Recon is the first step in the Cyber Kill Chain, but what tools to start with?

Let's Kickoff your OSINT toolbox with these 10 website OSINT tools that rock

Let's start with a banger that I just found out about ...
#cybersecurity #OSINT #pentesting
[1] TINFOLEAK tinfoleak.com

This site allows you to Search for Twitter users leaks 😱

Basic info about a Twitter user (name, picture, location, followers, etc.)

Devices and OS and much more. Full, informative briefing on a twitter user
[2] Shodan! shodan.io

Shodan is a search engine scanning the entirety of the internet for connected devices. 🌎

Arguably my favorite and one that every #cybersecuirty pro should know both for recon and for educating end users on 'whats out there!' Shodan searching for port 22 in Charleston SC
[3] BuiltWith builtwith.com

BuiltWith® covers 60,940+ internet technologies which include analytics, advertising, hosting, CMS and many more. ⚒️

Basically it will allow you to plugin a website and see what the tech stack is under it. Tesla.com tech stack
[4] Google (Dorking) Google.com

Google is a powerful search engine, but power users know how to really utilize it. 🔍

Keywords you can elicit very interesting OSINT from it. Check out this link for how to utilize Google for OSINT

securitytrails.com/blog/google-ha… Google Dorking FTW!
[5] ZoomEye zoomeye.org

China based Internet resource aggregator.👀

Per ZoomEye, its dataset is based on a large number of global surveying and mapping nodes, according to the global IPv4, IPv6 address and website domain name database. Think Shodan, but different.
[6] OSINT Framework osintframework.com

Great starting point mindmap of various OSINT tools and resources. 🖼️

This one is a bit meta on this list as its less of an OSINT tool and more of a repo of OSINT tools. Still awesome OSINT Framework mindmap
[7] Email OSINT with Hunter.io hunter.io

Straight simple tool. You drop in a business domain and it pops out likely email naming convention based on OSINT. Tie this with 📨

LinkedIN and you can likely derive folks business email. Microsoft.com email addresses
[8] Reverse Image Search TinEYE tineye.com

Cool tool to have in the back pocket, TinEye allows you upload an image and find other instances of it on the Internet. 📷

Useful if you're trying to build out a network or get leads with a pic. TinEye searching on my pic
[9] Business lookup aihitdata.com

Want to get info on a business or find other businesses in the same area as a client. 🏭

This quick and simple tool will help you with that. Business look up in Deadwood SD
[10] SOCK Puppet Helper - thispersondoesnotexist.com

If you need a picture of a person but want to avoid privacy issues, and you're in a rush, this site will instantly generate someone that's completely virtual. Perfect for your sock puppets! 🥺 This guy is not real
[BONUS Material] I'm not a pentester, so my use of OSINT tools isn't to the max, but considering following these accounts for conversations of this nature or just GREAT cybersecurity content: @thecybermentor @bettersafetynet @C_3PJoe @_JohnHammond @vxunderground @GossiTheDog 💪
@thecybermentor @bettersafetynet @C_3PJoe @_JohnHammond @vxunderground @GossiTheDog That's a wrap!

If you enjoyed this thread:

1. Follow me @Gerald_Auger for more of these
2. RT the tweet below to share this thread with your audience

SimplyCyber.io for a ton more free #cybersecurity resources. 💙
If you like this tweet, you'll love my exclusive email that helps you crush work, delivering 3 actionable cyber tasks every Monday morning to your inbox.

Join here: simplycyber.io/newsletter

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Gerald Auger, Ph.D.

Gerald Auger, Ph.D. Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @Gerald_Auger

Sep 27
You want to work in cybersecurity, but not sure which role? 💥

I've worked in industry for nearly 20 years and you can to💙

Here are 5 entry cybersecurity level roles that might be a good fit:

A thread [🧵]
[1] SOC Analyst 🛡️
Blue team defender with hands on keyboard defending, responding, and hunting for threats and compromises. Lot of opportunity with MSSPs for this role.

I did a deeper dive on SOC Analyst here:
[2] Digital Forensics Engineer (DFIR) 🔍
You are like a detective going through evidence trying to piece together what happened and recovering data. You are collecting evidence and it may be used in court. CSI-esque.

I give deeper analysis on DFIR here:
Read 11 tweets
Sep 23
Trying to get into #cybersecurity?

Here's the TOP 5 cybersecurity job hunting questions from an industry expert that has placed over a 1000 people into a cybersecurity job.

All answered with time stamps:

#iThinkThisIsHowYouUseThreads
[🧵] Image
0:47 How do I break into cybersecurity?
3:53 How do I identify if a role is remote?
Read 8 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(