0% found this document useful (0 votes)
3 views44 pages

CPENT Module 03 Open Source Intelligence (OSINT)

The document outlines the methodology and tests for conducting Open-Source Intelligence (OSINT) as part of the Certified Penetration Testing Professional program by EC-Council. It includes various tests to gather information about a target organization, such as domain identification, employee enumeration, and social media analysis. Each test provides sections for recording results, tools used, and analysis, emphasizing the importance of thorough data collection in penetration testing.

Uploaded by

program85
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views44 pages

CPENT Module 03 Open Source Intelligence (OSINT)

The document outlines the methodology and tests for conducting Open-Source Intelligence (OSINT) as part of the Certified Penetration Testing Professional program by EC-Council. It includes various tests to gather information about a target organization, such as domain identification, employee enumeration, and social media analysis. Each test provides sections for recording results, tools used, and analysis, emphasizing the importance of thorough data collection in penetration testing.

Uploaded by

program85
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

EC-Council Certified Penetration Testing Professional

Certified Penetration Testing Professional

Methodology: Open-Source Intelligence (OSINT)

Penetration Tester:
Organization:
Date: Location:

Confidential 1 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1: OSINT through the WWW

Test 1.1: Find the Domain and Sub-domains of the Target

Target Organization
URL
Search Engine Used
Found the Domain and Sub-domains of the Target Successfully? Yes No

Attack Surfaces of
Target Organization
Command Used
Domain and Sub- 1.
domains Identified 2.
3.
4.
5.

Results Analysis:

Confidential 2 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.2: Find Similar or Parallel Domain Names

Target Organization
URL
Country Code URL

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 3 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.3: Refine Web Searches using Advanced Operators

Target Organization
URL
Search Engine Used
Refined Your Web Yes No
Searches using
Google’s Advanced
Operators?
Google’s Advanced 1.
Operators Used 2.
3.
4.
5.
6.
7.
8.
9.
10.

Queries to find,
filter, and sort
Specific
Information
Information
Gathered
Technique Used
GHDB Search Query Used Information Gathered

Confidential 4 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Tools Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 5 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.4: Footprint the Target using Shodan

Target Organization
URL
Successfully Blueprinted the Target using Shodan? Yes No
Devices Identified Webcam
using Shodan Router
Switches
Others Specify

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 6 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.5: Find the Geographical Location of a Company

Target Organization
URL
Location of the
Organization
Recovered Maps? Yes No
Neighboring 1.
company and 2.
famous landmarks
3.
4.
5.

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 7 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.6: List Employees and their Email Addresses

Target Organization

URL

Employee Name Email IDs/Contact Details

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 8 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.7: Identify Key Email Addresses through Email Harvesting

Target Organization
URL
Command used
Domain Name Employee Name Email IDs

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 9 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.8: Enumerate Key Email Addresses from Pastebin and HaveIBeenPwned

Target
Organization

URL

Pastebin
HaveIBeenPwned
Others Specify
Website(s) used

Employee Name Telephone Date of Birth Email Residential Address

Tools/Services 1.
Used 2.
3.
4.
5.

Confidential 10 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Results Analysis:

Confidential 11 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.9: List Key Personnel of the Company

Target Organization
URL
Search Engine Used
Job Sites
Work Completed Accomplish
Employee Name Resumes
experience projects
Promotions
ments

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 12 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.10: Using People Search Online Services to Collect Information

Target
Organization

URL

Date Satellite pictures


Employee Contact Residential
of Email Photo of private
Name Number Address
Birth residencies

Yes Yes
No No
Yes Yes
No No
Yes Yes
No No
Yes Yes
No No
Yes Yes
No No
Yes Yes
No No
Yes Yes
No No
Yes Yes
No No
Yes Yes
No No
Yes Yes
No No

Any other
information
found:

Confidential 13 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Tools/Services 1.
Used 2.
3.
4.
5.

