CyberNotes
Reconnaissance/Passive Recon

Passive Reconnaissance

Gathering information about a target system or network without directly interacting with it

Passive reconnaissance activities include many activities, for instance:

  • Looking up DNS records of a domain from a public DNS server.
  • Checking job ads related to the target website.
  • Reading news articles about the target company.

whois / nslookup / dig

PurposeCommandline
Lookup WHOIS recordwhois google.com
Lookup DNS A recordsnslookup -type=A google.com
Lookup DNS MX records at DNS servernslookup -type=MX google.com 1.1.1.1
Lookup DNS TXT recordsnslookup -type=TXT google.com
Lookup DNS A recordsdig google.com A
Lookup DNS MX records at DNS serverdig @1.1.1.1 google.com MX
Lookup DNS TXT recordsdig google.com TXT

Other Resources

On this page