Glossary entry

Reconnaissance

In the context of cybersecurity, reconnaissance is the practice of covertly discovering and collecting information about a system.

Glossary entry Attack lifecycle · pen testing

Reconnaissance · covert discovery before the attack

In the context of cybersecurity, reconnaissance is the practice of covertly discovering and collecting information about a system. This method is often used in ethical hacking or penetration testing.

Like many cybersecurity terms, reconnaissance derives from military language, where it refers to a mission with the goal of obtaining information from enemy territory.

How Reconnaissance Works

Reconnaissance generally follows seven steps:

  1. 01 Collect initial information
  2. 02 Determine the network range
  3. 03 Identify active machines
  4. 04 Find access points and open ports
  5. 05 Fingerprint the operating system
  6. 06 Discover services on ports
  7. 07 Map the network
File permissions Running network services OS platform Trust relationships User account information

Differences Between Passive and Active Reconnaissance

There are two main types of reconnaissance: active and passive reconnaissance.

How To Prevent Reconnaissance

Organizations can use penetration testing to determine what their network would reveal in the event of a reconnaissance attack. Organizations can outsource the work by hiring security testing professionals to carry out penetration testing, vulnerability assessment, compliance testing, etc.

During testing, organizations can deploy port scanning tools (which scan large networks and determine which hosts are up) and vulnerability scanners (which find known vulnerabilities in the network).

SIEM solutions can also detect source IPs that are running a port scanning tool in your network.

Other reconnaissance prevention techniques are highlighted in the MITRE ATT&CK Framework.

Next step

Experience Blumira Today.

Integrated security for modern threats.

Browse the glossary