SEC-OSINT-201 · Cybersecurity & intelligence

Open-Source Intelligence (OSINT) Gathering with Recon-ng and Shodan

Build a disciplined, lawful and evidence-led OSINT workflow: define the intelligence question, select passive sources, operate Recon-ng methodically, interpret Shodan observations and produce defensible findings.

Authorisation boundaryCourse exercises use synthetic fixtures, documentation-only values or assets explicitly placed in scope. The course does not authorise private-person profiling, credential testing, bypassing access controls, active scanning or live third-party probing.

Capability outcomes

From search results to defensible intelligence.

Scope and governance

Define purpose, authority, exclusions, data-minimisation rules and stop conditions before collection begins.

Recon-ng methodology

Use workspaces, marketplace metadata, modules, options and passive domain-to-host workflows without treating tool output as truth.

Shodan interpretation

Design bounded queries and interpret time-stamped service observations without assuming current exposure, ownership or vulnerability.

Evidence correlation

Join search, DNS, certificate, repository and service-index evidence while preserving contradictions and uncertainty.

Privacy-aware collection

Collect the minimum data required and use defined escalation routes for secrets, personal data or out-of-scope material.

Reporting

Separate observation, corroboration, inference, confidence, business relevance and recommended defensive action.

Learning map

Full-length course structure

01 · OSINT as an intelligence disciplineRequirements, public-source limits, observation vs inference.
02 · Search-engine reconnaissanceSource planning, query narrowing and result validation.
03 · Recon-ng architectureWorkspaces, data model, installation and evidence handling.
04 · Recon-ng marketplace and modulesDependencies, keys, module selection and passive workflows.
05 · Shodan fundamentalsService observations, filters, counts, facets and host records.
06 · Shodan query designHypothesis-driven queries, timestamps and banner interpretation.
07 · Cross-source correlationDNS, certificates, repositories, service indexes and graph thinking.
08 · Reporting and provenanceReproducibility, evidence records and severity discipline.
09 · Privacy and professional conductPurpose limitation, data minimisation and escalation.
10 · Repeatable OSINT playbookPassive-first decision trees, resilience and source substitution.

Practical evidence

Six labs plus a capstone intelligence brief.

The learning journey includes a collection-plan lab, Recon-ng workspace setup, passive module-selection exercise, synthetic Shodan interpretation, evidence-correlation matrix, the LAB-OSINT-201 browser workbench and a capstone external attack-surface intelligence brief with an executive summary and technical appendix.