Reconnaissance & OSINT

intermediate5 labsSubscription

Build the full recon kill-chain: passive OSINT, active host discovery, Nmap service scanning, web/DNS enumeration, and turning findings into a vulnerability picture.

This path is available with a Purple Edge subscription. Sign in to read the full overview and start the labs.

Labs in this path

  1. 1
  2. 2
  3. 3
  4. 4
  5. 5

Unlock this lab

Launch the lab in your browser. Real Kali, Ubuntu and Windows targets, guided step by step. No setup, no VM downloads.

Updated 2026-06-15