According to recent studies:
- 76% of the attacks begin with the reconnaissance phase (Verizon DBIR 2023)
- 68% of organizations suffered OSINT-based attacks in 2023
- On average, attackers spend 247 days in reconnaissance activities before venting an attack
- 92% of business passwords found in the dark web comes from third-party leaks
Information Gathering Methodologies
1. OSINT (Open Source Intelligence)
- Public sources
- Social Media
- Public registers
- WHOIS database
- Specialist search engines
- Advanced Techniques
- Google Dorks
- Metadata Analysis
- Email Pattern Recognition
- Certificate Transparency Logs
2. Passive Information Gathering
Tools and Techniques
# DNS Enumeration
dig +short target.com
whois target.com
host -t ns target.com
# SSL/TLS Analysis
sslscan target.com
testssl.sh target.com
# Subdomain Enumeration
subfinder -d target.com
amass enum -passive -d target.com
3. Active Information Gathering
Network Scanning
# Basic Network Scan
nmap -sS -sV -p- target.com
# Service Detection
nmap -sC -sV --script vuln target.com
# Web Application Scanning
nikto -h target.com
gobuster dir -u target.com -w wordlist.txt
Essential tools
1. Reconnaissance Framework
- Maltego
- Data display
- API integration
- Transform Hub
- SpiderFoot
- OSINT automation
- 200+ integrated modules
- Advanced Reporting
2. DNS Analysis
- DNSRecon
dnsrecon -d target.com -t std
dnsrecon -d target.com -t axfr
- ♪
sublist3r -d target.com -e google,yahoo,bing
3. Web intelligence
- The Harvester
theHarvester -d target.com -b all
- WayBackMachine
- Historical analysis
- Forgotten files
- Exposed configurations
Attack scenarios
1. Social Engineering
# Script esempio per email harvesting
import re
from bs4 import BeautifulSoup
import requests
def extract_emails(domain):
emails = set()
search_urls = [
f"https://www.google.com/search?q=@{domain}",
f"https://www.bing.com/search?q=@{domain}"
]
email_pattern = re.compile(f'[a-zA-Z0-9._%+-]+@{domain}')
for url in search_urls:
try:
response = requests.get(url)
soup = BeautifulSoup(response.text, 'html.parser')
found_emails = email_pattern.findall(soup.text)
emails.update(found_emails)
except Exception as e:
print(f"Error: {e}")
return emails
2. Infrastructure Mapping
# Network topology discovery
nmap -sn 192.168.1.0/24
masscan -p1-65535 192.168.1.0/24 --rate=1000
# Service enumeration
nmap -sV -sC -p- -T4 192.168.1.0/24
3. Data Leakage Detection
# Script per cercate secrets in repository Git
import re
from git import Repo
def scan_repo(repo_path):
repo = Repo(repo_path)
commits = list(repo.iter_commits('master'))
patterns = {
'aws_key': r'AKIA[0-9A-Z]{16}',
'password': r'password.*=.*',
'api_key': r'api[_-]key.*=.*'
}
for commit in commits:
for diff in commit.diff(commit.parents[0]):
for pattern_name, pattern in patterns.items():
matches = re.finditer(pattern, diff.diff.decode())
for match in matches:
print(f"Found {pattern_name} in commit {commit.hexsha}")
Defence measures
1. Digital Footprint Reduction
# Nginx configuration per nascondere informazioni sensibili
server_tokens off;
proxy_hide_header X-Powered-By;
proxy_hide_header Server;
2. Content Security Policy
Content-Security-Policy: default-src 'self';
X-Frame-Options: DENY;
X-Content-Type-Options: nosniff;
Referrer-Policy: no-referrer;
3. DNS Security
# DNSSEC configuration
dnssec-keygen -a RSASHA256 -b 2048 -n ZONE domain.com
dnssec-signzone -A -3 $(head -c 1000 /dev/random | sha1sum | cut -b 1-16) -N INCREMENT -o domain.com -t domain.com.signed
Best Practices of Protection
- Monitoring and Detection
- Implementing SIEM
- Network traffic analysis
- Behavioral analytics
- Policy and Procedures
- Information
- Data handling guidelines
- Security awareness training
- Technical Controls
- WAF implementation
- IDS/IPS deployment
- DLP solutions
Resources
Training
- OSINT Framework
- SANS
- TCM Security OSINT Course
Tools
Documentation
How to Protect
- Asset Management
- Complete inventory
- Classification
- Access control
- Surface Reduction
- Remove unnecessary services
- Regular vulnerability scanning
- Security headers implementation
- Monitoring
- Log analysis
- Network monitoring
- Threat intelligence
Conclusion
Information Gathering is fundamental for both attackers and defenders. The key is:
- Maintain a proactive security program
- Monitoring Exposures constantly
- Implementing laminated controls




