Discovering exposed systems
During the reconnaissance phase, it’s essential for ethical hackers and penetration testers to identify the internal and external network infrastructure of their targets, as such information is useful for identifying the attack surface and attack vectors and developing exploits for future operations. Organizations often connect their systems and networks to the internet without performing a reconnaissance or OSINT penetration test on their own infrastructure to determine whether any of their assets are unintentionally exposed on the internet. Ethical hackers and penetration testers are hired by organizations to identify how their systems and network infrastructures are exposed and how their attack surface can be reduced to prevent future cyber-attacks and threats.
During this section, you will learn how threat actors and cybersecurity professionals can collect OSINT from specialized search engines to identify an organization’s infrastructure...