reconnaissance

Tools & Defense

Nmap in Practice: A Pentester’s Guide to Scanning, NSE, and Timing

A practical, accurate Nmap workflow covering host discovery, -p-, -sC -sV, NSE scripts, and timing — plus blue-team detection.
Tools & Defense

OSINT for Penetration Testers: A Practical Introduction to Passive Reconnaissance

A hands-on intro to OSINT for pentesters: theHarvester, recon-ng, Google dorks, Shodan, and Maltego, plus blue-team defenses.
Mobile API OSINT

OSINT for Red Teamers: Mapping People and Infrastructure

A practical red-team OSINT workflow for enumerating people and infrastructure with theHarvester, Shodan, breach data, and DNS recon.
Mobile API OSINT

Subdomain Enumeration and Attack Surface Mapping with Amass, Subfinder, and httpx

A practical recon workflow chaining amass, subfinder, httpx, and ffuf to map an organization's external attack surface.