Results Analysis:

Confidential 14 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.11: Browse Social Network Websites to Find Information on the Company and
Employees

Target Organization
URL
Information gathered

Social Networks 1.
Used 2.
3.
4.
5.

Results Analysis:

Confidential 15 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.12: Use Web Investigation Tools to Extract Sensitive Data about the Company

Target Organization
URL
Information 1.
Gathered 2.
3.
4.
5.
6.
7.
8.
9.
10.

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 16 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.13: Identify the Type of Network Devices used in the Organization

Target Organization
URL

Search Engines Used


Sources Used to
Gather relevant
Information
Company’s Oracle database server
Infrastructure in the Cisco routing devices
Organization Checkpoint firewalls
Any other, specify

Network Devices
Identified

Tools/Techniques 1.
Used 2.
3.
4.
5.

Results Analysis:

Confidential 17 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.14: Look for the Sensitive Information in Email Headers

Target Organization
URL
Information on
Recipient’s MIME- Geo- Device
Email ID browser and
IP address Version location Type
operating system

Any other
information found:

Tools/Techniques 1.
Used 2.
3.
4.
5.

Results Analysis:

Confidential 18 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.15: Look for Valuable Information in NNTP Usenet Newsgroups

Target Organization
Newsgroups Used to
gather Information
Information
Gathered

Tools/Techniques 1.
Used 2.
3.
4.
5.

Results Analysis:

Confidential 19 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.16: Other Useful Footprinting Activities to Find Information about the Target

§ Search for the company’s information in online trade association directories


Target Organization
URL
Information
Gathered

Tools/Techniques 1.
Used 2.
3.
4.
5.

Results Analysis:

§ Collect the company’s information through groups, forums, and blogs


Target Organization
URL
Groups/Forums/Blogs
used for gathering
information

Confidential 20 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Public network
information found

System information
found

Employee
information found

Tools/Techniques 1.
Used 2.
3.
4.
5.

Results Analysis:

§ Search for press releases issued by the company using Google/Yahoo Finance
Target Organization
URL
Tools used Google Finance
Yahoo Finance
Any other, specify

Confidential 21 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Information
Gathered

Tools/Techniques 1.
Used 2.
3.
4.
5.

Results Analysis:

§ Search for the link popularity of the company’s website


Target Organization
URL
Information
Gathered

Confidential 22 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Tools/Techniques 1.
Used 2.
3.
4.
5.

Results Analysis:

§ Monitor the target using alerts such as Google Alerts, Yahoo Alerts, and Twitter Alerts
Target Organization
URL
Alert used Google Alerts
Yahoo Alerts
Twitter Alerts
Any other, specify

Information
Gathered

Confidential 23 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Tools/Techniques 1.
Used 2.
3.
4.
5.

Results Analysis:

§ Gather competitive intelligence by visiting websites such as EDGAR Database, Business


Wire, LexisNexis, and Hoovers
Target Organization
URL
Website used EDGAR Database
Business Wire
LexisNexis
Hoovers
Any other, specify

Company’s Strategy Location of the


Branch
establishment date used company

Confidential 24 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Tools/Techniques 1.
Used 2.
3.
4.
5.

Results Analysis:

§ Search and list the products/services sold by the company


Target Organization
URL
Email Product Product Price

Confidential 25 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Tools/Techniques 1.
Used 2.
3.
4.
5.

Results Analysis:

§ Compare the prices of products or services with those of the competitor


Target Organization
URL

Merchant ratings of the


company

Customer reviews

List of products and


services provided by the
company
Tools/Techniques Used 1.

Confidential 26 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

2.
3.
4.
5.

Results Analysis:

Confidential 27 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2: OSINT through Website Analysis

Test 2.1: Search Contact Information, Email Addresses, and Telephone Numbers from
Company Website

Target Organization
URL
Contact Numbers 1.
2.
3.
4.
5.
Email IDs 1.
2.
3.
4.
5.
Addresses 1.
2.
3.
4.
5.
Company’s Location 1.
and Branches 2.
3.
4.

