This article is part of a series on understanding the processes and tools behind an APT-based incident. The first thing an attacker is going to collect during the reconnaissance phase are the publically available documents produced by the target. The information that harms an organization or person the most is something that wasn’t viewed as important enough to protect to begin with. This can be anything from telephone or email directory listings, metadata within a document passed around online, to an executive’s full name and corporate biography.”]