Skip to content

Passive Reconnaissance

Passive recon means gathering all possible information about a target without interacting directly with its infrastructure: you send no packets to its servers, scan no ports, touch nothing that leaves a trace in its logs. You rely on third-party sources (public DNS, certificates, search engines, social networks, leaks) that already hold the data. It’s the first phase of every pentest and the stealthiest: the target never notices.

Every passive datum reduces the noise you’ll make later. Before scanning you already know the subdomains, the cloud provider, the mail, the technologies, and sometimes leaked credentials. Plus, in bug bounty and red team, the more you get without touching the target, the lower the chance of being detected before you even start.

Sources and techniques (without touching the target)

Section titled “Sources and techniques (without touching the target)”
# DNS and historical DNS (third-party sources)
SecurityTrails, DNSdumpster, VirusTotal
# Certificate Transparency: subdomains via issued certificates
crt.sh, censys.io
# search engines specialized in exposed devices/services
Shodan, Censys, FOFA, ZoomEye (see recon-shodan)
# Google dorking: files, panels, indexed leaks
site:, filetype:, inurl: (see recon-dorking)
# social and professional networks
LinkedIn (employees), GitHub (code/secrets), Twitter
# credential leaks
HaveIBeenPwned, Dehashed, leak databases
# historical archive
Wayback Machine, archive.today
amass enum -passive -d target.com # subdomains from many passive sources
subfinder -d target.com # passive subdomains
theHarvester -d target.com -b all # emails, hosts, names
spiderfoot / recon-ng # automated OSINT frameworks
maltego # relationship graphs (see recon-maltego)

What turns “passive” into “active” is touching the target’s infrastructure: a query to crt.sh is passive; an nmap against its IPs is active. A dig to a public resolver is passive; a zone transfer against its NS is active. The boundary matters for stealth and, sometimes, legal scope.

  • Use third-party sources and, if you query something attributable, do it from infrastructure not linked to you.
  • Don’t authenticate with your real accounts on target portals during recon.
  • Save and organize everything (domains, IPs, emails, technologies) in your vault for the active phase.

An organization reduces its passive footprint by: minimizing data in certificates and DNS, reviewing what employees leak on GitHub/LinkedIn, monitoring Certificate Transparency and leaks (HIBP), and stripping metadata from published documents.

  • Domains and subdomains collected (amass/subfinder/crt.sh)
  • Org IPs, ranges, and ASN
  • Technologies and providers identified
  • Emails and employees (theHarvester, LinkedIn)
  • Search for leaked secrets (GitHub, leaks, HIBP)
  • Documents and metadata collected
  • History reviewed (Wayback)
  • Everything organized in the vault for the active phase