โ† All cheat sheets

SOCIAL-MEDIA-OSINT

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Tools and techniques for gathering intelligence from social media
platforms. Covers Twint, OSINTgram, Sn0int, and general techniques.

TWINT (TWITTER/X OSINT)#

# Note: Twint functionality may be limited due to X/Twitter API changes.
# Consider alternatives: snscrape, Nitter instances

INSTALLATION#

pip install twint
# Or from source:
git clone https://github.com/twintproject/twint
cd twint && pip install .

BASIC USAGE#

# Search tweets by keyword
twint -s "cybersecurity"

# Search user tweets
twint -u username

# Search with date range
twint -u username --since "2024-01-01" --until "2024-06-01"

# Search by location
twint -g="48.8566,2.3522,10km"              # Lat,Lon,Radius

# Limit results
twint -u username --limit 100

# Output formats
twint -u username -o output.json --json     # JSON
twint -u username -o output.csv --csv       # CSV
twint -u username --database tweets.db      # SQLite

# User info
twint -u username --user-full               # Full profile info

# Followers/following
twint -u username --followers
twint -u username --following

# Filter tweets
twint -u username --images                  # Only with images
twint -u username --videos                  # Only with videos
twint -u username --links                   # Only with links
twint -u username --min-likes 100           # Minimum likes
twint -u username --min-retweets 50         # Minimum retweets

# Search with filters
twint -s "password" --verified              # From verified users
twint -s "api key" --lang en                # Language filter

# Mentions and replies
twint -u username --mentions
twint -u username --replies

ALTERNATIVES TO TWINT#

# snscrape (maintained, multi-platform)
pip install snscrape
snscrape twitter-search "from:username since:2024-01-01"
snscrape twitter-user username

# Nitter (Twitter frontend, no API needed)
# Use Nitter instances: nitter.net, nitter.it, etc.
# RSS feeds available for any profile

=========================================================================

OSINTGRAM (INSTAGRAM OSINT)#


    

INSTALLATION#

git clone https://github.com/Datalux/Osintgram
cd Osintgram
pip install -r requirements.txt

# Configure credentials (Instagram login required)
# Edit config/credentials.ini:
# [Credentials]
# username = your_instagram_user
# password = your_instagram_pass

USAGE#

python3 main.py target_username

# Interactive commands:
Osintgram > addrs                # Addresses tagged in photos
Osintgram > captions             # Captions of posts
Osintgram > comments             # Comments on posts
Osintgram > followers            # List followers
Osintgram > followings           # List following
Osintgram > fwersemail           # Followers' emails
Osintgram > fwingsemail          # Following's emails
Osintgram > fwersnumber          # Followers' phone numbers
Osintgram > fwingsnumber         # Following's phone numbers
Osintgram > hashtags             # Hashtags used
Osintgram > info                 # Profile info
Osintgram > likes                # Users who liked posts
Osintgram > mediatype            # Media type analysis
Osintgram > photodes             # Photo descriptions
Osintgram > photos               # Download photos
Osintgram > propic               # Download profile picture
Osintgram > stories              # Download stories
Osintgram > tagged               # Tagged users
Osintgram > target               # Change target
Osintgram > wcommented           # Users who commented
Osintgram > wtagged              # Users who tagged target

=========================================================================

SN0INT (OSINT FRAMEWORK)#

Semi-automatic OSINT framework with a module system and database.
Written in Rust, scriptable with Lua.

INSTALLATION#

# Arch Linux
pacman -S sn0int

# Debian/Ubuntu
apt install sn0int

# macOS
brew install sn0int

# From source (Rust)
cargo install sn0int

# Docker
docker run --rm -it sn0int/sn0int

WORKSPACE MANAGEMENT#

# Create/select workspace
sn0int workspace create myproject
sn0int workspace select myproject
sn0int workspace list

ADDING TARGETS#

# Enter the sn0int shell
sn0int

# Add targets to investigate
sn0int > add domain example.com
sn0int > add email user@example.com
sn0int > add ip 1.2.3.4
sn0int > add phonenumber "+1234567890"
sn0int > add account github:username

