CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationHard

A penetration tester is conducting a black-box assessment of an organization's external presence. They have identified numerous subdomains and are now looking for publicly exposed API endpoints or development environments. Which OSINT tool is specifically designed to discover a wide range of public-facing assets, including subdomains, IP addresses, open ports, and potentially vulnerable services by querying various public data sources?

  1. AShodan
  2. BtheHarvester
  3. CAmass
  4. DCensys
Show answer & explanation

Correct answer: A. Shodan

Shodan is a search engine for internet-connected devices that allows users to find specific types of devices and services (e.g., webcams, routers, servers) using a variety of filters, making it excellent for discovering public-facing assets and potential vulnerabilities beyond just subdomains.

Why the other options are wrong

  • B. theHarvester primarily focuses on gathering emails, subdomains, hosts, and employee names from public sources, but not deep service/port enumeration.
  • C. Amass is a powerful subdomain and attack surface mapping tool, but its primary focus is on DNS and certificate enumeration, not direct service/port identification like Shodan.
  • D. Censys is similar to Shodan but focuses more on certificate data and host information derived from full IPv4 and TLS scans, less on broad service discovery like Shodan.

Shodan

A search engine for internet-connected devices that allows users to discover webcams, routers, servers, and more by querying for specific services, ports, and banners.

  • Indexes internet-facing devices and services.
  • Provides information on open ports, services, and banners.
  • Useful for identifying exposed assets and misconfigurations.

Memory trick: Shodan shows you the 'show' of what's publicly online.

More Reconnaissance and Enumeration questions