GO KALI FREE
AdvancedRed Team

OSINT for Red Team: Offensive Intelligence Reconnaissance

Master OSINT techniques for red team operations. Learn target profiling, social engineering prep, infrastructure mapping, attack surface discovery, and integrating Maltego into red team workflows.

#red-team#osint#reconnaissance#social-engineering#maltego#offensive-security

# OSINT for Red Team: Offensive Intelligence Reconnaissance

Red team operations require thorough intelligence gathering to simulate real-world attacks effectively. OSINT provides the foundation for understanding targets, identifying vulnerabilities, and planning attack vectors. What follows explores offensive OSINT techniques with focus on [Maltego](/tools/maltego) for red team reconnaissance.

Why Red Teams Need OSINT

Effective red team operations require understanding:

  • **Target Profile**: Who works there, what technologies they use
  • **Attack Surface**: What systems are exposed and accessible
  • **Defensive Posture**: What security controls are in place
  • **Social Vectors**: Which employees can be targeted
  • **Infrastructure**: How systems are connected and configured
  • Target Profiling

    Organization Profiling

    Build a comprehensive profile of the target organization:

  • **Corporate Information**:
  • - Company structure and hierarchy

    - Key personnel and roles

    - Business relationships and partners

    - Technology stack and vendors

    - Recent news and events

  • **Technical Infrastructure**:
  • - Domain portfolio

    - IP ranges and network blocks

    - Cloud services and providers

    - Third-party integrations

    - Security tools and controls

  • **Employee Information**:
  • - Organizational chart

    - Key technical personnel

    - Social media presence

    - Professional backgrounds

    - Communication patterns

    Using Maltego for Organization Profiling

    [Maltego](/tools/maltego) provides comprehensive organization profiling:

  • **Domain Analysis**:
  • - Map all domain assets

    - Identify subdomains and services

    - Analyze certificate transparency

  • **Employee Discovery**:
  • - Find email addresses

    - Map social media profiles

    - Identify key personnel

  • **Infrastructure Mapping**:
  • - Map IP ranges and networks

    - Identify cloud services

    - Analyze hosting providers

    Employee Profiling

    Build profiles of target employees:

  • **Professional Information**:
  • - Job title and responsibilities

    - Technical skills and expertise

    - Professional network connections

    - Conference presentations and publications

    - Open source contributions

  • **Social Media Presence**:
  • - LinkedIn profile and connections

    - Twitter and social media activity

    - GitHub and code repositories

    - Personal blogs and websites

    - Forum participation

  • **Technical Indicators**:
  • - Programming languages used

    - Tools and frameworks

    - Development practices

    - Security awareness level

    - Potential vulnerabilities

    Social Engineering Preparation

    OSINT provides intelligence for social engineering:

  • **Pretext Development**:
  • - Research employee interests and backgrounds

    - Identify common communication patterns

    - Understand organizational culture

    - Develop convincing scenarios

  • **Target Selection**:
  • - Identify high-value targets

    - Assess security awareness levels

    - Find potential weak links

    - Map communication channels

  • **Credential Harvesting**:
  • - Collect email addresses

    - Identify password patterns

    - Find leaked credentials

    - Map authentication systems

    Infrastructure Mapping

    Network Discovery

    Map the target's network infrastructure:

  • **Domain Enumeration**:
  • - Certificate transparency analysis

    - DNS record enumeration

    - Subdomain discovery

    - Technology fingerprinting

  • **IP Address Discovery**:
  • - DNS resolution

    - Reverse DNS lookups

    - Network range identification

    - ASN mapping

  • **Service Discovery**:
  • - Port scanning (with authorization)

    - Service identification

    - Banner grabbing

    - Version detection

    Using Maltego for Infrastructure Mapping

    [Maltego](/tools/maltego) automates infrastructure discovery:

  • **Subdomain Enumeration**:
  • - Certificate transparency transforms

    - DNS enumeration transforms

    - Technology detection transforms

  • **Service Mapping**:
  • - Shodan integration

    - Service discovery transforms

    - Banner analysis

  • **Network Analysis**:
  • - IP range mapping

    - ASN identification

    - Network topology visualization

    Cloud Infrastructure

    Identify cloud services and configurations:

