Corporate Reconnaissance
Corporate reconnaissance is a foundational phase in social engineering campaigns, involving the systematic collection of publicly available information about an organization to identify vulnerabilities, map relationships, and tailor attacks. This phase leverages open-source intelligence (OSINT) tools, web scraping, and network analysis to build a comprehensive profile of the target. Below are key methodologies and techniques used in corporate reconnaissance.
Web Scraping and Archive Analysis¶
Web scraping is a critical technique for extracting data from an organization’s website, including contact information, job postings, and infrastructure details. Tools like curl, wget, and Python libraries such as BeautifulSoup or Scrapy are commonly used.
Example: Extracting job titles from a company’s careers page
import requests
from bs4 import BeautifulSoup
url = "https://example-company.com/careers"
response = requests.get(url)
soup = BeautifulSoup(response.text, "html.parser")
for job in soup.find_all("div", class_="job-title"):
print(job.text.strip())
Archive analysis involves using the Wayback Machine (archive.org) to retrieve historical snapshots of a company’s website. This can reveal outdated contact details or internal documentation.
OSINT Platforms and Social Media¶
Social media platforms like LinkedIn, Twitter, and Facebook are rich sources of employee data, organizational hierarchies, and event schedules. Tools like Maltego, SpiderFoot, and Hunter.io automate the aggregation of this data.
Example: Using linkedin-scraper to extract employee roles
from linkedin_scraper import Profile
profile = Profile("https://linkedin.com/in/john-doe")
print(profile.name, profile.job_title)
Tip: Search for company hashtags (e.g., #ExampleCorp) or event mentions to identify internal communication channels or upcoming conferences.
Network and Infrastructure Analysis¶
Analyzing an organization’s network infrastructure can reveal subdomains, IP ranges, and cloud services. Tools like Shodan, Censys, and DNS Dumpster help identify exposed assets.
Example: Scanning for exposed subdomains with subfinder
Example: Checking for misconfigured cloud services with Censys
Employee Data Collection¶
Gathering employee details (e.g., names, roles, email patterns) is vital for crafting personalized attacks. Techniques include:
- Email pattern inference: Analyze job titles to guess email formats (e.g., john.doe@example.com).
- Directory enumeration: Use tools like dirsearch to find hidden directories containing employee data.
Example: Enumerating a company’s directory structure
Physical Reconnaissance Techniques¶
Physical reconnaissance involves gathering information from public sources like company event listings, maps, or local directories. For example:
- Event tracking: Use Google Calendar or Eventbrite to find internal meetings or conferences.
- Geolocation: Analyze company addresses on Google Maps to infer office locations or parking details.
Example: Finding company events with Google’s Advanced Search
Key takeaways¶
- Web scraping and archive analysis are essential for extracting structured data from public websites.
- OSINT platforms and social media provide rich insights into employee roles and organizational culture.
- Network analysis tools like Shodan and Censys help identify exposed infrastructure and cloud services.
- Employee data collection enables personalized social engineering attacks, such as spear-phishing.
- Physical reconnaissance complements digital efforts by identifying real-world touchpoints (e.g., events, locations).