Partner’s 1.
Information 2.
3.
4.

Confidential 28 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

5.
Any other
information found

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 29 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2.2: Search for Web Pages Posting Patterns and Revision Numbers

Target Organization
URL
Page URL Revision Date Nature of the Revision
1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
11.
Any other
information found

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 30 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2.3: Search [Link] for Old Information about the Company

Target Organization
URL
Page URL Search Date Page Found
1. Yes No
2. Yes No
3. Yes No
4. Yes No
5. Yes No
Any other
information found

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 31 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2.4: Monitor Web Updates using WebSite-Watcher

Target Organization
URL
Page URL Revision Date Nature of the Revision
1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
11.
Any other
information found

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 32 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2.5: Examine HTML Source of the Web Pages

Target Organization
URL
HTML Source
Information
Gathered

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 33 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 3: OSINT through DNS Interrogation

Test 3.1: Perform Whois Lookups

Target Organization
URL
Registrars Searched African Network Information Centre (AfriNIC)
American Registry for Internet Numbers (ARIN)
Asia-Pacific Network Information Centre (APNIC)
Latin America and Caribbean Network Information Centre
(LACNIC)
Reseaux IP Europeens Network Coordination Centre (RIPE
NCC)
Any other, specify

Registrant Address

Domain name details

IP address and
Network Range

Physical Location
Administrative
Contact

Confidential 34 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Technical Contact

Record Created On
Record Expires On
Database Last
Updated On
Domain Servers In 1.
Listed Order 2.
3.
4.
5.

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 35 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 3.2: Find IP Address Block Allocated to the Organization

Target Organization
URL
Found IP Range Yes No
Successfully?
IP Registries Used
Whois database
Used
IP Range Identified
NSLookup Command
Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 36 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 3.3: Find the DNS Records for Domain

Target Organization
URL
Command Used
DNS Records
Name Class Type Data TTL

Any other
information found

Tools/Services Used 1.
2.
3.
4.
5.

Confidential 37 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Results Analysis:

Confidential 38 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 3.4: Perform Reverse Lookups

Target Organization
URL
Performed Reverse
DNS Lookup Yes No
Successfully?
Commands Used

IP Range for Reverse


DNS lookup
DNS PTR records
found

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 39 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 3.5: Perform DNS Zone Transfer

Target Organization
URL
Performed DNS Zone
Yes No
Transfer Successfully?
Gathered DNS
Information
dig Commands Used
to perform DNS Zone
Transfer
nslookup Commands
Used to perform DNS
Zone Transfer
dnsrecon Commands
Used to perform DNS
Zone Transfer
Identified Host
Names
Identified Machine
Names
Identified
Usernames
Identified IP
Addresses
Any other
information found

Tools/Services Used 1.
2.
3.
4.
5.

Confidential 40 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Results Analysis:

Confidential 41 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 3.6: Draw a Network Diagram using Traceroute Analysis

Target Organization
URL
Conducted
Traceroute Yes No
Successfully?
Extracted
Information after
conducting
Traceroute
Is Network Diagram
drawn successfully
Yes No
using Traceroute
Analysis?
Commands Used to
perform Traceroute
Any other
information found

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 42 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 3.7: Create Topological Map of the Network

Target Organization
URL
Created Physical and
Logical Topological
Map of the Network Yes
based on If Yes, attach a copy of the No
Information network topology map
Gathered through
Traceroute?
Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 43 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 4: Automating your OSINT Effort using Tools/Frameworks/Scripts

Target Organization
URL
Is OSINT Efforts
automated by using Yes No
Tools/Frameworks/Scripts?
Tools/Frameworks/Scripts 1.
Used 2.
3.
4.
5.

Information Gathered

Results Analysis:

Confidential 44 Template OSINT Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.

You might also like