Information gathering refers to collecting information about a target company that will help in penetration testing and security auditing of the company.
Objective
- Extract a company’s information
- List employees of the company
- Use search engines to collect the information
- Search for link popularity of the company’s website
- Gather competitive intelligence
- List the company’s partners and distributors
- Visit the company as an inquirer and extract privileged information
- Look up registered information in WhoIs Database
- Extract DNS information using domain research tools
- Locate the network range
- Track email communications

Scenario
A penetration tester collects the information of a company such as internal and external links of the company's website, people working in the company, geographical location, DNS information, competitive intelligence, network range etc. This information is collected in order to search for vulnerabilities, so as to exploit and sniff valuable information. In order to become an expert penetration tester and security auditor, you must know various techniques to gather a company's information.
Information Gathering
The Security Analyst Exercises / Information Gathering contains the following Exercises:
- Information Gathering
The Virtual Private Cloud for this Lab set utilizes:
Security Analyst Exercises are available as part of the following subscription:
Lab exercises are included for:
- TCPIP Packet Analysis
- Information Gathering
- Vulnerability Analysis
- External Penetration Testing
- Internal Network Penetration Testing
- Firewall Penetration Testing
- IDS Penetration Testing
- Password Cracking Penetration Testing
- Social Engineering Penetration Testing
- Web Application Penetration Testing
- SQL Penetration Testing