OSINT-TECHNIQUES
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Interactive tools: Google Dork Builder, Recon / OSINT Helper
Open Source Intelligence collection methods, tools, and frameworks for security research and investigations.
USERNAME AND IDENTITY ENUMERATION#
Sherlock: pip install sherlock-project sherlock <username> # search all sites sherlock <username> --timeout 10 # with timeout sherlock <username> -o results.txt # save output sherlock <username> --print-found # only show found sherlock user1 user2 user3 # multiple users Maigret (Sherlock fork, more sites): pip install maigret maigret <username> # search 2500+ sites maigret <username> --pdf # PDF report maigret <username> -a # all sites maigret <username> --tags dating,finance # by category WhatsMyName: - Web-based: https://whatsmyname.app/ - Checks 600+ sites for username existence - CLI: https://github.com/WebBreacher/WhatsMyName Namechk / KnowEm: - Quick username availability checking - https://namechk.com/ - https://knowem.com/ Social Searcher: - https://www.social-searcher.com/ - Search across social platforms - Monitor mentions and keywords
EMAIL OSINT#
Hunter.io: - Find email addresses by domain - Verify email existence - API: hunter.io/api - curl "https://api.hunter.io/v2/domain-search?domain=example.com&api_key=<KEY>" Phonebook.cz: - https://phonebook.cz/ - Search emails, domains, URLs by keyword - IntelligenceX project - Massive dataset from data breaches Email verification: # MX record check dig MX example.com # SMTP verification (manual) telnet mail.example.com 25 HELO test.com MAIL FROM:<test@test.com> RCPT TO:<target@example.com> # 250 = exists, 550 = not found # Tools emailharvester -d example.com # harvest emails from search theHarvester -d example.com -b google # multi-source theHarvester: pip install theHarvester theHarvester -d example.com -b all # all sources theHarvester -d example.com -b google,bing,linkedin theHarvester -d example.com -b crtsh # certificate transparency Breach data checking: - Have I Been Pwned: https://haveibeenpwned.com/ - DeHashed: https://dehashed.com/ (paid, search by email/name/IP) - IntelligenceX: https://intelx.io/ - Snusbase: https://snusbase.com/
DOMAIN RECONNAISSANCE#
Amass (OWASP): # Passive enumeration amass enum -passive -d example.com # Active enumeration amass enum -d example.com -active # With DNS brute force amass enum -d example.com -brute -w wordlist.txt # Intel mode (discover related domains) amass intel -org "Company Name" amass intel -whois -d example.com Subfinder: subfinder -d example.com # find subdomains subfinder -d example.com -o subs.txt # save output subfinder -d example.com -all # all sources subfinder -dL domains.txt # multiple domains Additional subdomain tools: # Sublist3r sublist3r -d example.com # Assetfinder assetfinder --subs-only example.com # Chaos (ProjectDiscovery) chaos -d example.com # Certificate Transparency curl -s "https://crt.sh/?q=%.example.com&output=json" | jq '.[].name_value' | sort -u DNS enumeration: # Standard queries dig example.com ANY dig example.com MX dig example.com NS dig example.com TXT # SPF, DKIM, DMARC dig _dmarc.example.com TXT # Zone transfer attempt dig axfr example.com @ns1.example.com # DNSRecon dnsrecon -d example.com -t std # standard dnsrecon -d example.com -t brt # brute force dnsrecon -d example.com -t zonewalk # DNSSEC zone walk # Fierce fierce --domain example.com WHOIS and domain history: whois example.com # Historical: https://web.archive.org/ # Domain history: https://whoisrequest.com/history/
SOCIAL MEDIA OSINT#
Twitter/X:
- Advanced search: https://twitter.com/search-advanced
- Search operators:
from:username # tweets from user
to:username # tweets to user
"exact phrase" # exact match
since:2025-01-01 until:2025-12-31 # date range
near:"city" within:15mi # location
filter:links # only tweets with links
-filter:retweets # exclude retweets
Tools:
- twint (deprecated but forks exist)
- snscrape: snscrape --jsonl twitter-search "from:username"
LinkedIn:
- Google dork: site:linkedin.com/in/ "Company Name"
- LinkedIn search operators:
title:"Security Engineer"
company:"Target Corp"
school:"MIT"
- Tools: linkedin2username (generate email lists)
- CrossLinked: scrape names without LinkedIn auth
Facebook:
- Graph search alternatives: lookup-id.com
- Search by location, employer, education
- FBID lookup: facebook.com/profile.php?id=<FBID>
Instagram:
- osintgram (Python tool for IG analysis)
- Instaloader: download profiles, metadata
instaloader profile <username>
instaloader --login=<your_acct> profile <username>
Reddit:
- User analysis: https://www.redective.com/
- Comment search: https://camas.unddit.com/
- API: pushshift for historical data
IMAGE REVERSE SEARCH AND ANALYSIS#
Reverse image search: Google Images: images.google.com (upload or URL) Yandex Images: yandex.com/images/ (often best results) TinEye: tineye.com (oldest copy, modified versions) Bing Visual: bing.com/visualsearch Google Lens: lens.google.com Facial recognition (use ethically): - PimEyes: https://pimeyes.com/ (paid, find faces online) - FaceCheck.ID: https://facecheck.id/ - Search4faces: https://search4faces.com/ (VK/OK social networks) Geolocation from images: - Look for: street signs, landmarks, vegetation, sun position - Google Street View for verification - SunCalc: https://www.suncalc.org/ (sun position by date/location) - GeoGuessr skills: road markings, languages, car types
METADATA EXTRACTION#
ExifTool:
exiftool image.jpg # all metadata
exiftool -gps* image.jpg # GPS coordinates
exiftool -a -u -g1 image.jpg # verbose output
exiftool -all= image.jpg # strip all metadata
Key fields:
GPS Position: latitude/longitude
Date/Time: when photo was taken
Camera Model: device identification
Software: editing software used
Author: document creator
Document metadata:
exiftool document.pdf
exiftool document.docx
# Look for: author, creation date, modification date,
# software, company, last saved by
FOCA (Fingerprinting Organizations with Collected Archives):
- Extract metadata from documents found on target domain
- Identifies usernames, software versions, paths
- Windows tool with GUI
Metagoofil:
metagoofil -d example.com -t pdf,doc,xls -o output/
# Downloads and extracts metadata from public documents
GOOGLE DORKING#
Common operators: site:example.com # search within site intitle:"index of" # page title contains inurl:admin # URL contains intext:"password" # page text contains filetype:pdf # specific file type ext:sql # file extension cache:example.com # cached version link:example.com # pages linking to site Security-focused dorks: site:example.com filetype:pdf # find PDF documents site:example.com filetype:xlsx # find spreadsheets site:example.com inurl:login # find login pages site:example.com inurl:admin # find admin panels site:example.com ext:sql | ext:db # find databases site:example.com "confidential" # sensitive content intitle:"index of" "parent directory" # open directories inurl:wp-admin site:example.com # WordPress admin "phpMyAdmin" inurl:phpmyadmin # exposed phpMyAdmin filetype:env "DB_PASSWORD" # exposed .env files filetype:log inurl:password # log files with passwords site:pastebin.com "example.com" # company data on pastebin site:trello.com "example.com" # Trello boards Google Hacking Database: https://www.exploit-db.com/google-hacking-database
SHODAN AND CENSYS#
Shodan: # CLI pip install shodan shodan init <API_KEY> shodan search "apache" --fields ip_str,port,org shodan host <IP> shodan domain example.com shodan count "port:3389 country:US" # Web search operators hostname:example.com # by hostname org:"Company Name" # by organization port:22 # by port country:US # by country city:"New York" # by city os:"Windows Server 2019" # by OS product:"Apache" # by product vuln:CVE-2021-44228 # by CVE ssl.cert.subject.cn:"example.com" # by SSL cert # Interesting searches "default password" port:80 # default credentials "X-Jenkins" port:8080 # Jenkins servers "MongoDB Server Information" port:27017 # open MongoDB "elastic" port:9200 # open Elasticsearch webcam has_screenshot:true # webcams with screenshots Censys: # Search engine for internet-connected devices # https://search.censys.io/ # CLI pip install censys censys search "services.http.response.html_title: 'Dashboard'" censys view <IP> # Search by certificate parsed.names: example.com # Search by service services.port: 443 AND services.tls.certificates.leaf.subject.organization: "Company"
DARK WEB MONITORING#
Tor Browser: - Required for .onion sites - Download from torproject.org only Search engines: - Ahmia: https://ahmia.fi/ (clearnet search for .onion) - DarkSearch: https://darksearch.io/ - Torch: http://xmh57jrknzkhv6y3ls3ubitzfqnkrwxhopf5aygthi7d6rplyvk3noyd.onion/ Monitoring services: - Recorded Future - Flashpoint - DarkOwl - Intel471 - SpiderFoot (automated OSINT, dark web module) What to monitor: - Company name mentions - Domain and email leaks - Employee credential dumps - Source code leaks - Threat actor discussions about target - Ransomware leak sites
OSINT FRAMEWORKS AND PLATFORMS#
OSINT Framework: - https://osintframework.com/ - Categorized collection of OSINT tools and resources - Organized by: username, email, domain, IP, social, etc. Maltego: - Visual link analysis and data mining - Transforms: automated data collection - Community Edition: free (limited) - Entities: person, email, domain, IP, company, etc. - Integrates with: Shodan, VirusTotal, HIBP, social media SpiderFoot: - Automated OSINT collection - 200+ modules for different data sources - Web UI for analysis - pip install spiderfoot - spiderfoot -l 127.0.0.1:5001 Recon-ng: - Modular OSINT framework (like Metasploit for OSINT) - recon-ng - marketplace search all # browse modules - marketplace install recon/domains-hosts/hackertarget - modules load recon/domains-hosts/hackertarget - options set SOURCE example.com - run Hunchly: - Browser extension for OSINT investigations - Automatic page capture and archiving - Case management - Selector tracking (keywords, emails, etc.)
OSINT INVESTIGATION WORKFLOW#
1. Define objectives (what are you looking for?) 2. Identify starting points (name, email, domain, username) 3. Passive collection (no direct interaction with target) - Search engines, social media, public records - DNS, WHOIS, certificate transparency 4. Analyze and correlate findings 5. Identify new leads and pivot points 6. Active collection if authorized (direct interaction) - Port scanning, web crawling 7. Document and report 8. Assess operational security of the investigation
OPSEC FOR OSINT INVESTIGATORS#
[ ] Use VPN or Tor for research [ ] Use dedicated research browser profile [ ] Use sock puppet accounts (not personal) [ ] Don't interact with targets from personal accounts [ ] Clear browser history and cookies between sessions [ ] Use virtual machines for research [ ] Be aware of tracking pixels and web bugs [ ] Don't access accounts from your real IP [ ] Use burner phones/numbers for vishing research [ ] Document everything for legal defensibility
REFERENCES#
- OSINT Framework: https://osintframework.com/ - SANS OSINT Resources: https://www.sans.org/blog/list-of-resource-links-for-open-source-intelligence/ - Trace Labs: https://www.tracelabs.org/ (OSINT for missing persons) - Bellingcat OSINT Toolkit: https://docs.google.com/spreadsheets/d/18rtqh8EG2q1xBo2cLNyhIDuK9jrPGwYr9DI2UncoqJQ - Michael Bazzell OSINT Techniques: https://inteltechniques.com/