OSINT

Credit to https://tcm-sec.com/ and https://github.com/jivoi for many of the tools in this section

Huge List of Tools

This repo is amazing ^ I have barely scratched the surface of the number of tools listed in there. Highly recommend checking it out.

IP - Domain OSINT

Sometimes you want to get some information on an IP/Domain without actually scanning and drawing the attention to yourself. That's what these tools are for

IP/Domain Lookup Tool
Data on VPN/Proxys
Want to see a sketchy website but not actually open the link? Bingo
Huge search engine for Internet Connected Devices
DNS info, self explanatory
SSL certificate search tool

Email Address OSINT

Discovering Email Addresses

hunter.io

  • It will give you 50 to 100 free searchers per month and can be signed up to free with a google account

phonebook.cz

  • does domains, emails, and URLs

voilanobert.com

Scraping emails with LinkedInDumper

Python tool to scrape company emails from a linkedin page + fill in the blanks if given a set format. Works by using your li_at session cookie value which can be grabbed from the developer tools

Additional usage information here:

Verify Email Addresses

tools.verifyemailaddress.io

email-checker.net/validate

Verifying O365 Emails with UhOh365

Super useful tool for taking a list of emails and verifying if they are active or not. What is unique about this tool is it uses Microsoft's built-in Autodiscover API which is invisible to the person/company who owns said email address

(alternative tool)

Verifying Gmail accounts with geeMailUserFinder

Where there is microsoft, there is google. Same concept as Oh365 but for gmail.


Social media OSINT

Finding Usernames with WhatsMyName

WhatsMyName has been abandoned as a solo tool, it can however be integrated into multiple OSINT frameworks like Spiderfoot or visited via a web portal here

Finding Usernames with Sherlock

Another great tool for discovering usernames used across multiple sites. There are some false positives (some sites it pulls from will report a username for any request whether it exists or not) but overall a super easy to use tool.

Twitter OSINT (Or X depending on the day)

Search for leaks related to that user, useful for basic account info

A really useful vector for social media OSINT is to leverage tools typically used for marketing. The tools listed below can be used to create a map of the users habits and interactions by using tools typically used to track account impression

Breaks down reach, impressions, tweets by sentiment sources etc.
Very similar to Social Bearing
Tracks account and user data changes - useful for long term targets

Twitter Dorking

Did you know you can treat the twitter search bar very similar to google dorking?

Instagram OSINT

instadip.co

  • Lets you fullsize and download the image to try and hunt it down somewhere else

Now for the super creepy parts

Hands down the best facial reverse engineering tool out there. The results are highly truncated on the free tier but it is super fun for scammers.

Phone-sint (see what I did there)

Phone number OSINT is honestly a PITA. I am actively looking for suggestions for better free tools there. I refuse to "pay 99 cents to unlock this users full record".

Credential Hunting

Such an important part of proper OSINT is hunting for leaked credentials. The "industry standard" tool for this right now is dehashed. This is a paid subscription, and the API credits (a need) are a couple extra bucks on top of the monthly subscription.

Super useful tool from the TCMsec guys for pulling from dehashed API.

Outside of this, the most commonly used tool for your own "ethically sourced" databases is most likely breach parse. Its a super simple bash tool that is built for the old megabreach and COMB leaks.

There are also some "specialty" parsers out there for some other breaches. I am not going to provide the magnet link too them however the hint I will give is "AntiPublic" and "Collection 1-5". Consider this a little OSINT practice and go figure that out.

Last updated