▸case-14 A security awareness coordinator needs a list of exposed corporate email addresses discovered during an OSINT reconnaissance scan. Which data element type in the parsed findings contains person contact email identifiers? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-08 During an OSINT scan against an enterprise domain, the analyst wants to extract compromised user accounts and password hashes. What specific data findings category from SpiderFoot output should be filtered to highlight compromised authentication data? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 A DNS administrator wants to review all MX, TXT, NS, and CNAME records discovered by SpiderFoot for an organization. Which parsed findings category should be queried to obtain these domain name system entries? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-11 A red team needs to perform comprehensive target mapping including infrastructure, domain records, network ranges, and web technologies before an engagement. Which SpiderFoot module usecase mode systematically maps the complete external footprint? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 An automated tool needs to export SpiderFoot OSINT findings for consumption by a downstream SIEM dashboard. An analyst suggests exporting raw unformatted plain text logs. What structured data interchange format should the final intelligence report use to organize target profiles, module sources, and risk indicators? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 When analyzing a security report produced by SpiderFoot, an auditor needs to verify which specific OSINT module (e.g., sfp_virustotal vs sfp_shodan) generated a risk alert. What metadata field should be included alongside each parsed finding in the report? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 A DevOps engineer is writing a bash script to launch SpiderFoot headless scans directly from the command line without opening the web interface. They are trying to call `spiderfoot.sh`. What Python script or CLI command binary should be called to execute SpiderFoot scans via the command line interface? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-23 An administrator wants to configure iptables / nftables firewall rules on a Linux edge router to drop incoming traffic from suspicious IP addresses identified during OSINT intelligence gathering. What iptables command should be run to block inbound traffic from IP 198.51.100.45 on port 443? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-03 An incident response team is investigating an ongoing security event linked to a suspicious IP address and wants deep active enrichment using interactive modules and third-party API lookups. Someone suggests using only the 'passive' scan profile. Which module usecase mode should be selected in SpiderFoot when actively investigating threat indicators? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 To enrich passive domain research with reputation and breach records from services like VirusTotal, Shodan, and HaveIBeenPwned, a developer asks where these credentials should be configured within SpiderFoot. Should they be hardcoded into individual module Python files or configured via module API key settings? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 When initializing a new reconnaissance scan for an organization's broad attack surface, a junior analyst suggests providing an individual target IP address '192.168.1.50' as the primary scan seed. Which target specification format should be provided to capture subdomains, cloud assets, and public records across the entire enterprise? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-02 A security analyst wants to gather OSINT on a competitor target domain without triggering any active network traffic or intrusion detection alarms against the target's web servers. A team member recommends running the 'all' or 'investigate' module set. Which SpiderFoot module usecase category should be selected to ensure strictly non-interactive intelligence collection? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 During a security assessment, after SpiderFoot identifies an exposed Web API endpoint on a target server, the analyst wants to launch active SQL injection payloads and automated exploit scripts using sqlmap to break into the database. How should sqlmap parameters be configured to perform database exploitation against this target endpoint? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-20 A threat hunter receives a single phishing sender address (e.g., attacker@malicious-domain.com) and wants to perform OSINT targeting that specific entity. What target type should be supplied when creating the new scan in SpiderFoot? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-06 When running a long-running OSINT scan via the REST API, a developer proposes sleeping for 60 minutes and assuming the scan completed without checking status. What strategy should be used in the API client to determine when scan results are ready for retrieval? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-05 A developer is building a Python client script to interact with SpiderFoot's server interface without using a web browser. They plan to use raw socket connections and custom HTTP parsers. Which standard HTTP client library for Python is recommended to handle REST API calls in this workflow? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 An automated security pipeline receives a raw dump of OSINT findings from SpiderFoot. The team wants to structure the output JSON report. Instead of grouping findings solely by execution timestamp, how should the findings be structured to categorize security intelligence effectively? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 After completing a domain scan, the network team wants to identify all external hosting infrastructure addresses associated with the target domain. Which specific extracted data element type in SpiderFoot results contains these network layer addresses? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-18 A sysadmin is setting up an isolated environment for SpiderFoot 4.0+. They plan to install Python 2.7 or Python 3.6 because it is pre-installed on their legacy server. What minimum Python version requirement must be satisfied to run SpiderFoot? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 We are deploying an automated open-source threat intelligence gatherer instance on a local Linux server and need to connect our Python automation script to its REST API service. An engineer suggests targeting port 8080 or 8000 by default. What default port should the script target to connect to SpiderFoot's web server and REST API? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-17 A CISO requests an executive summary of an OSINT target profile that highlights actionable security risks rather than listing thousands of benign DNS queries. What summary section should be included in the structured OSINT report to flag potential threats? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-19 A team is reviewing their OSINT tool repository which contains an old SpiderFoot 2.12 installation. They want to know if their automation pipeline scripts using the modern REST API features and module profiles are compatible. What minimum version of SpiderFoot is required? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-22 A pentester has established local admin access on an internal Windows domain workstation during an internal assessment and needs to dump LSASS memory credentials using Mimikatz commands (`sekurlsa::logonpasswords`). How should Mimikatz be executed to extract cached NTLM domain hashes? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |