5:51 · May 2026

Passive Reconnaissance

Passive reconnaissance is where every professional pentest should start. Before you touch the target, you gather everything the internet already knows about them. In this lecture, I walk through three of the most valuable passive recon techniques: WHOIS lookups, Shodan searches, and Google dorking. Done right, these methods surface domains, exposed services, leaked credentials, and misconfigurations without sending a single packet to the target.

Downloads

Goes deeper in these books