# List targets in scope
sn0int > select domains
sn0int > select emails
sn0int > select ips

RUNNING MODULES#

# List available modules
sn0int > mod list

# Install module from registry
sn0int > pkg install kpcyrd/dns-resolve
sn0int > pkg install kpcyrd/ctlogs
sn0int > pkg install kpcyrd/shodan
sn0int > pkg install kpcyrd/pgp-keyserver

# Run module
sn0int > use kpcyrd/dns-resolve
sn0int > run

# Run all modules of a type
sn0int > run -t dns

# Run with specific target
sn0int > use kpcyrd/dns-resolve
sn0int > set domain example.com
sn0int > run

KEY MODULES#

Module                    Purpose
------                    -------
kpcyrd/dns-resolve        DNS resolution
kpcyrd/ctlogs             Certificate transparency
kpcyrd/shodan             Shodan integration
kpcyrd/censys             Censys integration
kpcyrd/pgp-keyserver      PGP key search
kpcyrd/subdomain-brute    Subdomain brute force
kpcyrd/geoip              IP geolocation
kpcyrd/whois              WHOIS lookup
kpcyrd/port-scan          Port scanning
kpcyrd/web-screenshot     Website screenshots

DATABASE & EXPORT#

# Query database
sn0int > select * from domains
sn0int > select * from subdomains where value like '%api%'
sn0int > select * from emails

# Export
sn0int > export json > results.json
sn0int > export csv > results.csv

# Noscope (remove irrelevant results)
sn0int > noscope domain unwanted.com

# Delete specific entry
sn0int > delete domain old.example.com

=========================================================================

GENERAL SOCIAL MEDIA OSINT TECHNIQUES#


    

TWITTER/X#

# Advanced search operators
from:username                               # Tweets from user
to:username                                 # Tweets to user
@username                                   # Mentions
"exact phrase"                              # Exact match
keyword1 OR keyword2                        # Either term
keyword -exclude                            # Exclude term
since:2024-01-01 until:2024-06-01          # Date range
filter:media                                # With media
filter:links                                # With links
filter:replies                              # Only replies
min_faves:100                               # Minimum likes
min_retweets:50                             # Minimum retweets
geocode:48.8566,2.3522,10km                # Near location
lang:en                                     # Language

LINKEDIN#

# Google dorks for LinkedIn OSINT
site:linkedin.com/in/ "Company Name"
site:linkedin.com/in/ "job title" "location"
site:linkedin.com/company/target-company
inurl:linkedin.com/in/ "target name"

# Tools
linkedin2username                           # Generate usernames from LinkedIn
CrossLinked                                 # LinkedIn username scraping

FACEBOOK#

# Graph search (limited)
# Facebook ID lookup: fb.com/profile.php?id=USER_ID
# Public posts search: fb.com/search/posts/?q=keyword
# People search: fb.com/search/people/?q=name

# Tools
facebook-scraper (Python)
fb-sleep (location tracking from Messenger)

INSTAGRAM#

# Web interface recon (no login)
instagram.com/username/                     # Public profile
instagram.com/explore/tags/hashtag/         # Hashtag search

# Tools
Osintgram                                   # Detailed analysis
Instaloader                                 # Download content
  pip install instaloader
  instaloader profile username
  instaloader --hashtag cybersecurity
  instaloader --login youruser profile target

REDDIT#

# Useful for finding people and interests
reddit.com/user/username                    # Profile
# Search: reddit.com/search?q=keyword
# Subreddit search: reddit.com/r/subreddit/search

# Tools
redditsfinder                               # Find accounts
BDFR (Bulk Downloader for Reddit)

GENERAL TIPS#

  - Check profile creation dates for account age
  - Cross-reference usernames across platforms (Sherlock)
  - Archived profiles: web.archive.org/web/*/platform.com/username
  - Deleted posts may be cached in Google or Wayback Machine
  - Location data from check-ins and geotagged posts
  - Photo EXIF data may contain GPS coordinates
  - Friend/follower overlap reveals social connections
  - Writing style analysis (stylometry) can link anonymous accounts
  - Monitor changes over time with periodic scraping
  - Always respect privacy laws and platform ToS
  - Document findings with screenshots and timestamps