Passive and Active Reconnaissance
In the CompTIA Security+ exam, they measure the types of reconnaissance that could be used by an attacker. Let's first look at active and passive reconnaissance and then the tools that can be used to carry out these activities:
- Active Reconnaissance: Active reconnaissance is where someone actively tries to gain information about the system. For example, an attacker finds a username left on one of the corporate desktops; they then ring up the Active Directory team, pretending to be that person, and requests a password reset. This is active reconnaissance, as they have carried out an action.
- Passive Reconnaissance: Passive reconnaissance is where an attacker is constantly gathering information, without the victim's knowledge. For example, an attacker is sitting in a coffee shop when they realize that two members of Company A's security team are having lunch. The attacker listens to every word that is said, and the security...