Skip to main content
7 min read Intermediate OSINT

OSINT Collections and tools || Check Lists

Image

image

SiteDescription
WebCheckAn all-in-one tool for discovering information about a website or host.
CIRCL - AIL FrameworkThe Analysis Information Leak (AIL) framework for analyzing leaks of sensitive information.
Leakcorp.comAn online community focused on discussions and information related to data breaches.
Leaked.siteA platform to check if your email or data has been compromised.
Leakedsource.ruA resource for accessing data from past data breaches.
Hashes.orgA repository for cryptographic hash values commonly used in password cracking.
Dehashed.comA platform offering access to breached databases and password cracking services.
Joe.black/leakengine.htmA website related to data leak analysis and information.
Intelx.ioAn intelligence search engine providing access to various data sources.
Weleakinfo.toA site known for sharing information from various data breaches.
MetagoofilA tool for extracting metadata from public documents (PDF, DOC, XLS, PPT, etc.) available on the web.
Scatteredsecrets.comA service that searches for exposed personal data and credentials.
MaltegoA comprehensive tool for gathering information from various public sources and visualizing the relationships between entities.
ZoomEyeA search engine for cyberspace, enabling searches for specific network components and vulnerabilities.
Private-base.infoA source for leaked databases and personal information.
IntelTechniquesA website offering various OSINT tools and resources for online investigations.
Leak-lookup.comA tool to check if your personal information is part of any public data breaches.
DataSploitAn OSINT framework to perform various reconnaissance techniques on companies, individuals, and employees.
Haveibeenpwned.comA widely recognized tool for checking if your email has been involved in data breaches.
ShodanA search engine allowing users to find specific types of computers, services, and information connected to the internet.
Ghostproject.frA French website known for sharing data from various breaches.
Snusbase.comA database of leaked credentials and data, useful for security and research.
Leakcheck.netAnother website to check if your email has been part of a data breach.
Services.normshield.comA service offering cybersecurity solutions and breach monitoring.
Leakpeek.comA platform providing insights into leaked data and breaches.
SpiderFootAn open-source OSINT automation tool for gathering data from various sources for reconnaissance purposes.
GephiAn open-source platform for visualizing and analyzing large networks, useful for understanding social connections.
TheHarvesterA tool for gathering information like email addresses, subdomains, hosts, employee names, open ports, and banners from different public sources.
Leakcheck.ioA tool to verify if your email address has been involved in data breaches.
Leak-sxA platform known for sharing information about data leaks and breaches.
Breachchecker.comA website for checking if your email address has been compromised in data breaches.
Haveibeensold.appA service helping you check if your personal data is being sold online.
FOCAA tool for metadata analysis and information gathering from public documents, including Word, PDF, and PowerPoint files.
PiplA people search engine that allows you to find detailed information about a person based on their online presence.
Leakcheck.ioA tool to verify if your email address has been involved in data breaches.
Leak-sxA platform known for sharing information about data leaks and breaches.
Breachchecker.comA website for checking if your email address has been compromised in data breaches.
Haveibeensold.appA service helping you check if your personal data is being sold online.
FOCAA tool for metadata analysis and information gathering from public documents, including Word, PDF, and PowerPoint files.
PiplA people search engine that allows you to find detailed information about a person based on their online presence.
PeekYouA search engine that provides comprehensive people search, including social media profiles and public records.
IntelTechniquesA website offering various OSINT tools and resources for online investigations.
EchosecA social media monitoring platform that enables real-time threat detection by analyzing publicly available social media posts.
Recon-ngA full-featured web reconnaissance framework written in Python, providing a powerful environment for conducting reconnaissance.
TheHarvesterA tool for gathering information like email addresses, subdomains, hosts, employee names, open ports, and banners from different public sources.
EchosecA social media monitoring platform that enables real-time threat detection by analyzing publicly available social media posts.
Recon-ngA full-featured web reconnaissance framework written in Python, providing a powerful environment for conducting reconnaissance.
EchosecA social media monitoring platform that enables real-time threat detection by analyzing publicly available social media posts.
Recon-ngA full-featured web reconnaissance framework written in Python, providing a powerful environment for conducting reconnaissance.
EchosecA social media monitoring platform that enables real-time threat detection by analyzing publicly available social media posts.
Recon-ngA full-featured web reconnaissance framework written in Python, providing a powerful environment for conducting reconnaissance.

Check lists for OSINT

Information Gathering

Define Objectives

  • Clearly define the objectives and scope of the OSINT investigation.
  • Ensure compliance with legal and ethical guidelines.
  • Respect privacy and terms of service.

Target Identification

  • Identify the target(s) or subject(s) of the investigation.

Online Sources

Search Engines

Social Media

Forums and Communities

  • Explore relevant forums, discussion boards, and online communities.

Blogs and Personal Websites

  • Look for blogs and personal websites related to the target.

News Articles

  • Search for news articles or mentions related to the target.

Public Records

  • Access public records, such as property records, court documents, and business registrations.

WHOIS Lookup

  • Use WHOIS databases to gather information about domain registrations.

DNS Enumeration

  • Enumerate DNS records to identify subdomains and related services.

Email Addresses

  • Search for email addresses associated with the target.

Social Engineering

Phishing

  • Use ethical phishing techniques to gather information (obtain informed consent).

In-Person Engagement

  • Attend events, conferences, or gatherings where the target may be present.

Dark Web

Dark Web Monitoring

  • If relevant, monitor dark web marketplaces and forums for mentions of the target.

Onion Sites

  • Explore Tor network (.onion) sites for hidden information.

Tools and Resources

OSINT Tools

Wayback Machine

Google Dorks

  • Use advanced Google search operators to refine search results.

Social Media Scraping

  • Employ tools or scripts to scrape social media profiles and content.

Publicly Available Data

  • Explore public datasets, such as data.gov and data repositories.

APIs

  • Access APIs of social media platforms or data providers for information retrieval.

Verification

Cross-Reference Data

  • Verify information from multiple sources to ensure accuracy.

Source Reliability

  • Assess the reliability and credibility of information sources.