โ† All cheat sheets

OSINT-TECHNIQUES

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Interactive tools: Google Dork Builder, Recon / OSINT Helper

Open Source Intelligence collection methods, tools, and frameworks
for security research and investigations.

USERNAME AND IDENTITY ENUMERATION#

Sherlock:
  pip install sherlock-project
  sherlock <username>                      # search all sites
  sherlock <username> --timeout 10         # with timeout
  sherlock <username> -o results.txt       # save output
  sherlock <username> --print-found        # only show found
  sherlock user1 user2 user3               # multiple users

Maigret (Sherlock fork, more sites):
  pip install maigret
  maigret <username>                       # search 2500+ sites
  maigret <username> --pdf                 # PDF report
  maigret <username> -a                    # all sites
  maigret <username> --tags dating,finance # by category

WhatsMyName:
  - Web-based: https://whatsmyname.app/
  - Checks 600+ sites for username existence
  - CLI: https://github.com/WebBreacher/WhatsMyName

Namechk / KnowEm:
  - Quick username availability checking
  - https://namechk.com/
  - https://knowem.com/

Social Searcher:
  - https://www.social-searcher.com/
  - Search across social platforms
  - Monitor mentions and keywords

EMAIL OSINT#

Hunter.io:
  - Find email addresses by domain
  - Verify email existence
  - API: hunter.io/api
  - curl "https://api.hunter.io/v2/domain-search?domain=example.com&api_key=<KEY>"

Phonebook.cz:
  - https://phonebook.cz/
  - Search emails, domains, URLs by keyword
  - IntelligenceX project
  - Massive dataset from data breaches

Email verification:
  # MX record check
  dig MX example.com

  # SMTP verification (manual)
  telnet mail.example.com 25
  HELO test.com
  MAIL FROM:<test@test.com>
  RCPT TO:<target@example.com>
  # 250 = exists, 550 = not found

  # Tools
  emailharvester -d example.com           # harvest emails from search
  theHarvester -d example.com -b google   # multi-source

theHarvester:
  pip install theHarvester
  theHarvester -d example.com -b all      # all sources
  theHarvester -d example.com -b google,bing,linkedin
  theHarvester -d example.com -b crtsh    # certificate transparency

Breach data checking:
  - Have I Been Pwned: https://haveibeenpwned.com/
  - DeHashed: https://dehashed.com/ (paid, search by email/name/IP)
  - IntelligenceX: https://intelx.io/
  - Snusbase: https://snusbase.com/

DOMAIN RECONNAISSANCE#

Amass (OWASP):
  # Passive enumeration
  amass enum -passive -d example.com

  # Active enumeration
  amass enum -d example.com -active

  # With DNS brute force
  amass enum -d example.com -brute -w wordlist.txt

  # Intel mode (discover related domains)
  amass intel -org "Company Name"
  amass intel -whois -d example.com

Subfinder:
  subfinder -d example.com                 # find subdomains
  subfinder -d example.com -o subs.txt     # save output
  subfinder -d example.com -all            # all sources
  subfinder -dL domains.txt               # multiple domains

Additional subdomain tools:
  # Sublist3r
  sublist3r -d example.com

  # Assetfinder
  assetfinder --subs-only example.com

  # Chaos (ProjectDiscovery)
  chaos -d example.com

  # Certificate Transparency
  curl -s "https://crt.sh/?q=%.example.com&output=json" | jq '.[].name_value' | sort -u

DNS enumeration:
  # Standard queries
  dig example.com ANY
  dig example.com MX
  dig example.com NS
  dig example.com TXT                      # SPF, DKIM, DMARC
  dig _dmarc.example.com TXT

  # Zone transfer attempt
  dig axfr example.com @ns1.example.com

  # DNSRecon
  dnsrecon -d example.com -t std          # standard
  dnsrecon -d example.com -t brt          # brute force
  dnsrecon -d example.com -t zonewalk     # DNSSEC zone walk

  # Fierce
  fierce --domain example.com

WHOIS and domain history:
  whois example.com
  # Historical: https://web.archive.org/
  # Domain history: https://whoisrequest.com/history/

SOCIAL MEDIA OSINT#

Twitter/X:
  - Advanced search: https://twitter.com/search-advanced
  - Search operators:
    from:username                          # tweets from user
    to:username                            # tweets to user
    "exact phrase"                         # exact match
    since:2025-01-01 until:2025-12-31     # date range
    near:"city" within:15mi               # location
    filter:links                           # only tweets with links
    -filter:retweets                       # exclude retweets

