
Explore ethical osint recon to ship reports with public data. Map domains with whois and dns, pull subdomains from certificate transparency logs, and x-ray the internet with Shodan and Censys.
Master open-source intelligence through a practical, ethical workflow to collect, process, analyze, and disseminate public data from websites, social platforms, certificate transparency logs, documents, press releases, and code repositories.
Follow three guardrails: use public data only, avoid exploitation, and stay professional. Define scope, log sources with timestamps, minimize PII, and map domains with whois and dns.
Use whOIs as the internet phone book to reveal registrars, name servers, and domain timelines. Employ pivoting and reverse WHOIS to uncover interconnected assets and technical clues.
Explore WHOIS as the original domain registration lookup to reveal a domain's life cycle, registrar, creation and expiry dates, registrant details, and DNS name servers for OSINT.
Discover subdomain infrastructure through certificate transparency logs and DNS enumeration using crt.sh, whois, and DNS tools like dig and nslookup, revealing mappings from DNS records to hosting and email services.
Explore crt.sh and dns osint to map a domain's infrastructure by examining ssl certificates, subdomains, a records, and dns records as mx and txt with spf, dkim, and dmarc.
Explore OSINT quick recon with email footprinting basics, using theharvester and Google advanced search operators to uncover Gmail addresses, LinkedIn and Twitter profiles, and data breaches.
Master practical, legal osint with theHarvester to map public data from NASA.gov and identify subdomains. Pivot with Epieos to validate emails and active platforms.
Learn to use Have I Been Pwned to check email breaches, and practice data correlation to map usernames, domains, and digital footprints within legal, public data.
Explore how Have I Been Pwned and Google dorking reveal publicly exposed data, helping beginners audit their own footprints with awareness, not exploitation, in open-source intelligence contexts.
Extract metadata with ExifTool to reveal hidden details in files, and use Metagoofil to extract metadata from documents for OSINT investigations, including GPS data in images.
Explore how metadata reveals hidden clues such as usernames, GPS coordinates, and internal file paths with exiftool, then scale with metagoofil to audit an organization, noting NASA's sanitized public documents.
Images embed GPS metadata in exif data, revealing coordinates and privacy risks; strip metadata with ExifTool using the all flag or remove specific fields, plus MAT2 or online tools.
Learn to strip metadata to prevent OSINT leaks using ExifTool for single files and MAT2 for batch cleanup, ensuring GPS data, timestamps, and author info are removed before publishing.
Explore Google dorking using site, filetype, intitle, inurl, and cache operators to create targeted OSINT searches that reveal publicly accessible login pages, documents, and administration panels.
Identify publicly indexed administration panels, forgotten login pages, and unsecured network cameras using Google dorking, inurl, and intitle, while safely locating documents with filetype searches.
Explore Google dorking with advanced operators to surface publicly indexed content, including PDFs, Word docs, and metadata, across NASA.gov and beyond, including login portals and index of directories.
Shodan indexes internet-connected devices, revealing open ports, services, and banners to map a target's digital footprint and identify vulnerabilities using filters.
Explore Shodan's filtering and vuln filter to identify internet-connected devices and CVEs. Then use Censys' certificate-centric SSL/TLS data to map a domain's digital footprint.
Discover how Shodan and Censys act as search engines for the internet of devices, revealing open ports, banners, and certificates to audit your own infrastructure ethically.
Organize OSINT findings into logical categories with tagging to turn raw data into clear, actionable insights. Use a simple markdown template and tools like Obsidian or Notion for fast reporting.
Conduct a fast, lawful osint recon on a safe target using whois, crt.sh, theharvester, google dorking, shodan, and censys to deliver a structured public-data report.
Apply practical OSINT tools and a curious mindset to uncover intelligence hidden in plain sight, while staying ethical, legal, and respectful of privacy.
Learn how to investigate the internet like a professional with this beginner OSINT course. OSINT (Open-Source Intelligence) is the practice of collecting and analyzing publicly available information — a key skill for cybersecurity, ethical hacking, journalism, and digital investigations.
In this hands-on course, you’ll follow a Quick Recon method: fast, legal OSINT techniques you can apply immediately. Each module includes practical demos using real tools, so you won’t just hear about theory — you’ll actually practice.
You will learn how to:
Perform WHOIS lookups and DNS recon to uncover domain details and subdomains
Use crt. sh for certificate transparency research
Find exposed emails and credentials with theHarvester and Have I Been Pwned
Extract hidden metadata from files and images using ExifTool, Metagoofil, and MAT2
Master Google Dorking to reveal login portals, sensitive files, and misconfigurations
Search for exposed systems and services with Shodan and Censys
Organize your OSINT findings with professional reporting templates
Whether you are a cybersecurity student, ethical hacker, penetration tester, or curious beginner, this course will give you the core OSINT skills to perform safe, ethical, and impactful investigations.
Join now and start mastering practical open-source intelligence with OSINT Quick Recon — and build a foundation for your future in cybersecurity.