  • **AWS Discovery**:
  • - S3 bucket enumeration

    - EC2 instance discovery

    - CloudFront distribution mapping

    - IAM analysis

  • **Azure Discovery**:
  • - Azure AD enumeration

    - Storage account discovery

    - Service enumeration

    - Authentication analysis

  • **GCP Discovery**:
  • - GCP project enumeration

    - Storage bucket discovery

    - Service mapping

    - Authentication analysis

    Attack Surface Discovery

    Web Application Attacks

    Identify web application vulnerabilities:

  • **Technology Detection**:
  • - CMS identification

    - Framework detection

    - Library versioning

    - Server software

  • **Endpoint Discovery**:
  • - API endpoint enumeration

    - Hidden file discovery

    - Directory traversal

    - Parameter discovery

  • **Vulnerability Identification**:
  • - Known vulnerability scanning

    - Configuration analysis

    - Authentication testing

    - Authorization testing

    Email-Based Attacks

    Use OSINT for email-based attacks:

  • **Email Enumeration**:
  • - Email address discovery

    - Email pattern analysis

    - Email verification

    - Spoofing analysis

  • **Credential Attacks**:
  • - Password pattern analysis

    - Credential leak checking

    - Password spraying

    - Brute force preparation

  • **Phishing Campaigns**:
  • - Target selection

    - Pretext development

    - Infrastructure setup

    - Campaign tracking

    Social Media Attacks

    Leverage social media for attacks:

  • **Platform Analysis**:
  • - Profile information extraction

    - Connection mapping

    - Activity analysis

    - Interest identification

  • **Information Gathering**:
  • - Technical discussions

    - Company information

    - Project details

    - Security practices

  • **Social Engineering**:
  • - Pretext development

    - Relationship building

    - Trust exploitation

    - Credential harvesting

    Maltego for Red Team Operations

    Maltego Red Team Workflow

  • **Reconnaissance Phase**:
  • - Create investigation workspace

    - Add target domain as seed

    - Run comprehensive transforms

    - Map infrastructure

  • **Enumeration Phase**:
  • - Discover subdomains and services

    - Identify technology stack

    - Map employee information

    - Analyze attack surface

  • **Weaponization Phase**:
  • - Identify vulnerable targets

    - Develop attack vectors

    - Create custom transforms

    - Automate discovery

  • **Reporting Phase**:
  • - Document findings

    - Create attack narratives

    - Generate reports

    - Track metrics

    Custom Transforms for Red Teams

    Create custom transforms for red team-specific tasks:

    # Custom transform for email verification
    from maltego_trx.maltego import MaltegoTransform, MaltegoMsg
    from maltego_trx.transform import DiscoverableTransform
    import smtplib
    
    class EmailVerificationTransform(DiscoverableTransform):
        @classmethod
        def create_entities(cls, request: MaltegoMsg, response: MaltegoTransform):
            email = request.Value
            
            # Basic email validation
            import re
            if not re.match(r'^[^@]+@[^@]+\.[^@]+$', email):
                response.addException("Invalid email format")
                return
            
            # Add email entity with verification status
            entity = response.addEntity("maltego.EmailAddress", email)
            entity.addProperty("email", "Email", "loose", email)
            entity.addProperty("status", "Status", "loose", "Verified")
    

    Maltego Red Team Best Practices

  • **Operational Security**:
  • - Use clean infrastructure

    - Rotate identifiers

    - Avoid patterns

    - Document activities

  • **Methodology**:
  • - Follow structured workflow

    - Document all findings

    - Validate discoveries

    - Report comprehensively

  • **Tool Integration**:
  • - Combine with other tools

    - Automate repetitive tasks

    - Centralize findings

    - Track metrics

    Red Team OSINT Checklist

    Reconnaissance

  • [ ] Read target scope and rules
  • [ ] Create investigation workspace
  • [ ] Configure tools and API keys
  • [ ] Document methodology
  • Organization Profiling

  • [ ] Map organizational structure
  • [ ] Identify key personnel
  • [ ] Research technology stack
  • [ ] Analyze recent news and events
  • Employee Profiling

  • [ ] Discover employee information
  • [ ] Map social media profiles
  • [ ] Identify technical skills
  • [ ] Assess security awareness
  • Infrastructure Mapping

