As mentioned previously, the first stage of a penetration test is to gather as much information as possible on a given target or organization. Gathering information prior to exploiting and gaining access to a network or system will help the penetration tester narrow the scope of the attack and design specific types of attacks and payloads that are suitable for the attack surface of the target. We will begin our information-gathering phase by utilizing the largest computer network in existence: the internet.
The following diagram provides a brief overview of the different areas where OSINT can be found on a target:
The internet has many platforms, ranging from forums and messaging boards to social media platforms. A lot of companies create an online presence to help market their products and services to potential clients. In doing so, the creation of a company...