How Pentesters Map a Target Without Sending a Single Packet
Passive reconnaissance is where every professional pentest should start. Before you touch the target, you gather everything the internet already knows about them. In this lecture, I walk through three of the most valuable passive recon techniques: WHOIS lookups, Shodan searches, and Google dorking. Done right, these methods surface domains, exposed services, leaked credentials, and misconfigurations without sending a single packet to the target. I'm Thomas Wilhelm. 30 years in offensive security, former practice director, Army cryptanalyst, and author of "Professional Penetration Testing" and "Basics of Hacking and Penetration Testing." On this channel, I teach the methodology, scoping, and execution side of pentesting that most tutorials skip. TECHNIQUES AND TOOLS COVERED WHOIS lookups Domain registration and ownership data Registrar, nameservers, and historical records Pivoting from WHOIS to related infrastructure Shodan.io Searching by IP, organization, and product Filters for ports, services, and vulnerabilities Identifying exposed industrial systems and devices Google dorks Operators: site:, filetype:, inurl:, intitle:, intext: Finding exposed documents, configs, and credentials The Google Hacking Database (GHDB) as a starting point RESOURCES: Join this channel to get access to perks → / @pentest_tv Get my newsletter → https://tinyurl.com/pentest-mailing-list Visit the website → https://Pentest.TV Join the Pentest.TV Discord → / discord #PassiveReconnaissance #PenetrationTesting #EthicalHacking #Shodan #GoogleDorks #WHOIS #OSINT #CyberSecurity #InfoSec #PentestTutorial #ReconTechniques #RedTeam #HackingTutorial #CyberSecurityTraining #Pentesting

The 4 NMAP Scans Every Pentester Runs First

How Microsoft Silenced the Researcher Who Broke Windows🎙 Snake Bytes Ep. 6: Rogue Planet

Privacy: For Sale

8 New Kali Linux Tools Released in 2026 That Nobody Is Talking

Password Cracking with Hashcat

Why you aren't getting hired as a hacker

Cracking Password Hashes with John the Ripper

I Tried 500+ Hacking Tools, These 13 Should Be ILLEGAL

How To Become Invisible On Linux With One Command

The 5 Phases of a Real Penetration Test (PTES Explained)

Stop using Kali Linux. Use this instead...

Pass The OSCP with just 3 TOOLS (MY 2026 CHECKLIST)

15 New Phone Tracking & Spyware Tools EVERYONE Should Now in 2026

Find Valid Usernames Before You Crack a Single Password

Watch this if everything feels too much (gentle comfort for tired women)

OSINT Toolkit Every Investigator Needs in 2026

This is What REAL Hacking Looks Like!

The Secret Linux Setup Hackers Hide From You

DEF CON 33 - Kill List: Hacking an Assassination Site on the Dark Web - Carl Miller, Chris Monteiro

