Lesson 1 of 1 in Reconnaissance
Before They Knock
The quietest stage, and the one you can influence most. An attacker builds a map of you from public records, social media, old breaches and the metadata in your files — and then knocks on exactly the right door.
3 min read
Not yet reviewed
If I have not been attacked yet, there is nothing to see. The story starts when they try something, surely.
The story starts long before that, and quietly. I read first. Your domain, your staff, the software in your job adverts, the password that leaked from a site you forgot. By the time I knock, I know which door.
And almost none of that is a hack. It is public. Which is the good news, because public is a thing you can partly control.
Legal
Gathering information about a person or organisation from public sources is mostly legal, and it is the same craft a journalist or a recruiter uses. What is not legal is using it to access, impersonate, or defraud someone without authorisation. Learn the reconnaissance so you can see your own exposure — not to build a file on somebody else.
What is already public about you
Reconnaissance is assembly, not intrusion. Each piece is harmless on its own; together they are a plan. The attacker never had to break anything to collect them, which is exactly why this stage leaves no alarm to trip.
Domains & DNS what you run, and where
Staff & roles names, titles, who reports to whom
Job adverts the exact software and versions you hire for
Social media holidays, office photos, a lanyard, a screen
Old breaches passwords you reused, sitting in a public dump
Document metadata usernames and software baked into your own files
- Line 3A job advert for "an engineer with five years of a specific firewall" tells an attacker what firewall you run before they send one packet.
- Line 5A password that leaked from a hobby forum in 2016 is tried against your email in 2026, because people reuse. The old breach is a present danger.
A company proudly posts a photo of the team at their desks. What might an attacker take from it that the company never meant to give?
Shrinking your shadow
You cannot make yourself invisible, and trying to is a trap. What you can do is decide what is public on purpose rather than by accident: assume anything you publish will be read by someone who does not wish you well, keep software versions out of public adverts and error pages, and treat any password that has ever appeared in a breach as burned everywhere it was reused.
Leaks reconnaissance
Error page: "PostgreSQL 14.2 on Debian"
Advert: "5 years with FortiOS 7.x"
Reused the 2016 forum password on emailGives nothing away
Error page: a generic message, details in the logs
Advert: "experience with modern firewalls"
Every account a unique password in a managerNone of the safe versions cost security elsewhere. They only stop handing the attacker the map for free, which pushes them back toward noisy, detectable probing — the thing your later defences are actually good at catching.
One thing you can do this week: find out what has already leaked about you. Check your email addresses at Have I Been Pwned, and for every breach it lists, make sure that password is not still in use anywhere. You are doing your own reconnaissance before an attacker does theirs.