Reconnaissance & OSINT
intermediate5 labsSubscription
Build the full recon kill-chain: passive OSINT, active host discovery, Nmap service scanning, web/DNS enumeration, and turning findings into a vulnerability picture.
This path is available with a Purple Edge subscription. Sign in to read the full overview and start the labs.
Labs in this path
- 1
- 2
- 3
- 4
- 5
Unlock this lab
Launch the lab in your browser. Real Kali, Ubuntu and Windows targets, guided step by step. No setup, no VM downloads.
Updated 2026-06-15