Reconnaissance
Also known as Recon
Gathering information about a target before attempting anything against it.
Passive reconnaissance uses public sources only: DNS records, certificate transparency logs, job postings, breach data, and search engines for internet-connected devices. The target sees nothing.
Active reconnaissance touches the target directly with scans and probes, which is faster but visible and requires authorization. Passive work usually reveals more than expected before anything active begins.
Where this comes up
Reconnaissance sits inside our penetration testing work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.