  Tools:
    - twint (deprecated but forks exist)
    - snscrape: snscrape --jsonl twitter-search "from:username"

LinkedIn:
  - Google dork: site:linkedin.com/in/ "Company Name"
  - LinkedIn search operators:
    title:"Security Engineer"
    company:"Target Corp"
    school:"MIT"
  - Tools: linkedin2username (generate email lists)
  - CrossLinked: scrape names without LinkedIn auth

Facebook:
  - Graph search alternatives: lookup-id.com
  - Search by location, employer, education
  - FBID lookup: facebook.com/profile.php?id=<FBID>

Instagram:
  - osintgram (Python tool for IG analysis)
  - Instaloader: download profiles, metadata
    instaloader profile <username>
    instaloader --login=<your_acct> profile <username>

Reddit:
  - User analysis: https://www.redective.com/
  - Comment search: https://camas.unddit.com/
  - API: pushshift for historical data

IMAGE REVERSE SEARCH AND ANALYSIS#

Reverse image search:
  Google Images:    images.google.com (upload or URL)
  Yandex Images:    yandex.com/images/ (often best results)
  TinEye:           tineye.com (oldest copy, modified versions)
  Bing Visual:      bing.com/visualsearch
  Google Lens:      lens.google.com

Facial recognition (use ethically):
  - PimEyes: https://pimeyes.com/ (paid, find faces online)
  - FaceCheck.ID: https://facecheck.id/
  - Search4faces: https://search4faces.com/ (VK/OK social networks)

Geolocation from images:
  - Look for: street signs, landmarks, vegetation, sun position
  - Google Street View for verification
  - SunCalc: https://www.suncalc.org/ (sun position by date/location)
  - GeoGuessr skills: road markings, languages, car types

METADATA EXTRACTION#

ExifTool:
  exiftool image.jpg                       # all metadata
  exiftool -gps* image.jpg                 # GPS coordinates
  exiftool -a -u -g1 image.jpg            # verbose output
  exiftool -all= image.jpg                 # strip all metadata

  Key fields:
    GPS Position:  latitude/longitude
    Date/Time:     when photo was taken
    Camera Model:  device identification
    Software:      editing software used
    Author:        document creator

Document metadata:
  exiftool document.pdf
  exiftool document.docx
  # Look for: author, creation date, modification date,
  # software, company, last saved by

FOCA (Fingerprinting Organizations with Collected Archives):
  - Extract metadata from documents found on target domain
  - Identifies usernames, software versions, paths
  - Windows tool with GUI

Metagoofil:
  metagoofil -d example.com -t pdf,doc,xls -o output/
  # Downloads and extracts metadata from public documents

GOOGLE DORKING#

Common operators:
  site:example.com                         # search within site
  intitle:"index of"                       # page title contains
  inurl:admin                              # URL contains
  intext:"password"                        # page text contains
  filetype:pdf                             # specific file type
  ext:sql                                  # file extension
  cache:example.com                        # cached version
  link:example.com                         # pages linking to site

Security-focused dorks:
  site:example.com filetype:pdf            # find PDF documents
  site:example.com filetype:xlsx           # find spreadsheets
  site:example.com inurl:login             # find login pages
  site:example.com inurl:admin             # find admin panels
  site:example.com ext:sql | ext:db        # find databases
  site:example.com "confidential"          # sensitive content
  intitle:"index of" "parent directory"    # open directories
  inurl:wp-admin site:example.com          # WordPress admin
  "phpMyAdmin" inurl:phpmyadmin            # exposed phpMyAdmin
  filetype:env "DB_PASSWORD"               # exposed .env files
  filetype:log inurl:password              # log files with passwords
  site:pastebin.com "example.com"          # company data on pastebin
  site:trello.com "example.com"            # Trello boards

Google Hacking Database:
  https://www.exploit-db.com/google-hacking-database

SHODAN AND CENSYS#

Shodan:
  # CLI
  pip install shodan
  shodan init <API_KEY>

  shodan search "apache" --fields ip_str,port,org
  shodan host <IP>
  shodan domain example.com
  shodan count "port:3389 country:US"

  # Web search operators
  hostname:example.com                     # by hostname
  org:"Company Name"                       # by organization
  port:22                                  # by port
  country:US                               # by country
  city:"New York"                          # by city
  os:"Windows Server 2019"                 # by OS
  product:"Apache"                         # by product
  vuln:CVE-2021-44228                      # by CVE
  ssl.cert.subject.cn:"example.com"        # by SSL cert

  # Interesting searches
  "default password" port:80               # default credentials
  "X-Jenkins" port:8080                    # Jenkins servers
  "MongoDB Server Information" port:27017  # open MongoDB
  "elastic" port:9200                      # open Elasticsearch
  webcam has_screenshot:true               # webcams with screenshots

Censys:
  # Search engine for internet-connected devices
  # https://search.censys.io/

  # CLI
  pip install censys
  censys search "services.http.response.html_title: 'Dashboard'"
  censys view <IP>

  # Search by certificate
  parsed.names: example.com
  # Search by service
  services.port: 443 AND services.tls.certificates.leaf.subject.organization: "Company"

DARK WEB MONITORING#

Tor Browser:
  - Required for .onion sites
  - Download from torproject.org only

Search engines:
  - Ahmia: https://ahmia.fi/ (clearnet search for .onion)
  - DarkSearch: https://darksearch.io/
  - Torch: http://xmh57jrknzkhv6y3ls3ubitzfqnkrwxhopf5aygthi7d6rplyvk3noyd.onion/

Monitoring services:
  - Recorded Future
  - Flashpoint
  - DarkOwl
  - Intel471
  - SpiderFoot (automated OSINT, dark web module)

What to monitor:
  - Company name mentions
  - Domain and email leaks
  - Employee credential dumps
  - Source code leaks
  - Threat actor discussions about target
  - Ransomware leak sites

OSINT FRAMEWORKS AND PLATFORMS#

OSINT Framework:
  - https://osintframework.com/
  - Categorized collection of OSINT tools and resources
  - Organized by: username, email, domain, IP, social, etc.

Maltego:
  - Visual link analysis and data mining
  - Transforms: automated data collection
  - Community Edition: free (limited)
  - Entities: person, email, domain, IP, company, etc.
  - Integrates with: Shodan, VirusTotal, HIBP, social media

SpiderFoot:
  - Automated OSINT collection
  - 200+ modules for different data sources
  - Web UI for analysis
  - pip install spiderfoot
  - spiderfoot -l 127.0.0.1:5001

Recon-ng:
  - Modular OSINT framework (like Metasploit for OSINT)
  - recon-ng
  - marketplace search all                # browse modules
  - marketplace install recon/domains-hosts/hackertarget
  - modules load recon/domains-hosts/hackertarget
  - options set SOURCE example.com
  - run

Hunchly:
  - Browser extension for OSINT investigations
  - Automatic page capture and archiving
  - Case management
  - Selector tracking (keywords, emails, etc.)

OSINT INVESTIGATION WORKFLOW#

1. Define objectives (what are you looking for?)
2. Identify starting points (name, email, domain, username)
3. Passive collection (no direct interaction with target)
   - Search engines, social media, public records
   - DNS, WHOIS, certificate transparency
4. Analyze and correlate findings
5. Identify new leads and pivot points
6. Active collection if authorized (direct interaction)
   - Port scanning, web crawling
7. Document and report
8. Assess operational security of the investigation

OPSEC FOR OSINT INVESTIGATORS#

  [ ] Use VPN or Tor for research
  [ ] Use dedicated research browser profile
  [ ] Use sock puppet accounts (not personal)
  [ ] Don't interact with targets from personal accounts
  [ ] Clear browser history and cookies between sessions
  [ ] Use virtual machines for research
  [ ] Be aware of tracking pixels and web bugs
  [ ] Don't access accounts from your real IP
  [ ] Use burner phones/numbers for vishing research
  [ ] Document everything for legal defensibility

REFERENCES#

- OSINT Framework: https://osintframework.com/
- SANS OSINT Resources: https://www.sans.org/blog/list-of-resource-links-for-open-source-intelligence/
- Trace Labs: https://www.tracelabs.org/ (OSINT for missing persons)
- Bellingcat OSINT Toolkit: https://docs.google.com/spreadsheets/d/18rtqh8EG2q1xBo2cLNyhIDuK9jrPGwYr9DI2UncoqJQ
- Michael Bazzell OSINT Techniques: https://inteltechniques.com/