  • [ ] Enumerate subdomains
  • [ ] Discover IP ranges
  • [ ] Map network topology
  • [ ] Identify cloud services
  • Attack Surface

  • [ ] Discover web applications
  • [ ] Identify technologies
  • [ ] Map API endpoints
  • [ ] Analyze authentication
  • Social Engineering

  • [ ] Collect email addresses
  • [ ] Develop pretexts
  • [ ] Identify targets
  • [ ] Plan campaigns
  • Reporting

  • [ ] Document all findings
  • [ ] Create attack narratives
  • [ ] Generate reports
  • [ ] Track metrics
  • Common Red Team OSINT Mistakes

  • **Insufficient Reconnaissance**: Not gathering enough information
  • **Poor Documentation**: Not recording methodology and findings
  • **Detection Risk**: Being detected during reconnaissance
  • **Scope Violations**: Going outside authorized scope
  • **Tool Over-Reliance**: Using tools without understanding
  • **Incomplete Reporting**: Not documenting all findings
  • **No Validation**: Not verifying discoveries
  • **Poor OPSEC**: Revealing red team activities
  • Conclusion

    OSINT is the foundation of effective red team operations. By thoroughly profiling targets, mapping infrastructure, and identifying attack surfaces, red teams can simulate realistic attacks and provide actionable security improvements.

    Tools like [Maltego](/tools/maltego) provide powerful visualization and automation capabilities for red team reconnaissance. Combine Maltego with other OSINT tools for comprehensive coverage and effective attack simulation.

    Remember to always operate within authorized scope and maintain professional ethics. Document your methodology, validate your findings, and provide comprehensive reports that help organizations improve their security posture.

    For related topics, explore [OSINT for Bug Bounty](/learn/osint-for-bug-bounty) for vulnerability hunting techniques and [Entity Relationship Mapping](/learn/entity-relationship-mapping) for structured relationship analysis.

    Frequently Asked Questions

    Why do red teams need OSINT?

    Red teams require OSINT to understand targets, identify vulnerabilities, plan attack vectors, and simulate real-world attacks effectively. Thorough intelligence gathering reveals the organization's attack surface, employee information, and defensive posture.

    What is target profiling in red team OSINT?

    Target profiling builds a comprehensive understanding of the organization including corporate structure, key personnel, technology stack, network infrastructure, security controls, and business relationships. This intelligence guides attack planning and social engineering preparation.

    How do red teams map attack surfaces?

    Red teams use OSINT to discover subdomains, identify exposed services, map IP ranges, analyze certificate transparency, enumerate cloud resources, and identify third-party integrations. Maltego visualizes these relationships to reveal attack paths.

    What is social engineering preparation?

    Social engineering prep involves gathering employee information (names, roles, email patterns), identifying high-value targets (executives, IT admins), understanding organizational culture, and crafting convincing pretexts based on publicly available information.

    How does Maltego support red team reconnaissance?

    Maltego maps organizational infrastructure, discovers employee relationships, visualizes attack paths, correlates intelligence from multiple sources, and provides a structured view of the target environment for attack planning.

    What is infrastructure-as-a-service for red teams?

    Red team infrastructure includes phishing domains, C2 servers, payload hosting, and redirectors. OSINT helps identify clean infrastructure, avoid detection by monitoring services, and establish attack infrastructure that blends with legitimate traffic.

    How do red teams maintain operational security?

    Red teams use OSINT to understand defensive monitoring capabilities, identify security tools in use, avoid known detection signatures, use infrastructure that appears legitimate, and conduct activities during periods of high network noise.

    What is the difference between red team and penetration testing OSINT?

    Red team OSINT is more comprehensive, focusing on the entire organization including employees, physical security, and business processes. Penetration testing OSINT typically focuses on technical infrastructure. Red teams simulate full adversary campaigns.

    How do red teams identify social vectors?

    Red teams analyze employee social media profiles, professional networks, organizational charts, and communication patterns to identify targets susceptible to phishing, pretexting, or other social engineering attacks based on their online presence.

    What are common red team OSINT mistakes?

    Common mistakes include inadequate scope understanding, insufficient documentation, failing to account for defensive monitoring, not validating findings before acting, and neglecting operational security during reconnaissance phases.