Google hacking is the correct passive reconnaissance activity. Passive reconnaissance collects information without directly interacting with the target’s systems in a way that is likely to trigger alerts. Google hacking uses search engines and advanced search operators to discover publicly indexed information, such as exposed documents, login pages, metadata, directories, or sensitive files. DNS zone transfers require querying the target’s DNS infrastructure and are considered active reconnaissance. Vulnerability scanning sends probes to target systems and is also active. Social engineering interacts with people and attempts to manipulate them, so it is not passive technical reconnaissance. In a penetration test, Google hacking is a classic OSINT method because it gathers public information without touching the target network directly.
================
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit