Blacksec

Administrator
Staff member
ROOT
VIP
OSINT is detective work with a search box — no exploits, no malware, no illegal access, just everything people publish about themselves without thinking. One username, one photo, one email — and the whole digital life unfolds. This guide covers the method, the tools, and the trail people leave by accident. Kid-simple, case-ready.

TL;DR — Every person is a puzzle of public fragments: usernames, photos, emails, breach data, metadata. Cross-reference, pivot, chain. The full methodology — search layers, dork patterns, pivoting tricks — below.

1. THE DIGITAL FOOTPRINT (KID VERSION)

Kid version: every kid in school leaves footprints in the playground — a dropped note, a locker combination written on a hand, a signature on the bathroom wall. None of it is locked away. All of it tells you where they'll be after class.

OSINT works on exactly that principle. Nobody hacks anything. You read what people already threw away: usernames, bios, old forum registrations, photo backgrounds, job posts, breach lists, domain records, conference badges, running-route screenshots with street signs visible. Humans are pattern animals — they reuse handles, reuse emails, reuse everything — and that habit is the entire attack surface.

The discipline has a professional name: Open Source Intelligence. Police use it, companies use it for fraud checks, journalists use it to verify stories, and attackers use it because it is free, legal, and devastatingly effective. The data was given away voluntarily. OSINT just reads the giveaway.

2. THE LAYERS (WHERE TO DIG FIRST)

Work outside-in, every layer pivots into the next:

Layer one — the handle. One unique username is a skeleton key. Tools like Sherlock and Namechk fire the name at hundreds of platforms simultaneously — where the account EXISTS tells you where the person lives digitally, which platforms they prefer, which old accounts are still dormant and unmonitored.

Layer two — the email. Breach-check services (Have I Been Pwned and friends) show which dumps contain the address. Each dump = new context: a forum registration from 2014, a shopping account, an old gaming forum — every hit is a thread to pull.

Layer three — the person. Real name, employer, city from LinkedIn. Old accounts connect through password-reset hints, profile photos reused across platforms, and recovery emails visible in public records.

Layer four — the physical. Photos carry background detail — street signs, landmarks, window reflections. Job locations, event check-ins, sports club pages narrow the address. Property records and voter files (public in the US) finish the map.

Each layer feeds the next. Username → platforms → email → breaches → real name → employer → address. Six pivots from a handle to a doorstep, all from data people posted themselves.

3. GOOGLE DORKS — THE SEARCH SCALPEL

Regular search finds pages. Dork search finds specific VULNERABLE or EXPOSED content. The operators worth memorizing:

Bash:
site:target.com filetype:pdf         files only on their domain
intitle:"index of" password            exposed directory listings
inurl:admin.php                        admin panels in URL
"john.doe@gmail.com"                   exact string across the web
filetype:xls "credit card"             leaked spreadsheet hunt
related:target.com                     sites like theirs (network mapping)
"Target Corp" (hr OR careers OR jobs)  employee hunting
cache:target.com                       old versions of a page

Directory listings alone ("index of") have leaked thousands of backup files — sql dumps, config.php copies, .env files — because admins forgot one line in their web server config. That is OSINT's whole personality: no exploitation, just finding the door someone left open and reading the label.

4. USERNAME PIVOTING (THE CORE TRICK)

The one technique that makes everything else click: REUSE.

  • Grab a target's handle on one platform. Search it EXACT — quotes force literal matches.
  • Find it on old forums where people used their real email or real name in the signature. Old internet was careless; current internet remembers.
  • Profile photo reuse: reverse image search the avatar. People upload the same photo for a decade across platforms — TinEye and Google Images map the whole account graph from one picture.
  • The email pattern: firstname.lastname@, flastname@, nickname1990@ — once you know one address, generate the likely variants and test them at password-reset forms (where allowed) or breach searches.
  • Metadata: photos taken with phones carry EXIF — GPS coordinates, device model, timestamp. Post the photo anywhere that strips metadata now, but old uploads and forums often preserved it. exiftool reads it all in one command.

Handle → photo → email → phone number → real identity. Four pivots, zero exploits, all public.

5. TOOLS OF THE TRADE

JobToolWhat it returns
Username sweepSherlock, NamechkPlatforms where the handle exists
Email breach checkHave I Been PwnedDumps containing the address
Photo pivotGoogle Images, TinEye, YandexWhere else the picture appears
Domain intelWHOIS, crt.sh, ShodanOwner, subdomains, exposed services
Metadataexiftool, FOCAGPS, device, timestamps in files
Archive time machineWayback MachineDeleted pages, old versions, dead data
People recordsPublic records, Pipl, TruePeopleSearchAddress history, relatives, property

Shodan deserves its own sentence: it indexes internet-connected devices — cameras, databases, RDP ports, industrial controllers — searchable by banner content. Find every exposed machine in a country with one query. It is the infrastructure layer of OSINT.

6. OPSEC — BOTH SIDES OF THE LENS

If you are READING people: understand where the line sits in your jurisdiction. Stalking laws cover persistent unwanted research. GDPR and CCPA cover commercial use of personal data. Licensed investigators have frameworks precisely because raw collection without purpose gets people sued — or worse, charged.

If you are being READ — everyone is — reduce the blast radius:

  • Unique handle per platform. Reuse is the pivot that kills you.
  • Strip EXIF before uploading anywhere, always.
  • Separate identity emails from registration emails.
  • Google yourself quarterly and delete what you find — old forums, forgotten accounts, data-broker listings (opt out of Spokeo, WhitePages, BeenVerified — the brokers sell what you never posted).
  • Assume every breach is public. Because it is.

7. FIELD CHEAT SHEET

TaskMove
Startexact handle search + Sherlock sweep
Pivot 1reverse image the profile photo
Pivot 2breach search the email, mine old dumps
Pivot 3dork the real name + employer
Deep file huntsite:target filetype:pdf / xls / sql
Device layerShodan query for exposed services
Self-defenseunique handles, strip EXIF, broker opt-outs

— RELATED GUIDES —

Handle in, identity out — four pivots, zero exploits, everything pulled from what people already published. Sherlock swept, photo pivoted, dorks fired, breach data mined. The footprint was always there; now go read it like a case file.
 
Last edited: