OSINT - What it is & why you should familiarise yourself within

 

OSINT

What it is & why you should familiarise yourself within


8 min read·Dec 6, 2023

In the vast digital expanse, where electrons dance & stories are reeled.

It is a great way to gather information on a variety of topics, including politics, economics, culture, & security issues.

Intoday’s world, knowledge is power, & open-source intelligence (OSINT) is an approach that aids in gathering data from publicly available sources. OSINT is an essential tool for journalists, investigators, researchers, & even individuals who want to make informed decisions. It is a great way to gather information on a variety of topics worldwide.

OSINT is in many ways the mirror image of operational security (OPSEC), which is the security process by which organizations protect public data about themselves that could, if properly analyzed, reveal damaging truths.

an eclectic set of techniques, websites, software & more….. of seeking & digging information from publicly available sources.

In this post, we will introduce you to the top 15 OSINT websites & tools, highlighting their pros & cons, whilst, providing practical examples of how they can be used. We will also recommend 10 free PDFs for further reading on the subject.

Top 14 Tools & Websites OSINT

1. — Maltego — https://www.maltego.com

2. — SpiderFoot — https://www.spiderfoot.net

3. — Intelligence X — https://intelx.io

4. — Shodan — https://www.shodan.io

5. — Metagoofil — https://www.kali.org/tools/metagoofil

6. — Lampyre — https://lampyre.io

7. — Spokeo — https://www.spokeo.com

8. — Recon-ng — https://github.com/lanmaster53/recon-ng

9. — Mitaka — https://chrome.google.com/webstore/detail/mitaka/bfjbejmeoibbdpfdbmbacmefcbannnbg

10. — Babel Street — https://www.babelstreet.com

11. — Seon — https://seon.io

12. — Google Dork — GHDB — https://www.exploit-db.com/google-hacking-database

13. — Metasploit — https://www.metasploit.com

14. — Creepy — https://www.geocreepy.com

15. — Maltego 
https://www.maltego.com

Credits: Maltego

The Web’s Artisan Crafting tales of links, no less than a magician, through relationships & ties, It unveils truths & lies.

Specializes in unveiling connections among people, companies, domains, telephone numbers, e-mail & more….

— all of which can benefit anything from law enforcement investigations to cybersecurity threat detection.

  • Pros: is a powerful tool for visualizing relationships between data points.
  • Cons: requires a paid subscription for full functionality.

2. — SpiderFoot :

Credits: Spiderfoot

The Web’s Tracker, no trail too faint, no lead slacker, pursuing data’s footprint with care, revealing stories bare.

With more than 200 modules, it can be used either offensively for reconnaissance of a specific target or defensively to gather information about what a user might have exposed over the internet and how likely the threat of a security breach is.

  • Pros: has a large number of modules for gathering information from various sources.
  • Cons: may require some technical expertise to use effectively.

3. — Intelligence X:

https://intelx.io

Credits: IntelX

Intelligence X is an OSINT tool that allows users to search for publicly available information across multiple sources. It provides advanced search capabilities and filters to help users find the information they need quickly and easily.

  • Pros: provides advanced search capabilities for finding publicly available information almost everywhere online.
  • Cons: requires a paid subscription for full functionality.

4. — Shodan:

https://www.shodan.io

Credits: Shodan

The Internet’s Seer, a scout without peer, webcams, routers, & beyond, Its touch unveils what’s spawned.

Shodan is an OSINT tool that allows users to search for internet-connected devices and systems. It provides detailed information about these devices, including their location, operating system, and vulnerabilities.

  • Pros: provides detailed information about internet-connected devices.
  • Cons: may require some technical expertise to use effectively along registration or paid subscription to enhance results.

5. — Metagoofil:

https://www.kali.org/tools/metagoofil

Credits: Kali-Linux

Harvester of Metadata, delving into files, it’s a crusader, extracting precious info, no task greater.

This metadata can provide valuable information about the authorship and history of these documents.

  • Pros: provides detailed metadata about publicly available documents.
  • Cons: may require some technical expertise to use effectively & you will need a Linux OS.

6. — Lampyre:

https://lampyre.io

Credits: Lampyre

Lampyre is an OSINT tool that provides due diligence and cyber threat intelligence capabilities. It allows users to gather information from various sources and analyze it in order to identify potential threats or risks.

  • Pros: provides advanced capabilities for due diligence and cyber threat intelligence.
  • Cons: requires a paid subscription for full functionality.

7. — Spokeo:

https://www.spokeo.com

Credits: Spokeo

Spokeo is an OSINT tool that allows users to search for information about US citizens, including their contact information, social media profiles, and public records.

  • Pros: provides detailed information about US citizens.
  • Cons: only provides information about US citizens & requires a paid subscription for full functionality.

8. — Recon-ng:

https://github.com/lanmaster53/recon-ng

Credits: Recon-ng

Sentinel of the Web, through the vast web, its threads ebb,

It stands watch, ever keen, Unveiling what’s unseen.

Itincludes a wide range of modules for gathering information from various sources whilst, analyzing it to identify potential vulnerabilities or risks.

  • Pros: Recon-ng is a powerful and flexible platform for conducting reconnaissance.
  • Cons: Recon-ng may require some technical expertise to use effectively & a Linux OS.

