# Course 35 - Footprinting and Reconnaissance | Episode 1: Methodology, OSINT Tools, and Lab Setup Page: https://stenobird.com/podcast/cybercode-academy-7578615/course-35-footprinting-and-reconnaissance-episode-1-methodology-osint-tools-and-lab-setup Text version: https://stenobird.com/podcast/cybercode-academy-7578615/course-35-footprinting-and-reconnaissance-episode-1-methodology-osint-tools-and-lab-setup.md Podcast: [CyberCode Academy](https://stenobird.com/podcast/cybercode-academy-7578615) Published: 2026-05-22T06:00:03+00:00 Episode link: https://www.spreaker.com/episode/course-35-footprinting-and-reconnaissance-episode-1-methodology-osint-tools-and-lab-setup--72013113 Audio file: https://dts.podtrac.com/redirect.mp3/api.spreaker.com/download/episode/72013113/the_actual_mechanics_of_penetration_testing.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cybercode-academy-7578615/episodes/course-35-footprinting-and-reconnaissance-episode-1-methodology-osint-tools-and-lab-setup Duration seconds: 844 ## Resource In this lesson, you’ll learn about: footprinting, OSINT, and setting up a penetration testing lab1. Penetration Testing Methodology🔹 The First Rule: Legal Scope Before any testing: Define scope clearly Get explicit permission 👉 Why it matters: Protects you legally Defines what systems you can test Prevents unauthorized access issues 2. Footprinting & Reconnaissance🔹 Definition The process of gathering information about a target before attacking 🔹 Types of Footprinting🟢 Passive Footprinting No direct interaction with the target Uses publicly available data 🔴 Active Footprinting Direct engagement with the target Higher risk of detection 🌐 OSINT (Open Source Intelligence) Collecting intelligence from: Public databases Websites Social platforms 3. Essential OSINT & Footprinting Tools🔹 Basic Network Tools nslookup DNS records and IP resolution whois Domain registration and ownership details 🔹 Search & Intelligence Platforms Shodan Discover exposed devices and services 🔹 Visual Intelligence Tool Maltego Maps relationships between: Domains Emails Infrastructure 🔹 Website Analysis HTTrack Clone websites for offline analysis 🔹 Advanced Recon Frameworks Recon-ng theHarvester 👉 Used for: Automated data collection Email harvesting Domain intelligence 4. Building a Safe Lab Environment🔹 Why You Need a Lab Avoid testing on real systems Practice safely and legally Simulate real-world attacks 🔹 Virtualization Platform Oracle VM VirtualBox 👉 Important: Install: Base platform Extension Pack 🔹 Operating System for Pentesting Kali Linux 👉 Includes: Pre-installed security tools Ready-to-use environment 5. Troubleshooting Setup Always: Follow guides specific to your OS (Windows / Linux / Mac) Check virtualization support (VT-x / AMD-V) Key Takeaways Always start with scope and p… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cybercode-academy-7578615/episodes/course-35-footprinting-and-reconnaissance-episode-1-methodology-osint-tools-and-lab-setup/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cybercode-academy-7578615/course-35-footprinting-and-reconnaissance-episode-1-methodology-osint-tools-and-lab-setup.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.