Skip to main content
Tutorial — SpiderFoot recon overview
Skill: osint-automation-frameworks
Time: ~60 minutes setup + first run
Goal
Automate passive footprinting of a domain or entity inside a controlled environment.
Steps
- Install SpiderFoot locally or on an org VM — never against personal targets without policy.
- Create a new scan; choose passive modules first.
- Seed with domain name or company name from public records.
- Review findings as leads; manually verify high-impact items.
- Export JSON/CSV for your evidence log.
- Purge scan data per retention policy.
Pitfalls
- Active modules can touch targets — legal review first.
- False positives from shared infrastructure.
Next steps
- Tutorial — DNS and WHOIS basics for manual confirmation
