Good breakdown of passive vs active recon. One thing worth adding to the passive side: WHOIS lookups are still one of the most useful OSINT sources, even with privacy redaction becoming more common.
What WHOIS still reveals:
Registration and expiry dates, useful for spotting recently registered domains tied to phishing or fraud infrastructure
Registrar and nameserver history, which often exposes infrastructure relationships between domains
Historical WHOIS records, which can connect a domain to earlier ownership even after a privacy service gets added later
For teams doing this defensively, checking your own domain portfolio through something like WhoisFreaks is a quick way to catch expired registrations or nameserver drift before they become findable by someone else. Fits right into the "what does our external footprint look like" question you raised.
Good breakdown of passive vs active recon. One thing worth adding to the passive side: WHOIS lookups are still one of the most useful OSINT sources, even with privacy redaction becoming more common.
What WHOIS still reveals:
Registration and expiry dates, useful for spotting recently registered domains tied to phishing or fraud infrastructure Registrar and nameserver history, which often exposes infrastructure relationships between domains Historical WHOIS records, which can connect a domain to earlier ownership even after a privacy service gets added later
For teams doing this defensively, checking your own domain portfolio through something like WhoisFreaks is a quick way to catch expired registrations or nameserver drift before they become findable by someone else. Fits right into the "what does our external footprint look like" question you raised.