Skip to contentExploitQuest

Lesson 1 of 1 in Reconnaissance

Before They Knock

The quietest stage, and the one you can influence most. An attacker builds a map of you from public records, social media, old breaches and the metadata in your files — and then knocks on exactly the right door.

3 min read

Not yet reviewed

Wrenlearner

If I have not been attacked yet, there is nothing to see. The story starts when they try something, surely.

Magpieadversary

The story starts long before that, and quietly. I read first. Your domain, your staff, the software in your job adverts, the password that leaked from a site you forgot. By the time I knock, I know which door.

Rookmentor

And almost none of that is a hack. It is public. Which is the good news, because public is a thing you can partly control.

What is already public about you

Reconnaissance is assembly, not intrusion. Each piece is harmless on its own; together they are a plan. The attacker never had to break anything to collect them, which is exactly why this stage leaves no alarm to trip.

Domains & DNS     what you run, and where
Staff & roles     names, titles, who reports to whom
Job adverts       the exact software and versions you hire for
Social media      holidays, office photos, a lanyard, a screen
Old breaches      passwords you reused, sitting in a public dump
Document metadata usernames and software baked into your own files
  1. Line 3A job advert for "an engineer with five years of a specific firewall" tells an attacker what firewall you run before they send one packet.
  2. Line 5A password that leaked from a hobby forum in 2016 is tried against your email in 2026, because people reuse. The old breach is a present danger.

A company proudly posts a photo of the team at their desks. What might an attacker take from it that the company never meant to give?

Shrinking your shadow

You cannot make yourself invisible, and trying to is a trap. What you can do is decide what is public on purpose rather than by accident: assume anything you publish will be read by someone who does not wish you well, keep software versions out of public adverts and error pages, and treat any password that has ever appeared in a breach as burned everywhere it was reused.

Leaks reconnaissance

Error page: "PostgreSQL 14.2 on Debian"
Advert: "5 years with FortiOS 7.x"
Reused the 2016 forum password on email

Gives nothing away

Error page: a generic message, details in the logs
Advert: "experience with modern firewalls"
Every account a unique password in a manager

None of the safe versions cost security elsewhere. They only stop handing the attacker the map for free, which pushes them back toward noisy, detectable probing — the thing your later defences are actually good at catching.

One thing you can do this week: find out what has already leaked about you. Check your email addresses at Have I Been Pwned, and for every breach it lists, make sure that password is not still in use anywhere. You are doing your own reconnaissance before an attacker does theirs.