Passive
OSINT:
Open-source intelligence (OSINT) is the collection and analysis of data gathered from open sources (Publicly available sources) to produce actionable intelligence.
In this section of OSINT we will use various methods to gather Intelligence with Open Sources (Google, Bing, Yandex) there are a few tools that can help us reach these goals. A few tools that can help us with this in Email Gathering, Phones, Names, Addresses, and the possibility of Locations.
The information collected in this method is only as good collected as the Operator since this section can have a plethora of information being collected and to be confirmed positive results that are real.
Some great frameworks that can be used in this approach are datasploit, SpiderFoot or Recon-ng
Example:
​Google Dorking​
​
​
I used a combination of Dorks that can help me gather information, in this example it's Google.com and I am looking for specific file types PDF and in the PDF files, it needs to contain the words passwords.
​
We can tell that this PDF contains the words passwords, nothing being leaked but it gives us exactly what we were looking for and this can help to probably locate other files that are known for containing these passwords.
This method is considered Passive.
Copy link