Skip to content

Corporate Reconnaissance

Corporate reconnaissance is a foundational phase in social engineering campaigns, involving the systematic collection of publicly available information about an organization to identify vulnerabilities, map relationships, and tailor attacks. This phase leverages open-source intelligence (OSINT) tools, web scraping, and network analysis to build a comprehensive profile of the target. Below are key methodologies and techniques used in corporate reconnaissance.


Web Scraping and Archive Analysis

Web scraping is a critical technique for extracting data from an organization’s website, including contact information, job postings, and infrastructure details. Tools like curl, wget, and Python libraries such as BeautifulSoup or Scrapy are commonly used.

Example: Extracting job titles from a company’s careers page

import requests
from bs4 import BeautifulSoup

url = "https://example-company.com/careers"
response = requests.get(url)
soup = BeautifulSoup(response.text, "html.parser")

for job in soup.find_all("div", class_="job-title"):
    print(job.text.strip())

Archive analysis involves using the Wayback Machine (archive.org) to retrieve historical snapshots of a company’s website. This can reveal outdated contact details or internal documentation.

curl "https://archive.org/wayback/available?url=https://example-company.com"


OSINT Platforms and Social Media

Social media platforms like LinkedIn, Twitter, and Facebook are rich sources of employee data, organizational hierarchies, and event schedules. Tools like Maltego, SpiderFoot, and Hunter.io automate the aggregation of this data.

Example: Using linkedin-scraper to extract employee roles

from linkedin_scraper import Profile

profile = Profile("https://linkedin.com/in/john-doe")
print(profile.name, profile.job_title)

Tip: Search for company hashtags (e.g., #ExampleCorp) or event mentions to identify internal communication channels or upcoming conferences.


Network and Infrastructure Analysis

Analyzing an organization’s network infrastructure can reveal subdomains, IP ranges, and cloud services. Tools like Shodan, Censys, and DNS Dumpster help identify exposed assets.

Example: Scanning for exposed subdomains with subfinder

subfinder -d example-company.com -o subdomains.txt

Example: Checking for misconfigured cloud services with Censys

censys search 'company:example-company.com' | grep 'cloud'


Employee Data Collection

Gathering employee details (e.g., names, roles, email patterns) is vital for crafting personalized attacks. Techniques include:
- Email pattern inference: Analyze job titles to guess email formats (e.g., [email protected]).
- Directory enumeration: Use tools like dirsearch to find hidden directories containing employee data.

Example: Enumerating a company’s directory structure

dirsearch -u https://example-company.com -e php,txt


Physical Reconnaissance Techniques

Physical reconnaissance involves gathering information from public sources like company event listings, maps, or local directories. For example:
- Event tracking: Use Google Calendar or Eventbrite to find internal meetings or conferences.
- Geolocation: Analyze company addresses on Google Maps to infer office locations or parking details.

Example: Finding company events with Google’s Advanced Search

https://www.google.com/search?q=intitle%3A%22example%20corp%22+intitle%3A%22event%22


Key takeaways

  • Web scraping and archive analysis are essential for extracting structured data from public websites.
  • OSINT platforms and social media provide rich insights into employee roles and organizational culture.
  • Network analysis tools like Shodan and Censys help identify exposed infrastructure and cloud services.
  • Employee data collection enables personalized social engineering attacks, such as spear-phishing.
  • Physical reconnaissance complements digital efforts by identifying real-world touchpoints (e.g., events, locations).