Footprinting, WHOIS, DNS lookups, and passive certificate data gathering.
# Set target
TARGET=example.com
# WHOIS lookup
whois $TARGET
# DNS: A + MX + NS records
dig +noall +answer $TARGET A
dig +noall +answer $TARGET MX
dig +noall +answer $TARGET NS
# HTTP headers check
curl -I -L --max-redirs 5 https://$TARGET
# Certificate names (crt.sh)
curl -s "https://crt.sh/?q=%25.$TARGET&output=json" | jq -r '.[].name_value' | sort -u
# Passive OSINT (AUTHORIZED USE ONLY)
theharvester -d example.com -b google,bing,linkedin -l 500
shodan host 1.2.3.4