A Pentester's Guide: OSINT, Breach Dumps & External Footholds
The full external attack chain — from passive recon and LinkedIn OSINT to breach dumps, hash capture, and WAF bypass. Written by NaviSec practitioners from real-world engagements.
What's inside the guide
A five-chapter walkthrough of the full external attack chain — from open-source intelligence gathering to capturing credentials and bypassing edge security.
- Passive Recon & Asset Discovery
- LinkedIn OSINT — Building Target Email Lists
- Breach Dumps & Password Spraying
- Hash Capture & External Footholds
- Unmasking WAFs & Finding the Origin Server
44 pages. No filler. Techniques our team uses on real engagements.
The External Attack Chain
1 · OSINT: passive recon & asset discovery
2 · OSINT: LinkedIn is not just for jobs
3 · Breach dumps & password spraying
4 · Grabbing hashes & forging footholds
5 · Unmasking WAFs & finding the source
Get the free guide
Enter your email and we'll send the PDF straight to your inbox.
A look inside the guide.
Here's a sample from Chapter 3 — the kind of practical, step-by-step technique you'll find across all five chapters.
# Query Dehashed for breached credentials associated with a target domain curl -s -u "your@email.com:API_KEY" \ "https://api.dehashed.com/search?query=domain:target.com&size=100" \ | jq '.entries[] | .email + ":" + .password' > creds.txt # Spray extracted credentials against OWA / M365 spray.sh -u creds.txt -p Summer2024 -t owa.target.com -o results.txt
The full guide covers 5 attack phases with tool walkthroughs, command references, and screenshots from live testing environments.
Built for the field.
Penetration Testers
Looking for a structured methodology to follow on external assessments.
Red Teamers
Refining their OSINT and initial access workflows for adversary simulation engagements.
Security Students
Preparing for OSCP, CEH, or their first professional engagement.
For penetration testers.
NaviSec is a Tampa-based offensive and defensive cyber security firm. Our engineers run penetration tests for Internal, External, Web Applications, IoT/Hardware devices, Physical security penetration testing, Red Team, Purple Team and more. NaviSec provides defensive services such as SOC/SIEM, Managed Detection and Response (MDR), and secure infrastructure design. We operate in nearly every industry including government, healthcare, finance, and manufacturing. We have pen tested jails, pasta factories and everything in between!
We've used this cheat sheet internally for many years and are releasing it now to the community.
Common questions.
What is OSINT in penetration testing?
What is password spraying and why is it used instead of brute-forcing?
What are breach dumps and how are they used in pentesting?
How do penetration testers find the origin server behind a WAF?
Is this guide free?
Does NaviSec offer penetration testing services?
Find out where you stand — free.
Take the free online risk assessment, or start with a confidential conversation about your risk, threats, and current cybersecurity posture.
Take the Free Risk Assessment