Summarize with:

Google Yourself Like an Attacker: A 10-Minute Reconnaissance Test

Google Yourself Like an Attacker: A 10-Minute Reconnaissance Test

How much could a stranger learn about you in ten minutes?

You can get a rough idea with a browser, a few searches and a timer.

Set it for ten minutes.

For the next ten minutes, forget what you already know about yourself. Only use information that someone who doesn’t know you could find online.

The goal is simple: see how quickly your digital identity starts to take shape.

Minute 1–2: Search Your Name

Start with your full name in quotation marks.

“Jane Smith”

Don’t stop at the first result. Look through a few pages and pay attention to what appears.

Can you find your employer?

Your job title?

A company bio?

An old conference page?

A social media account?

A photo?

Now add some context:

“Jane Smith” + company
“Jane Smith” + city
“Jane Smith” + job title

You may already have enough information to understand where this person works and what they do.

Keep going.

Minute 3–4: Search Your Email

Search your personal and professional email addresses.

See where they appear.

You might find an old account, a public document, a forum post, an archived page or another profile connected to the same address.

An email address is particularly useful during reconnaissance because it can connect information that would otherwise look unrelated.

Write down anything you didn’t expect to find.

Minute 5–6: Search Your Usernames

Now search the usernames you use most often.

Then try older ones.

If you’ve reused the same username across different platforms, see how far you can follow it.

Does one account lead to another?

Does an old username eventually reveal your real name?

Can it be connected to your email, employer or social profiles?

This is where separate pieces of information often start becoming a recognizable identity.

Minute 7–8: Check Your Public Profiles

Pick one or two public profiles you’ve found and look at them as if they belonged to someone else.

Don’t focus only on what the profile says directly.

Look at the context around it.

Who do you interact with?

Which companies do you mention?

Which events have you attended?

What topics do you post about?

Are colleagues visible?

Does anything reveal your location or travel?

Now think about what someone could do with that information.

A phishing email that mentions your company is easy to ignore.

A phishing email that mentions your company, your role, a colleague and an event you recently attended is much more convincing.

That’s why reconnaissance matters.

Minute 9: Connect the Dots

Look at everything you’ve collected so far.

Don’t treat each result separately.

Try connecting them.

Name → company

Company → job title

Job title → colleagues

Email → accounts

Username → social profiles

Social profiles → interests and events

A few ordinary pieces of public information can provide a surprising amount of context when viewed together.

That’s often what an attacker is looking for.

Not one perfect piece of information.

Enough information to understand the target.

Minute 10: Ask the Important Question

You have one minute left.

Based only on what you’ve found, ask yourself:

Could someone use this information to create a believable message for me?

Maybe they know the name of someone you work with.

Maybe they know which department you’re in.

Maybe they found an event you attended.

Maybe they discovered an account you haven’t thought about in years.

If the answer is yes, you’ve just seen a small part of your personal attack surface.

And there’s an important catch.

Everything you found came from a normal search.

What Google Doesn’t Show You

Your ten-minute test has a limitation: search engines can only show you what they can index.

Your digital exposure can go further.

Old breached accounts, leaked credentials, data brokers, exposed records and other sources may contain information that doesn’t appear when you Google your name.

That changes the question.

It’s no longer:

“What can I find about myself on Google?”

It’s:

“What could someone actively researching me discover?”

That’s where personal threat intelligence comes in.

From a 10-Minute Search to ShadowID

ShadowID by ThreatMon is designed to give you a broader view of that exposure.

Instead of looking at a name, email address, username or exposed account separately, ShadowID helps uncover the connections between them.

It can help reveal where your digital identity is exposed and which findings may actually matter from a security perspective.

Because finding information is only the first step.

Understanding how it connects — and how it could be used against you — is what turns a digital footprint into actionable intelligence.

Your ten-minute search shows you what is easy to find.

ShadowID helps you understand what may exist beyond that search.

Know Your Shadow. Reduce Your Exposure.

ShadowID by ThreatMon

Table of Contents

More posts

Google Yourself Like an Attacker: A 10-Minute Reconnaissance Test
What Is Infostealer Malware and How Do You Know You’re Infected
What Is a Digital Footprint and How Do You Check Yours

Share this article

Found it interesting? Don’t hesitate to share it to wow your friends or colleagues