Узнай о цели ВСЁ, не отправив ни единого пакета! Google Dorking, Shodan, Maltego, утечки данных — 12 уроков разведки, после которых ни одна компания не сможет спрятать свои секреты от тебя!
Чему ты научишься
✓проводить продвинутый Google Dorking для поиска уязвимой информации
✓анализировать DNS, WHOIS и находить скрытую инфраструктуру
✓находить утечки данных и email-адреса через OSINT-инструменты
✓использовать Shodan, Censys и Maltego для разведки
✓автоматизировать OSINT с theHarvester, Recon-ng и SpiderFoot
✓проводить активную разведку: subdomain enumeration и fingerprinting
Что нужно знать
•
базовое понимание DNS, HTTP и веб-технологий
•умение работать с командной строкой Linux
•общее представление о принципах кибербезопасности
•аккаунты на Shodan и Censys (бесплатные)
Программа
M1
Passive Reconnaissance
4 карт · 4 шагов · тест 13 вопросов
Collect maximum intelligence without leaving traces — Google Dorking, DNS, data leaks and social media reveal more about the target than they realise themselves.
1.
Google Dorking: advanced search operatorsUse advanced Google operators to discover confidential files, exposed admin panels and accidental data leaks.1 шагов
2.
DNS records and WHOIS analysisExtract target infrastructure through DNS records, WHOIS data and domain history.1 шагов
3.
Data leaks and email discoveryFind compromised credentials, employee emails and exposed accounts through public leak sources.1 шагов
4.
Social media and metadata reconnaissanceExtract employee details from social networks and analyse file metadata to build a target profile.1 шагов
M2
OSINT Tooling
4 карт · 4 шагов · тест 13 вопросов
The professional reconnaissance toolbox — from Maltego for relationship visualisation to Shodan for finding vulnerable devices across the globe.
1.
theHarvester and Recon-ngAutomate gathering of emails, subdomains and hosts with theHarvester and the modular Recon-ng framework.1 шагов
2.
Maltego: visualising relationshipsBuild interactive relationship graphs between domains, IPs, emails and people with Maltego.1 шагов
3.
Shodan and Censys: device and service discoveryDiscover open ports, vulnerable services, IoT devices and forgotten servers through Shodan and Censys.1 шагов
4.
SpiderFoot and OSINT automationRun end-to-end automated reconnaissance through SpiderFoot with 200+ modules and a web interface.1 шагов
M3
Active Reconnaissance
4 карт · 4 шагов · тест 14 вопросов
Time to act — subdomain enumeration, port scanning and technology fingerprinting build a complete map of the attack surface.
1.
Subdomain Enumeration: Amass and SubfinderFind every subdomain of a target with Amass and Subfinder — from passive sources to DNS brute force.1 шагов
2.
Port scanning and service detectionUse Nmap to discover open ports, identify service versions and fingerprint target operating systems.1 шагов
3.
Directory Bruteforcing: Gobuster and FeroxbusterDiscover hidden directories, files and endpoints on web servers with Gobuster and Feroxbuster.1 шагов
4.
Technology Fingerprinting: Wappalyzer and WhatWebIdentify the technology stack of web applications — CMS, frameworks, servers, CDN — to look up version-specific vulnerabilities.1 шагов