OSINT for Penetration Testing Reconnaissance

OSINT penetration testing reconnaissance gives your tester the attacker's starting map before the first scan: assets you forgot you had, which ones are really yours, which sit with cloud and hosting providers, and what your staff and code reveal. We do it as a separate, authorized phase and hand over a pack your tester can use on day one.

  • Written authorization only
  • Every asset checked for ownership
  • Out-of-scope list included
  • Handover pack for your tester
Short answer

OSINT penetration testing reconnaissance is the information-gathering phase of a pentest, done from public and commercially available sources before any active testing. OSINT-S finds your internet-facing assets, confirms which are yours and which belong to providers, records exposed technology, people and leaked credentials, and delivers a scoped target list and an out-of-scope list. The active testing stays with your authorized tester.

Black-Box, Grey-Box and OSINT Penetration Testing Recon

The less your tester is told, the more the test depends on reconnaissance. A separate recon phase is most useful for black-box and threat-led tests.

Test typeWhat the tester is givenRole of OSINT recon
Black-boxOnly the company name or a main domainBuilds the target list from scratch, as an attacker would
Grey-boxAsset list, some accounts or documentationFinds what the list missed: shadow IT, old subdomains, acquired brands
White-boxFull architecture and source accessShows what outsiders can see, so findings can be ranked by real exposure
Threat-led or red teamObjectives and threat scenariosSupplies the intelligence that scenarios are built on

Buying recon as its own phase, from a team that does not run the exploitation, also gives you a second view of your estate that you can compare with the tester's results.

Scope Validation: Is Every Asset Really Yours?

Recon routinely finds hosts that look like yours but belong to a supplier, a former subsidiary or a shared cloud service. Testing them without permission is the commonest scope mistake.

Each asset we find is put in one of three groups, with the evidence for the decision: owned and in scope, owned but excluded by your rules of engagement, or not yours. Typical "not yours" cases are a marketing agency's hosting, a SaaS login page on your subdomain, a former subsidiary sold years ago and shared content delivery addresses.

Cloud assets need a further check because providers set their own rules. AWS, for example, lets customers test listed services on their own accounts without prior approval, but prohibits activities such as DNS zone walking through Route 53 hosted zones, denial-of-service testing, request flooding and S3 bucket or subdomain takeover (AWS penetration testing policy). We flag where each asset is hosted so your tester can check the right policy before touching it. A possible subdomain takeover is reported to you as a finding to fix, never claimed to prove it.

OSINT Recon in Web Application and Threat-Led Tests

Web application methodologies start with search-engine reconnaissance, and regulated threat-led tests require a formal threat intelligence phase.

Web application tests. The OWASP Web Security Testing Guide v4.2 opens its information gathering section with search engine discovery reconnaissance for information leakage, followed by tests such as reviewing webpage content for leakage and mapping application architecture (OWASP WSTG). We cover the public-source part: indexed admin pages, exposed documents, old API documentation and archived versions of the application.

Threat-led penetration testing in EU finance. Under the DORA standard on threat-led penetration testing, a threat intelligence provider analyzes generic and sector-specific threat intelligence for the financial entity, proposes scenarios that target each critical or important function in scope, and delivers a targeted threat intelligence report; the control team selects at least three scenarios. The recitals note that gathering typically takes about four weeks (Delegated Regulation (EU) 2025/1190, Article 10). Formal provider requirements apply to those tests, so we confirm with your test manager what role our reconnaissance can play before scoping.

The Recon Handover Pack for Your Tester

Six components in machine-readable and written form, so the tester spends day one testing, not searching.

Targets

In-scope asset list

Domains, subdomains, IP ranges and applications, each with ownership evidence and the date it was confirmed.

Exclusions

Out-of-scope list

Assets that look like yours but are not, with the reason, so nobody tests a supplier by accident.

Technology

Public fingerprints

Software, versions and services visible in public scan data, job ads and documentation.

Credentials

Exposure summary

Accounts in breach and stealer data, matched to current staff. We never test them; your rules decide whether the tester may.

Sources

Method notes

What was searched, when and with which tools, so results can be repeated after fixes.

Timelines, Authorization and Limits

Recon for a focused test from 10 business days, larger estates up to about a month, always under a signed authorization.

Recon for a focused external or web application test takes from 10 business days after the authorization is signed; a group with many brands, acquisitions or regions takes up to about a month. Urgent delivery costs 50% more, the price is fixed after written scoping, a senior analyst reviews the pack and the fee goes down if we miss the agreed date. We plan backwards from your tester's start date.

Our work stays passive: no scanning, exploitation, credential testing or takeover attempts. Employee data is minimized and deleted at the end as agreed under the GDPR and similar laws. If you are choosing tools to run recon in-house, see our reviews of theHarvester and Recon-ng. For the full method, including ATT&CK mapping and the exposure map, see red team OSINT reconnaissance; for other OSINT services for security teams, see the overview.

Give Your Tester the Attacker's Starting Map

Send the test type, the domains or brands in scope, the tester's start date and who will sign the authorization. We reply with scope and a fixed price.

OSINT Penetration Testing FAQ

We've booked a black-box external pentest for next month and the vendor will only get our company name — is it worth buying OSINT penetration testing reconnaissance separately first?

Usually, yes. In a black-box test the result depends on what reconnaissance finds, and a separate OSINT penetration testing phase gives you a validated target list, an out-of-scope list and a second view of your estate to compare with the tester's. If your vendor's own recon is strong, you can share our pack after the test instead to see what each side missed.

Your recon found a login page on one of our subdomains that is actually run by a SaaS provider — can our tester still attack it as part of the pentest?

Not without the provider's permission. Your authorization covers what you own or control; a SaaS application on your subdomain belongs to the provider, whose own testing policy applies. We list it in the out-of-scope pack with the reason. Report any concern to the provider, or ask them whether they allow customer testing and under what conditions.

We are an EU bank preparing for a DORA threat-led penetration test — can your OSINT reconnaissance be used in the threat intelligence phase?

Possibly, but check with your test manager first. The DORA standard requires a threat intelligence provider to deliver a targeted threat intelligence report with scenarios for each critical or important function, and formal provider requirements apply. Our reconnaissance can support that work, for example on your external exposure, but the role has to be agreed with your control team and the provider before scoping.

Our tester asked for any leaked employee passwords you find so they can try them against our VPN — will you hand those over?

Only if your rules of engagement allow it and through the channel they specify. We match leaked credentials to current staff and report them, but we never try them ourselves. Many organizations prefer to reset affected accounts immediately and let the tester simulate the access instead. The decision belongs to whoever signed the authorization, and we follow it in writing.

How long before our pentest start date should we book OSINT reconnaissance, and what do you need from us to begin?

Book at least three weeks ahead for a focused test, more for a large group. We need the signed authorization, the domains, brands and business units in scope, known exclusions, the tester's start date and a contact for urgent findings. Recon itself takes from 10 business days; urgent delivery is available for an extra 50%.