Red-Teaming
Reconnaissance
MITRE ATT&CK™ Reconnaissance - Tactic TA0043
Theory
Reconnaissance consists of techniques that involve adversaries actively or passively gathering information that can be used to support targeting. Such information may include details of the victim organization, infrastructure, or staff/personnel. This information can be leveraged by the adversary to aid in other phases of the adversary lifecycle, such as using gathered information to plan and execute Initial Access, to scope and prioritize post-compromise objectives, or to drive and lead further Reconnaissance efforts.

Resources
DNS EnumerationMITRE ATT&CK™ Gather Victim Network Information: DNS - T1590.002Email HarvestingMITRE ATT&CK™ Account Discovery - Technique T1087Files MetadataGoogle DorksHost DiscoveryMaltegoWIPGitHub ReconMITRE ATT&CK™ Data from Information Repositories - Technique T1213Specialized Search EnginesWIPSubdomains enumerationTCP/UDP Service ScanningMITRE ATT&CK™ Network Service Discovery - Technique T1046Vulnerability ScanningMITRE ATT&CK™ Active Scanning: Vulnerability Scanning - Technique T1595.002