Search

Exploring OSINT Frameworks

Allow us to have everything in one place

recon-ng (its similar to metasploit in how it works):

recon-ng
marketplace search

Marketplace:

Has all the tools with path, version, status and last updated

Install: (example script tool is hackertarget)

marketplace install hackertarget

load the tool:

modules load hackertarget

help/info on how to use:

info

How to use:

options set SOURCE tcm-sec.com
run

Found subdomains and IP addresses.

Check the table where these info get stored:

show hosts

To go back to default:

back

Profiler:

Uses the profiles table usernames to search them on WhatsMyName

options set SOURCE Alacritic

doesn’t work

He recommends:

sn0int

Spiderfoot

Maltego:

Most if not all Transforms (plugins) need API keys.

To use without API keys:

Make a new graph (upper left) and:

  1. add a domain from entities
    1. Double click to edit
    2. right click to run Transforms like DNS, Domain Owner, Email Addresses, Files and Docs
      1. All runs all of it
    3. choose the dates you want for Wayback machine

(I did great with it 💀)

Hunchly - https://hunch.ly

$130 per year, works on Chrome(ium?)

  1. Add case
    1. The Cyber Mentor
  2. Selectors:
    1. highlights, anything you want to see on a page
    2. like thecybermentor, Heath Adams
    3. should add usernames, emails, phone numbers, etc
  3. Tags:
    1. Social Media, Breached Passwords, Phone Numbers, People, Wireless Networks
  4. To do list to not miss a point
    1. Check next to it when you’re done with each
  5. How to use at 4:32: https://academy.tcm-sec.com/courses/1214089/lectures/27267102