9. — Mitaka:

https://chrome.google.com/webstore/detail/mitaka/bfjbejmeoibbdpfdbmbacmefcbannnbg

Credits: Mitaka

Available as a Chrome extension and Firefox add-on, Mitaka lets you search over six dozen search engines for IP addresses, URLs, hashes or other indicators of compromise (IoCs). It also supports VirusTotal, URLscan.io, along other popular OSINT tools.

  • Pros: Mitaka is easy to use and integrates with popular web browsers.
  • Cons: Mitaka may not provide as much detailed information as some other OSINT tools.

10. — Babel Street:

https://www.babelstreet.com

Credits: BabelStreet

Babel Street is an OSINT tool that uses AI to cross language barriers for any search term. This cloud-based service allows users to search for information in multiple languages, making it easier to find relevant information from sources around the world.

  • Pros: Babel Street uses AI to provide multilingual search capabilities.
  • Cons: Babel Street requires a paid subscription for full functionality.

11. — Seon:

https://seon.io

Credits: Seon

Seon is an OSINT tool that provides social and digital signal checks. It allows users to gather information from social media profiles and other online sources in order to assess the credibility of an individual or organisation.

  • Pros: provides advanced capabilities for assessing the credibility of individuals or organizations based on their online presence.
  • Cons: requires a paid subscription for full functionality.

12. — Google Dork / GDork / GHDB:

https://www.exploit-db.com/google-hacking-database

Credits: Exploit-db

The Silent Whisperer, in the vast sea of Google, it dives deeper, revealing secrets, the silent keeper.

Google Dork is actually a data enquiring method that allows users to search Google using advanced operators in order to find specific information. It can be used to find sensitive information that may have been inadvertently exposed online.

  • Pros: Google Dork provides advanced search capabilities using Google’s powerful search engine.
  • Cons: may require some technical expertise to use effectively.

13. — Metasploit:

https://www.metasploit.com

Credits: Metasploit

Metasploit is an open-source penetration testing framework that can be used as an OSINT tool. It allows users to gather information about vulnerabilities in systems and networks in order to assess their security posture.

  • Pros: provides advanced capabilities for assessing the security of systems and networks.
  • Cons: may require some technical expertise to use effectively & a Linux OS for better performances.

14. — Creepy:

https://www.geocreepy.com

Credits: Creepy

Creepy is a geolocation OSINT tool. It allows users to gather geolocation-related information about users of social networking platforms along, with image hosting services based on their usernames or user IDs.

  • Pros: provides detailed geolocation-related information about users of social networking platforms and image hosting services.
  • Cons: may not provide as much detailed information about non-geolocation-related data & not currently maintained.

Atale not of covert whispers, nor concealed glimpses, but of data that freely prance. Across the broad spectrum of the public’s eye, It’s data unrestricted as the vast sky. Yet, when heroes venture in defense, research, or quest,OSINT tools become their honoured caller.

They sift through the infinite, pursuing rare catches, disclosing tales & truths, once lost in the air.

Amidst this vast ocean of bytes and tales, ethics stands as the guiding gales.With great power comes great duty, to use OSINT with beauty & not booty.In this tale of data, emotion, and lore, the OSINT anthem forevermore, will be of open truths, tales to share, in this digital world, where we all care.

A few gems OSINT-related just below…

1. — OSINT_Handbook_2020.pdf

2.. — Open-source intelligence (OSINT) is intelligence collected from publicly available sources.

3.. — OSINT-FR is a cosmopolitan community, bringing together connoisseurs and curious people, eager to develop their skills for Open Source Intelligence (ROSO) or Open Source Intelligence (OSINT).

Inconclusion, there are many powerful OSINT tools available that can help you gather information from various public data sources. Each tool has its strengths and weaknesses, so it’s important to choose the right tool for your specific needs.

Top 14 Tools & Websites OSINT

1. — Maltego — 
https://www.maltego.com

2. — SpiderFoot -
https://www.spiderfoot.net

3. — Intelligence X -
https://intelx.io

4. — Shodan -
https://www.shodan.io

5. — Metagoofil -
https://www.kali.org/tools/metagoofil

6. — Lampyre -
https://lampyre.io

7. — Spokeo -
https://www.spokeo.com

8. — Recon-ng -
https://github.com/lanmaster53/recon-ng

9. — Mitaka -https://chrome.google.com/webstore/detail/mitaka/bfjbejmeoibbdpfdbmbacmefcbannnbg

10. — Babel Street -
https://www.babelstreet.com

11. — Seon -
https://seon.io

12. — Google Dork — GHDB -
https://www.exploit-db.com/google-hacking-database

13. — Metasploit -
https://www.metasploit.com

14. — Creepy -
https://www.geocreepy.com

Another work in progress project & a few alike just below, perfect for your online OSINT searches or conceals….

  1. https://start.me/p/ME7aRA/oosint
  2. https://start.me/p/Pwy0X4/osint-inception
  3. https://start.me/p/DPYPMz/the-ultimate-osint-collection
  4. https://start.me/p/b5Aow7/asint_collection
https://start.me/p/ME7aRA/oosint

(Note: The tools mentioned are real, but the OSINT links for regions are fictional. As always, ensure to refer to official and reliable sources for accurate information.)

Surf Safe & Stay Tuned

Comments