Module 02 Lab | Info Gathering
5/21/2023
25 Possible Points
IN PROGRESS
Next Up: Submit Assignment
Unlimited Attempts Allowed
Attempt 1 Add Comment
Details
Overview | Deliverable
You are tasked by your company (pick company target of choice) to find out what information and
assets they have. They instructed you to perform Open Source Intelligence (OSINT) and internal
scanning to determine what assets they have or might have exposed to the public. During your
assessment they informed you to not only take note of what you find but if you find any information
that might be exposed that shouldn’t be.
Objectives:
1. Simulate an attacker in the Targeting and Reconnaissance phase of the Attacker Methodology.
2. Find and document useful information about your “targets”
3. Handle that data ethically
The Software/Tools you will use are:
Maltego Community Edition
Shodan / Censys
OSint Framework
recon-ng
Lab Submission Guidelines
Submissions must be in Microsoft Word (.docx) or PDF format. Be sure to clearly label the question
being answered. As well as where possible, screenshots should be embedded directly in the
document. Screenshots should also be cropped to only include the necessary content to answer the
question.
Purpose
The main purpose or objective of this lab is to learn the basics of passive and active
reconnaissance. You will accomplish this via performing OSINT and internal discovery by network
(https://iu.instructure.com/courses/2154618/modules/items/29490409)
Submit
Assignment
(https://iu.instructure.com/cour
scanning.
This can be helpful during the course and beyond the course by allowing you to gather information
about the assets you interact with and ensure information isn’t exposed that shouldn’t be.
Tasks | Lab Requirements
Perform Passive Reconnaissance using some the tools mentioned in the below tasks to find
information like
Host Discover (IP Address, Operating System, Open Ports, Services/version running)
Determine some of the infrastructure being used (examples: Is it a Windows shop? Do they
use Cloud providers?)
Install Maltego CE (Community Edition)
Register or create a Maltego account on Paterva in order to use their transform server
Use Maltego (and various transforms) to collect information about the organization of choice
Utilize Shodan or Censys to lookup information you found (like IP addresses, Domain Name,
company name, ect) about the organization
Investigate the OSINT Framework and determine if there is any useful tools and resources you
could utilize
Criteria for Success
Report (https://iu.instructure.com/courses/2154618/files/156311198?wrap=1) (25 points) See Rubric
The report should have 3 sections:
Overview
Analysis
Demonstrate the usage of doing Recon to find information with various tools.
Provide detailed information of some of the data you found that could be considered
relevant.
Download the Report from the hyperlink in this section for more in depth information for each section.
Additional Help / Resources:
This section is dedicated for additional help or resources that could be applied during this
assignment/lab.
Problem: Where do I download Maltego CE?
Solution:
(https://iu.instructure.com/courses/2154618/modules/items/29490409)
Submit
Assignment
(https://iu.instructure.com/cour
Choose a submission type
For your local PC: https://www.maltego.com/ce-registration/ (https://www.maltego.com/ceregistration/)
OR you can use a VM like Kali linux that has some built in information gathering tools like Maltego
Site: https://www.kali.org/get-kali/ (https://www.kali.org/get-kali/)
1. Download the Virtual Machine image for either VWware or VirtualBox depending on virtualization
platform used.
2. If the Maltego software isn’t installed then install it by running: sudo apt-get install maltego
3. You should now be able to search for maltego or find the software under 01 – Information
Gathering in the program menu
Click to find where to download Maltego CE.
Upload More
Canvas Files
Choose a file to upload
or
(https://iu.instructure.com/courses/2154618/modules/items/29490409)
Submit
Assignment
(https://iu.instructure.com/cour
File permitted: PDF, DOC, DOCX
(https://iu.instructure.com/courses/2154618/modules/items/29490409)
Submit
Assignment
(https://iu.instructure.com/cour
MIS775 – Decision Modelling for Business Analytics
MIS775 – Decision Modelling for Business Analytics – Trimester 1 2023 Assessment Task 2 – A spreadsheet-based decision model – Individual DUE DATE: Wednesday, 24th May, by 8:00pm (Melbourne time) PERCENTAGE OF FINAL GRADE: 30% WORD COUNT: 1500 Maximum number of words Description Purpose This assignment task is aligned to the learning outcomes GLO1 & […]