identify attack surfaces, potential targets for social engineering, technology stacks, and credential exposures. Effective OSINT directly shapes initial access strategies and reduces operational risk.1112## Objectives1314- Enumerate the target organization's external attack surface (domains, IPs, cloud assets)15- Identify employees and their roles for social engineering targeting16- Discover leaked credentials, API keys, and sensitive documents17- Map the organization's technology stack and vendors18- Identify physical locations, office layouts, and access control details19- Build target profiles for spearphishing campaign development2021## Core Concepts2223### OSINT Categories2425| Category | Sources | Value |26|----------|---------|-------|27| Domain Intelligence | DNS records, WHOIS, CT logs, subdomain enumeration | Network attack surface |28| Personnel Intelligence | LinkedIn, social media, conference talks, publications | Social engineering targets |29| Credential Intelligence | Breach databases, paste sites, GitHub leaks | Valid credential discovery |30| Technology Intelligence | Job postings, Wappalyzer, Shodan, Censys | Vulnerability identification |31| Physical Intelligence | Google Maps, social media photos, Glassdoor | Physical access planning |32| Document Intelligence | SEC filings, public documents, metadata extraction | Organizational structure |3334### MITRE ATT&CK Mapping3536- **T1595.001** - Active Scanning: Scanning IP Blocks37- **T1595.002** - Active Scanning: Vulnerability Scanning38- **T1592** - Gather Victim Host Information39- **T1589** - Gather Victim Identity Information40- **T1590** - Gather Victim Network Information41- **T1591** - Gather Victim Org Information42- **T1593** - Search Open Websites/Domains43- **T1594** - Search Victim-Owned Websites44- **T1596** - Search Open Technical Databases4546## Implementation Steps4748### Phase 1: Domain and Network Reconnaissance491. Perform WHOIS lookups for target domains502. Enumerate subdomains using Certificate Transparency logs, DNS brute-force, and web scraping513. Identify IP ranges and ASN ownership524. Scan for exposed services using Shodan/Censys535. Check for cloud storage buckets (S3, Azure Blob, GCS)546. Map CDN and hosting providers5556### Phase 2: Personnel and Social Intelligence571. Enumerate employees via LinkedIn, company website, and conference speaker lists582. Identify email naming conventions593. Discover personal social media accounts of key targets604. Map organizational hierarchy and reporting structure615. Identify recently hired IT/security personnel626. Check for conference presentations and technical publications6364### Phase 3: Credential and Data Leak Discovery651. Search breach databases (Have I Been Pwned, DeHashed)662. Check paste sites (Pastebin, GitHub Gists)673. Search GitHub/GitLab for leaked secrets and API keys684. Look for exposed configuration files and backups695. Check for leaked internal documents via Google dorking7071### Phase 4: Technology Stack Identification721. Analyze job postings for technology mentions732. Use Wappalyzer/BuiltWith for web technology fingerprinting743. Check for exposed admin panels and development environments754. Identify VPN and remote access technologies765. Map cloud services and SaaS applications7778## Tools and Resources7980| Tool | Purpose | Type |81|------|---------|------|82| Amass | Subdomain enumeration and network mapping | Open Source |83| Subfinder | Passive subdomain discovery | Open Source |84| theHarvester | Email, subdomain, and name harvesting | Open Source |85| Maltego | Visual link analysis and data correlation | Commercial |86| SpiderFoot | Automated OSINT collection | Open Source |87| Shodan | Internet-connected device search | Commercial |88| Censys | Internet asset discovery | Commercial |89| Recon-ng | Web reconnaissance framework | Open Source |90| GitDorker | GitHub secret scanning | Open Source |91| Photon | Web crawler for OSINT | Open Source |9293## Validation Criteria9495- [ ] Complete list of target domains and subdomains96- [ ] Employee list with roles and email addresses97- [ ] Technology stack identified98- [ ] Credential leak assessment completed99- [ ] Attack surface map documented100- [ ] OSINT report compiled for engagement team