OSINT for Red Team: Offensive Intelligence Reconnaissance
Master OSINT techniques for red team operations. Learn target profiling, social engineering prep, infrastructure mapping, attack surface discovery, and integrating Maltego into red team workflows.
# OSINT for Red Team: Offensive Intelligence Reconnaissance
Red team operations require thorough intelligence gathering to simulate real-world attacks effectively. OSINT provides the foundation for understanding targets, identifying vulnerabilities, and planning attack vectors. What follows explores offensive OSINT techniques with focus on [Maltego](/tools/maltego) for red team reconnaissance.
Why Red Teams Need OSINT
Effective red team operations require understanding:
Target Profiling
Organization Profiling
Build a comprehensive profile of the target organization:
- Company structure and hierarchy
- Key personnel and roles
- Business relationships and partners
- Technology stack and vendors
- Recent news and events
- Domain portfolio
- IP ranges and network blocks
- Cloud services and providers
- Third-party integrations
- Security tools and controls
- Organizational chart
- Key technical personnel
- Social media presence
- Professional backgrounds
- Communication patterns
Using Maltego for Organization Profiling
[Maltego](/tools/maltego) provides comprehensive organization profiling:
- Map all domain assets
- Identify subdomains and services
- Analyze certificate transparency
- Find email addresses
- Map social media profiles
- Identify key personnel
- Map IP ranges and networks
- Identify cloud services
- Analyze hosting providers
Employee Profiling
Build profiles of target employees:
- Job title and responsibilities
- Technical skills and expertise
- Professional network connections
- Conference presentations and publications
- Open source contributions
- LinkedIn profile and connections
- Twitter and social media activity
- GitHub and code repositories
- Personal blogs and websites
- Forum participation
- Programming languages used
- Tools and frameworks
- Development practices
- Security awareness level
- Potential vulnerabilities
Social Engineering Preparation
OSINT provides intelligence for social engineering:
- Research employee interests and backgrounds
- Identify common communication patterns
- Understand organizational culture
- Develop convincing scenarios
- Identify high-value targets
- Assess security awareness levels
- Find potential weak links
- Map communication channels
- Collect email addresses
- Identify password patterns
- Find leaked credentials
- Map authentication systems
Infrastructure Mapping
Network Discovery
Map the target's network infrastructure:
- Certificate transparency analysis
- DNS record enumeration
- Subdomain discovery
- Technology fingerprinting
- DNS resolution
- Reverse DNS lookups
- Network range identification
- ASN mapping
- Port scanning (with authorization)
- Service identification
- Banner grabbing
- Version detection
Using Maltego for Infrastructure Mapping
[Maltego](/tools/maltego) automates infrastructure discovery:
- Certificate transparency transforms
- DNS enumeration transforms
- Technology detection transforms
- Shodan integration
- Service discovery transforms
- Banner analysis
- IP range mapping
- ASN identification
- Network topology visualization
Cloud Infrastructure
Identify cloud services and configurations:
- S3 bucket enumeration
- EC2 instance discovery
- CloudFront distribution mapping
- IAM analysis
- Azure AD enumeration
- Storage account discovery
- Service enumeration
- Authentication analysis
- GCP project enumeration
- Storage bucket discovery
- Service mapping
- Authentication analysis
Attack Surface Discovery
Web Application Attacks
Identify web application vulnerabilities:
- CMS identification
- Framework detection
- Library versioning
- Server software
- API endpoint enumeration
- Hidden file discovery
- Directory traversal
- Parameter discovery
- Known vulnerability scanning
- Configuration analysis
- Authentication testing
- Authorization testing
Email-Based Attacks
Use OSINT for email-based attacks:
- Email address discovery
- Email pattern analysis
- Email verification
- Spoofing analysis
- Password pattern analysis
- Credential leak checking
- Password spraying
- Brute force preparation
- Target selection
- Pretext development
- Infrastructure setup
- Campaign tracking
Social Media Attacks
Leverage social media for attacks:
- Profile information extraction
- Connection mapping
- Activity analysis
- Interest identification
- Technical discussions
- Company information
- Project details
- Security practices
- Pretext development
- Relationship building
- Trust exploitation
- Credential harvesting
Maltego for Red Team Operations
Maltego Red Team Workflow
- Create investigation workspace
- Add target domain as seed
- Run comprehensive transforms
- Map infrastructure
- Discover subdomains and services
- Identify technology stack
- Map employee information
- Analyze attack surface
- Identify vulnerable targets
- Develop attack vectors
- Create custom transforms
- Automate discovery
- Document findings
- Create attack narratives
- Generate reports
- Track metrics
Custom Transforms for Red Teams
Create custom transforms for red team-specific tasks:
# Custom transform for email verification
from maltego_trx.maltego import MaltegoTransform, MaltegoMsg
from maltego_trx.transform import DiscoverableTransform
import smtplib
class EmailVerificationTransform(DiscoverableTransform):
@classmethod
def create_entities(cls, request: MaltegoMsg, response: MaltegoTransform):
email = request.Value
# Basic email validation
import re
if not re.match(r'^[^@]+@[^@]+\.[^@]+$', email):
response.addException("Invalid email format")
return
# Add email entity with verification status
entity = response.addEntity("maltego.EmailAddress", email)
entity.addProperty("email", "Email", "loose", email)
entity.addProperty("status", "Status", "loose", "Verified")
Maltego Red Team Best Practices
- Use clean infrastructure
- Rotate identifiers
- Avoid patterns
- Document activities
- Follow structured workflow
- Document all findings
- Validate discoveries
- Report comprehensively
- Combine with other tools
- Automate repetitive tasks
- Centralize findings
- Track metrics
Red Team OSINT Checklist
Reconnaissance
Organization Profiling
Employee Profiling
Infrastructure Mapping
Attack Surface
Social Engineering
Reporting
Common Red Team OSINT Mistakes
Conclusion
OSINT is the foundation of effective red team operations. By thoroughly profiling targets, mapping infrastructure, and identifying attack surfaces, red teams can simulate realistic attacks and provide actionable security improvements.
Tools like [Maltego](/tools/maltego) provide powerful visualization and automation capabilities for red team reconnaissance. Combine Maltego with other OSINT tools for comprehensive coverage and effective attack simulation.
Remember to always operate within authorized scope and maintain professional ethics. Document your methodology, validate your findings, and provide comprehensive reports that help organizations improve their security posture.
For related topics, explore [OSINT for Bug Bounty](/learn/osint-for-bug-bounty) for vulnerability hunting techniques and [Entity Relationship Mapping](/learn/entity-relationship-mapping) for structured relationship analysis.