training
Practical Offensive Recon for Modern Attack Surfaces
- Location
- Online
- Audience
- Penetration Testers, Red Teamers, Bug Bounty Hunters, ASM/CTEM Teams, Threat Intelligence Analysts, Security Engineers
- Duration
- 3 days
Delivered a three-day online edition of RedHunt Labs’ offensive recon training for Byt3con Academy’s September 2026 cohort.
The training covers attacker-grade reconnaissance against modern organizations, where the attack surface now runs well past web apps into cloud, SaaS, APIs, mobile, third-party services, and AI platforms. Participants worked through hands-on labs against real-world targets and enterprise-scale datasets, mixing manual tradecraft with automation and AI-assisted workflows.
The three days were structured as:
- Day 1: Recon foundations and attack surface discovery. Attack surface intelligence, advanced internet recon (DNS, certificates, ASN, BGP, cloud), and asset discovery across web apps, APIs, mobile, SaaS, and third parties.
- Day 2: AI recon, intelligence collection, and exposure discovery. Hunting AI exposures (models, datasets, prompt templates), intelligence from GitHub, secrets, dark web, and leaked credentials, and cloud artifact recon across Docker images, snapshots, and storage.
- Day 3: Attack chaining and offensive operations. Validating findings, AI-assisted offensive recon, human intelligence and social engineering, attack chaining methodology, and a capstone engagement against a realistic enterprise target.