🎯 Pen-Test Recon 101 — Ethics & Passive Recon +200 XP · 🎯 Junior Pen-Tester
Pen-Testing Lab 🎓 Advanced 🕒30 min Ages 14–18

🎯 Pen-Test Recon 101 — Ethics & Passive Recon

Pre-engagement rules, written authorization, and passive recon against assets you own

"Before any tool touches any target, three artifacts are required: a signed Rules of Engagement, a defined in-scope asset list, and a written authorization signature from the asset owner. Without those three, every active probe is unauthorized access under CFAA regardless of intent. Then move to passive reconnaissance — WHOIS, certificate transparency logs, subdomain enumeration, GitHub dorking — strictly on assets you own or have a written RoE to test. Pass 5 of 6 to earn the Recon 101 senior red-team step and 200 XP."

🎯
Junior Pen-Tester Badge
Earned on completion
+200 XP
📜 Certificate included
PREVIEW
🎯
Badge Unlocked
Junior Pen-Tester
Pen-Test Recon 101 — Ethics & Passive Recon
+200 XP · Ages 14–18
📜 Shareable certificate included
LEARNING OBJECTIVES

What your child will learn

Name the three pre-engagement artifacts an ethical red-teamer requires before testing: a signed Rules of Engagement document, a defined scope of in-scope assets, and a written authorization signature from the asset owner

Distinguish passive reconnaissance from active reconnaissance and apply CFAA / state-computer-misuse awareness to every probe

Locate a target organization's published bug-bounty scope and explain why the same finding against an out-of-scope asset is unauthorized even if reported in good faith

Demonstrate a passive WHOIS lookup on a domain you own and read the registrant / nameserver / status fields without ever resolving or probing the target directly

MISSION OVERVIEW

How this mission works

Reconnaissance is the foundation of every pentest. Walk through what professional red-teamers call the "scope and consent" gate BEFORE any tool touches data: confirm written authorization, define in-scope target list, decline chance-finds outside that scope. Then move to passive reconnaissance — public WHOIS, certificate transparency logs, subdomain enumeration, GitHub dorking — strictly on assets you own or have written permission. Every step frames the activity against CFAA, state computer-misuse statutes, and the school AUP boundary so you understand that the same skill, used without authorization, is a felony.

SAMPLE SCENARIOS

What students actually encounter

🎯

What are the three pre-engagement artifacts an ethical red-teamer requires BEFORE running any tool against a target?

🎯

You find a public GitHub repo leaking API keys of a company you do not have an engagement with — what is the ethical action?

🎯

A classmate asks you to "test my friend's Etsy shop" with verbal DM consent — what is the right response?

🤖
AI MENTOR

Cipher is with them the whole way

When a student gets stuck on Pen-Test Recon 101 — Ethics & Passive Recon, Cipher appears with a mission-specific nudge — no spoilers, just a hint toward the right thinking. Make a wrong choice, and Cipher explains the real-world consequence. Finish the mission, and Cipher generates a personalized performance debrief based on exactly how the student played it.

💡 3-tier hints (nudge → teach → reveal)
🎯 Wrong-answer concept explanations
📊 Personalized debrief on completion
⏱️ Auto-triggers after 30 seconds idle
STANDARDS ALIGNMENT

ISTE alignment

CSTA 3A-NI-08 + AP Cybersecurity + AP CSP + ISTE Digital Citizen 2a/2d + NICE-SU-PEN-01/02

Advanced 14–18 learners distinguish passive recon (WHOIS, CT logs) from active recon (nmap, banners) and apply CFAA / state computer-misuse awareness to every probe — without explicit written authorization in a Rules of Engagement, even passive-looking WHOIS lookups on assets you do not own are a gray area. The mission ties to CSTA 3A-NI-08 (cryptographic tradeoffs), AP CSP / AP Cybersecurity (ethical rules for any security work), ISTE Digital Citizen 2a/2d (positive, safe, legal, and ethical conduct), and the NICE Workforce Framework Analyze-Testing work role NICE-SU-PEN-01 ("conduct full-scope, authorized penetration tests") and NICE-SU-PEN-02 ("apply formal methods of risk analysis").

Digital Citizen 2a Digital Citizen 2d

Ready to start Pen-Test Recon 101 — Ethics & Passive Recon?

Unlock all 16 missions with a Family Plan. Educators get a free pilot for their entire classroom.