: They must stay within the agreed-upon scope of the project.
Collecting data about the target without direct interaction. This includes OSINT (search engines, social media) and passive traffic monitoring. Scanning and Enumeration:
: If you stumble upon an "index of" that looks like it belongs to a private company and contains sensitive data, practice Responsible Disclosure and let them know. Conclusion