# Course 35 - Footprinting and Reconnaissance | Episode 7: Information Gathering and Domain Reconnaissance Lab Page: https://stenobird.com/podcast/cybercode-academy-7578615/course-35-footprinting-and-reconnaissance-episode-7-information-gathering-and-domain-reconnaissance-lab Text version: https://stenobird.com/podcast/cybercode-academy-7578615/course-35-footprinting-and-reconnaissance-episode-7-information-gathering-and-domain-reconnaissance-lab.md Podcast: [CyberCode Academy](https://stenobird.com/podcast/cybercode-academy-7578615) Published: 2026-05-28T06:00:02+00:00 Episode link: https://www.spreaker.com/episode/course-35-footprinting-and-reconnaissance-episode-7-information-gathering-and-domain-reconnaissance-lab--72013164 Audio file: https://dts.podtrac.com/redirect.mp3/api.spreaker.com/download/episode/72013164/stealthy_target_mapping_with_recon_ng.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cybercode-academy-7578615/episodes/course-35-footprinting-and-reconnaissance-episode-7-information-gathering-and-domain-reconnaissance-lab Duration seconds: 1123 ## Resource In this lesson, you’ll learn about: reconnaissance using Recon-ng1. What is Recon-ng? A full-featured web reconnaissance framework Pre-installed on Kali Linux Designed to automate OSINT and domain reconnaissance 🔹 Core Concept Works like a framework (similar to Metasploit) Uses modules to perform different recon tasks 👉 Purpose: Build a structured database of target intelligence 2. Tool Overview Recon-ng 🔹 Key Capabilities Domain intelligence gathering Contact harvesting Subdomain discovery File and directory enumeration 👉 Advantage: Organizes results into a workspace database 3. Workspace & Domain Setup🔹 Initial Steps Create a workspace Add target domain 👉 Why it matters: Keeps recon data organized and reusable 4. Contact Harvesting🔹 Module: whois_pocs Extracts: Names Email addresses Locations 👉 Use Case: Build a target profile Useful for: Social engineering OSINT correlation 5. Host Discovery & Stealth🔹 Module: bing_domain_web Finds: Hosts Indexed subdomains 🔹 Stealth Feature Recon-ng introduces delays (sleep) between requests 👉 Benefit: Mimics human browsing Reduces detection risk Avoids IP blocking 6. Subdomain Brute-Forcing🔹 Module: brute_hosts Uses wordlists to guess subdomains 🔹 Output Hidden subdomains Associated IP addresses 👉 Importance: Expands the attack surface Reveals hidden infrastructure 7. Sensitive File Discovery🔹 Module: interesting_files Searches for: robots.txt Backup files Config files 👉 Why it matters: May expose: Hidden directories Internal paths Misconfigurations 8. Analyzing Server Responses🔹 HTTP Status Codes 404 → Resource not found (client-side issue) 300-series → Redirection 👉 Insight: Helps understand: Server behavior Application structure 9. Cybersecurity Use Case🔹 Reconnaissance Phase Early stage of: Penetration testing Bug boun… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cybercode-academy-7578615/episodes/course-35-footprinting-and-reconnaissance-episode-7-information-gathering-and-domain-reconnaissance-lab/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cybercode-academy-7578615/course-35-footprinting-and-reconnaissance-episode-7-information-gathering-and-domain-reconnaissance-lab.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.